User Roles: How to Create User Roles | Sohonet CORE Help Center

User Roles: How to Create User Roles

August 31, 2023

Before Creating New User Roles

Find below a few tips and insights to help you better plan and prepare for User Role creation in CORE.

Naming Conventions Tips

Use a convention that can be applied consistently across projects. For instance:

Examples:

Craft User Role Templates

Templates save you time.

Create a template for each role type you’ve identified. Name them Template_Role Name, so all of your Admins and users with role access can save these roles to their own template folders.


Create a New User Role: A Step-By-Step Guide

Creating a User Role is done in multiple parts:

  1. Step 1: You must first create the basic user role in the Role Info tab.
  2. Step 2: If any, add Viewer Access Rules.
  3. Step 3: If any, add Edit Access Rules.
  4. Step 4: Finally, you create User Access Rules.

Step 1: Add Basic User Role Info

  1. Start by entering the User Role name.
  2. Choose what Domains they can access when uploading, tagging, and editing tags on files. If the user can't upload, leave it defaulted to ALL.
  3. Choose what Package Types they can share. Default is ALL.
  4. Choose what view or downloading permissions they can give on a package share. Default is ALL.
  5. Unless specifically an Admin or Coordinator, select Standard on User Access Level.
  6. The default package share type is a Standard package. Choose a different package type if desired.
  7. For Redirect on Login, choose Inbox, File Search, or the Dashboard for where they land after logging in.
  8. If your role isn't using SSO, choose whether or not they should have MFA.
  9. Choose what or if the users can download.
  10. Disregard the Watermark Strategy unless directed to change to Burn in.
  11. If this role is for a company subdivision requiring its users to have their own logo in CORE, select from provided logos.
  12. Choose if a user can tag files or skip and share (Quick Share) files without tags.
  13. If your system has a Dashboard, choose your dashboard type. We recommend the Package dashboard.
  14. Extend your users logout time in minutes. Most clients extend this between an hour and a day, depending on their security requirements.
  15. Next select from any Admin Controls.
  16. Followed by User Controls.
  17. Choose the Package Controls.
  18. Provide Device access.
  19. Finally, if the role can share packages and you want to narrow down what statuses they can request on Approval Packages, choose the options here.

Steps 2 and 3: Add View and Edit Access Rules

The difference between the two rules is:

When building rules, it's good to understand the following:

To create a rule:

  1. Go to either the View or Edit Access Rules tab.
  2. Select +Add Rule.
  3. Name the rule.

Step 4: Add User Access Rule

This enables users to see and share with other users in the system. If you don't add this rule, the users in the role will see only themselves.

  1. Go to User Access Rules tab.
  2. Select +Add Rule.
  3. Name the rule.
  4. Select if you want the users to be able to view, edit, and access sensitive users within the scope of the rule.
  5. Select the tags that make up your rule.
  6. Select the condition of the tag and its defining values such as Company, Department, or Production.
  7. Add another rule as needed.
  8. Before you leave the tab, select the Save button at the bottom.

User Role Examples

Example 1: Department Admin

The Department Admin will have the basic Permissions of a Standard User with additional access added to allow them to have Admin permissions for a specific department and production only.

  1. Create a new role and assign the new Role a name by entering it under User Role Name. For our department admin, we will name the role NoobAdventures_07_Editorial_ADMIN.
  2. Assign the specific settings in Role info.
  3. Users with this role will have the ability to Create Users and Upload Assets for the department and production they have access to.

Example 2: Viewer

The Viewer Role gives users permission to view assets within a particular production (no uploading, downloading or sharing options).

  1. Create a new role and assign the new Role a name by entering it under User Role Name. For our viewer role, we will call it KornFerry_Viewer.
  2. Assign the specific settings in Role info.
  3. Create an Access Rule that gives the Viewer access to only the project.

Example 3: Uploader Role

The Uploader Role gives users permission to upload and share assets within a particular production (no downloading options).

  1. Create a new role and assign the new Role a name by entering it under User Role Name. For our production uploader, we will name the role AirTheMovie_Uploader.
  2. Assign the specific settings in Role info.
  3. Create an Access Rule that gives the Uploader access to the Air the Movie project only.