Freedam

Asset Access Rules

Asset Access Rules allow administrators to define granular permissions for who can see, preview, and download specific assets. By combining user conditions (like roles or departments) with asset filters (like tags or asset classes), you can automate complex security requirements across your entire library.

This feature is essential for organizations managing sensitive brand assets, licensed content, or department-specific media. You can enforce watermarks on previews, restrict high-resolution downloads to specific teams, or require a formal approval workflow before an asset can be used.

Asset Access Rules overview

Page Overview

  • Purpose: To manage the logic that governs asset security and availability.
  • When to use it: Use this page when you need to hide assets from certain users, protect assets with watermarks, or set up "Request Access" workflows.
  • What you can do here:
    • Create and prioritize access rules.
    • Define visibility (Visible vs. Hidden) for specific user groups.
    • Configure preview types (Full, Watermarked, or None).
    • Set download restrictions and resolution limits.
    • Establish request workflows for restricted assets.
    • Test rule logic against specific users or assets.

Who can use it

Only administrators with the Asset Access Rules permission can open, create, edit, duplicate, toggle, or delete rules — and only they can use the Access Tester. Regular users and editors never see this page. The AI-powered Explain Rules button and both Access Tester tabs share the same permission.

Page Layout

  • Top bar: Contains the page title, the Add Rule button, and utility tools like Explain Rules and Test Access.
  • Main area: A searchable table listing all rules, showing their priority, name, conditions, and current status (Active/Inactive).
  • Search and Filter: A search bar to find rules by name and a dropdown to filter by status (All, Active, or Inactive).
  • Rule Dialog: A multi-tab interface (Basic Info, User Conditions, Asset Filters, Access Policy, Request Workflow, Download Intent) used for creating or editing rules.

Main Features

Access Policy

  • What it's for: Defining the specific permissions granted when a rule matches.
  • Typical use: Setting an asset to be "Visible" but only allowing "Watermarked Previews" and no direct downloads.
  • Result: Users matching the rule will see the asset in search results but cannot access the original file without further permission.

Request Workflow

  • What it's for: Creating a bridge for users who need higher access than their default permissions allow.
  • Typical use: Setting a rule where users must "Ask asset owner for access" to download high-res files.
  • Result: A "Request Access" button appears on the asset, and a notification is sent to the owner or admin team upon clicking.

Access Tester

  • What it's for: Verifying that your rules are working as intended without needing to log in as different users.
  • Typical use: Entering a user's email and an Asset ID to see exactly which rule is granting or denying access.
  • Result: A detailed breakdown of the "Effective Policy" and a list of all matching rules.

Detailed Feature Documentation

Creating an Access Rule

  • Purpose: To establish a new set of permissions for a specific scenario.
  • Where to find it: In the Top bar, click the Add Rule button.
  • What you'll see: A large dialog window with six tabs to configure the rule details.

How to use it:

  1. In the Basic Info tab, enter a Rule Name and set a Priority (higher numbers take precedence).
  2. Navigate to User Conditions to define who this rule applies to (e.g., User Role is "Marketing").
  3. Navigate to Asset Filters to define which assets are affected (e.g., Asset Class is "Logo").
  4. In the Access Policy tab, choose if assets are Visible or Hidden.
  5. Configure Preview and Download settings, including any required Watermarks.
  6. Click Create Rule to save and apply the logic.

Creating a new access rule

Download Intent Dialog

  • Purpose: To force users to acknowledge terms of use or state their purpose before downloading.
  • Where to find it: Inside the Rule Dialog, navigate to the Download Intent tab.
  • What you'll see: Options to enable a dialog, enter a multilingual message, and require acknowledgment.

How to use it:

  1. Check Show a download-intent dialog to users matched by this rule.
  2. Enter a Download Intent Message (e.g., "These assets are for internal use only").
  3. (Optional) Check The user will not be able to download without acknowledging the above text.
  4. (Optional) Check Ask the user to select a Download intent usage to provide a dropdown of reasons.
  5. Click Simulate Download Intent Dialog to see how it will appear to the end-user.

Access Tester

  • Purpose: To troubleshoot why a user can or cannot see an asset.
  • Where to find it: In the Top bar, click Test Access.
  • What you'll see: Two tabs: Test User (to see all rules matching a person) and Test Asset Access (to see the final permission result for a specific asset).

How to use it:

  1. Select the Test Asset Access tab.
  2. Enter the User email or ID and the Asset ID or GAID.
  3. Click Test.
  4. Review the Visibility, Preview, and Download cards to see the "Effective Policy."
  5. Expand Matching Rules to see which specific rules contributed to this result.

Access Tester

Complete Workflows

Workflow: Restrict High-Res Downloads to Marketing Team

  • Goal: Allow everyone to see assets, but only the Marketing team can download high-resolution versions.
  • Prerequisites: Marketing users must have a "Marketing" role assigned.

Steps:

  1. Click Add Rule in the Top bar.
  2. Name the rule "Marketing High-Res Access" and set Priority to 100.
  3. In User Conditions, add a condition where Role equals Marketing.
  4. In Access Policy, set Visibility to Asset visible to users.
  5. Enable Allow Download and check all available Download Resolutions.
  6. Click Create Rule.
  7. Create a second rule named "General Access" with Priority 50.
  8. In Access Policy, enable Allow Download but only check "Low Resolution" or "Web Ready."
  9. Click Create Rule.
  • Expected result: Marketing users get the high-priority rule (all resolutions), while others fall through to the lower-priority rule (limited resolutions).

Workflow: Require Approval for Sensitive Assets

  • Goal: Assets tagged "Confidential" should require Admin approval before download.
  • Prerequisites: Assets must be tagged with "Confidential."

Steps:

  1. Click Add Rule and name it "Confidential Asset Workflow."
  2. In Asset Filters, add a condition where Tags contains Confidential.
  3. In Access Policy, set Allow Download to Enabled.
  4. Navigate to the Request Workflow tab.
  5. Select Ask admin team for access under Workflow Type.
  6. In Request Message, type "Please explain why you need access to this confidential material."
  7. Click Create Rule.
  • Expected result: When a user tries to download a confidential asset, they will see a "Request Access" prompt instead of an immediate download.

Limits and guardrails

  • The rules list shows 20 rules per page. Use the search box or the status filter to narrow the list when your library grows past that.
  • The system ships with one Built-in Default Access Rule at the bottom of the priority stack. It grants permissive preview and download access so the product works out of the box, but it is only kept active when the server-level flag allows it. It cannot be edited, duplicated, or deleted from the interface.
  • Duplicated rules are always created as Inactive and dropped to the top of the priority list so you can safely tweak them before they start matching anyone. The edit dialog opens automatically on the fresh copy.
  • Both the Request Workflow and Download Intent sections are only enforced when the rule is Active. Inactive rules have no effect but are preserved so you can turn them back on later.
  • The three request workflows are: Access not limited (no restriction), Ask for access to the asset owner (routes the request to whoever uploaded the asset), or Ask for access to the Admin team (routes it to all administrators or to the designated reviewer group).

What happens behind the scenes

  • Activating, deactivating, editing, duplicating, or deleting any rule clears the platform-wide access cache so that all users see the new permissions within seconds — not at the next login.
  • Access decisions are cached in short-lived memory per request and in a shared cache for up to an hour, so repeat checks during a gallery scroll don't add noticeable load.
  • Rule evaluation is resilient: if a single condition fails for a technical reason, the rule is skipped rather than silently denying access to everything. The error is logged for troubleshooting.
  • The Explain Rules button sends the selected rules (or all of them if none are selected) to the configured AI provider, which returns a plain-English summary so you can show your team or auditors how access is governed without reading conditions row by row.
  • The Access Tester re-runs the live rule engine, so the result you see in the dialog is exactly the same policy a real user would experience at that moment.

Tips and Best Practices

  • Priority Matters: Rules are evaluated based on Priority. If two rules match a user, the one with the higher number wins.
  • Use "Built-in" Rules: Some rules are provided by the system. These cannot be deleted but can often be viewed to understand base permissions.
  • Performance Warning: If you use a Preview Watermark that includes user-specific placeholders (like Name or Email), it may slow down page loading as the system must generate a unique image for every user.
  • Duplicate Rules: Use the Duplicate option in the rule's action menu (three dots) to quickly create variations of complex rules.

Troubleshooting

Issue: User cannot see an asset they should have access to

  • Symptoms: Asset does not appear in search results for a specific user.
  • Cause: A high-priority rule may have Visibility set to "Hidden," or no rule exists to grant them visibility.
  • Fix: Use the Access Tester with the user's email and the Asset ID. Check if a "Hidden" rule is overriding your intended policy.
  • Prevention: Always set a descriptive name for rules so you can identify them easily in the tester.

Issue: "Simulate Download Intent Dialog" button is disabled

  • Symptoms: You cannot click the preview button in the Download Intent tab.
  • Cause: The dialog requires either a message to be typed or the "Ask usage" checkbox to be enabled before it can be previewed.
  • Fix: Type a message in the Download Intent Message field or check Ask the user to select a Download intent usage.

Issue: Rule changes are not appearing for users

  • Symptoms: You saved a rule, but users still see the old permissions.
  • Cause: The rule might be set to "Inactive."
  • Fix: Check the Status column in the main table. If it says "Inactive," click the action menu (three dots) and select Activate.

show.relatedDocs.heading

show.relatedDocs.subheading