User Roles: How to Create User Roles | Sohonet CORE Help Center
User Roles: How to Create User Roles
August 31, 2023
Before Creating New User Roles
Find below a few tips and insights to help you better plan and prepare for User Role creation in CORE.
Naming Conventions Tips
Use a convention that can be applied consistently across projects. For instance:
- Start each Role with the name of a project, business group or workflow that is most appropriate for your needs.
- Use numbers for easy identification of role type or complexity.
- If you know that every project has seven roles, scale them from 01 to 07 with 01 being the most basic user with limited access and 07 as your Admin.
- Use keywords that indicate the role type, such as Inbox Only, Upload, Download, Distribution, etc.
Examples:
- PROJECT A_01_Inbox Only
- PROJECT B_01m_Inbox_Mobile Only
- BUSINESS GRP_03_Upload-Download
- BUSINESS GRP_05_Package Mgr_Distro
- SYSTEM_07_Admin
Craft User Role Templates
Templates save you time.
Create a template for each role type you’ve identified. Name them Template_Role Name, so all of your Admins and users with role access can save these roles to their own template folders.
Create a New User Role: A Step-By-Step Guide
Creating a User Role is done in multiple parts:
- Step 1: You must first create the basic user role in the Role Info tab.
- Step 2: If any, add Viewer Access Rules.
- Step 3: If any, add Edit Access Rules.
- Step 4: Finally, you create User Access Rules.
Step 1: Add Basic User Role Info
- Start by entering the User Role name.
- Choose what Domains they can access when uploading, tagging, and editing tags on files. If the user can't upload, leave it defaulted to ALL.
- Choose what Package Types they can share. Default is ALL.
- Choose what view or downloading permissions they can give on a package share. Default is ALL.
- Unless specifically an Admin or Coordinator, select Standard on User Access Level.
- The default package share type is a Standard package. Choose a different package type if desired.
- For Redirect on Login, choose Inbox, File Search, or the Dashboard for where they land after logging in.
- If your role isn't using SSO, choose whether or not they should have MFA.
- Choose what or if the users can download.
- Disregard the Watermark Strategy unless directed to change to Burn in.
- If this role is for a company subdivision requiring its users to have their own logo in CORE, select from provided logos.
- Choose if a user can tag files or skip and share (Quick Share) files without tags.
- If your system has a Dashboard, choose your dashboard type. We recommend the Package dashboard.
- Extend your users logout time in minutes. Most clients extend this between an hour and a day, depending on their security requirements.
- Next select from any Admin Controls.
- Followed by User Controls.
- Choose the Package Controls.
- Provide Device access.
- Finally, if the role can share packages and you want to narrow down what statuses they can request on Approval Packages, choose the options here.
Steps 2 and 3: Add View and Edit Access Rules
The difference between the two rules is:
- View access rules give users the ability to view the files defined in the rules.
- Edit access rules give users the ability to both view and edit the files defined in the rules.
When building rules, it's good to understand the following:
- Conditionals within a rule act as an AND.
- Multiple rules within a role act as an OR.
To create a rule:
- Go to either the View or Edit Access Rules tab.
- Select +Add Rule.
- Name the rule.
Step 4: Add User Access Rule
This enables users to see and share with other users in the system. If you don't add this rule, the users in the role will see only themselves.
- Go to User Access Rules tab.
- Select +Add Rule.
- Name the rule.
- Select if you want the users to be able to view, edit, and access sensitive users within the scope of the rule.
- Select the tags that make up your rule.
- Select the condition of the tag and its defining values such as Company, Department, or Production.
- Add another rule as needed.
- Before you leave the tab, select the Save button at the bottom.
User Role Examples
Example 1: Department Admin
The Department Admin will have the basic Permissions of a Standard User with additional access added to allow them to have Admin permissions for a specific department and production only.
- Create a new role and assign the new Role a name by entering it under User Role Name. For our department admin, we will name the role NoobAdventures_07_Editorial_ADMIN.
- Assign the specific settings in Role info.
- Users with this role will have the ability to Create Users and Upload Assets for the department and production they have access to.
Example 2: Viewer
The Viewer Role gives users permission to view assets within a particular production (no uploading, downloading or sharing options).
- Create a new role and assign the new Role a name by entering it under User Role Name. For our viewer role, we will call it KornFerry_Viewer.
- Assign the specific settings in Role info.
- Create an Access Rule that gives the Viewer access to only the project.
Example 3: Uploader Role
The Uploader Role gives users permission to upload and share assets within a particular production (no downloading options).
- Create a new role and assign the new Role a name by entering it under User Role Name. For our production uploader, we will name the role AirTheMovie_Uploader.
- Assign the specific settings in Role info.
- Create an Access Rule that gives the Uploader access to the Air the Movie project only.