# User Roles: Setting Up Your CORE For Your Users and Best Practices

September 1, 2023

User Roles are the way you grant user permissions in CORE. They are highly customizable to meet various security and team workflow needs.

To minimize the "lift" when setting up your system, we've listed some best practices and recommendations for creating your user roles and permissions that we've seen work well across different client environments.

In this article:

- **Permissions: User Roles vs Package Sharing**
- **Before You Start: System Set Up Requirements**
- **Establish a Base Set of User Roles**
- **Define Your User Roles That Never Change**
- **Define Template Roles For New Projects and Productions**
- **How User Roles Work in Combination With Tags to Create Permissions**
- **Creating Access Controls That Enable Cross-Group Access**
- **User Overrides For Those Special Needs**
- **Create Your User Roles**

---

## CORE Permissions: Understanding User Roles vs Package Share Permissions vs the New Folder and Tag Permissions

First, you must understand how CORE is setup to understand our unique permissions capabilities. CORE is a two-part closed system with (1.) a DAM space called File Search where files are uploaded into the system to be stored, and (2.) an Inbox where collections of files are sent to system users for reviews, decision making, and collaboration.

### User Role Permissions

When setting user role permissions, you're defining what a user has access to across the system (both feature-wise and files-wise) and how they can interact with the system itself (uploading, sharing, etc.).

User Roles Define:

- If a user can upload files and to where they can upload
- If a user can share files in packages and how they can share
- How a user logs in and what parts of the system they see
- Whether or not they can download files from the system
- How secure the watermark is across different file types
- If they have additional admin controls to support their teams
- What projects or productions or groups of files they (users) can view and edit in the system
- Who they can see and share with

### Package Sharing Permissions

There's an additional layer of permissions that every user has control over: the permission settings on the individual packages that they share. What permissions they can grant, however, are dictated by their user roles.

Package Permissions Define:

- Whether or not a package is view only, downloadable with watermarks, or downloadable from source.
- How a recipient can view the files online.
- Package restrictions on when and how many times a package and its file can be viewed.
- Whether or not users can see one another.
- Whether or not users can comment on the files.

### Tag Access Permissions

This is a new feature coming out with our next major build, CORE 7.0. The current build is CORE 6.6.

As this feature evolves, Admins will be able to define user access controls on files and folders like you would in any other drive tool - on the files and folders themselves.

In addition to basic user role set up, you can now select a folder or tag in File Search, right click on it, and add a user or role to it in any combination. This permission becomes an add-on to any user role and an additive rule override to any user granted permission.

### Permissions Ranking: What Permission Types Overrides What

User Roles grant access to files and what users can be seen in the system, as well as define package sharing controls, upload/download capabilities, and a user's onscreen watermarks.

- A view-only user can be granted download permissions on a package when needed.
- Users with download permissions can be restricted to view only on a package when the sender thinks the materials are too sensitive to be downloaded.

---

## Before You Start: System Set Up Requirements

Before you can start defining user roles, you need to do one to three things:

1. **Define your system's tag schema / taxonomy**, including the values users can choose from.
2. **Add your companies.**
3. **Add your departments.**

These steps are crucial if your user access rules are dependent on a user's company or department.

---

## Establishing a Base Set of User Roles

When you first set up CORE, you need to define your base set of user roles.

You typically need roles that will always remain the same and will keep adding users to them, as well as roles that can be replicated for each new project.

---

## Define Your User Roles That Never Change

There are two base role types in the CORE system:

1. Admin - This is a system admin. In CORE, the Admin can do everything.
2. Standard - This is a user with no permissions whatsoever.

### Role Examples:

1. **Inbox Reviewer** - Cannot upload nor download, only able to respond to packages.
2. **Limited Inbox User** - Can respond to packages and share files that exist in the system.
3. **Inbox Uploader** - Can upload files they have access to.
4. **Uploader User** - Can edit and download files of a specific department.
5. **Departmental Admin** - Can add users and manage their permissions.

---

## Define Your Template Roles For New Projects and Productions

For every new project, you'll want to create a set of roles that can be reused across projects. Examples:

- **Template_Inbox Reviewer** 
- **Template_Inbox Uploader**

---

## How User Roles Work in Combination With Tags to Create Permissions

User Roles leverage tags to create access controls on files. Here are some example rules:

1. View rule provides view-only access to files.
2. Edit rule provides view and edit access to files.
3. User rules grant view and sharing access with the users defined in the rule.

### Example Rules:

1. Example: View access rule enables users to see approved files of a production.
2. Example: Edit access rule enables users to view and edit all files and metadata within a production.
3. Example: Combined access rules enable users to see and edit the files of their business unit.

---

## Creating Access Controls That Enable Cross-Group Access

Departments needing access to other productions or files can be granted wider access through the User Role settings. Here, use a combination of access rules for optimal control.

---

## User Overrides For Those Special Needs

When you have users requiring special combinations of access, you can assign a base role and apply overrides specific to them.

**Overrides are additive** and highlighted to show where your changes diverge from the original role.

---

## Create Your User Roles

To learn how to create user roles, see these articles:
- User Roles: An Overview of User Role Features
- User Roles: How to Create User Roles
- How to Create User Role Templates
