Fine-grained permissions
Seventy-seven distinct permissions across assets, collections, brand, AI, admin, and operations. Compose roles that match how your team actually works.

Built for the team running the library
Granular permissions, hierarchical user groups, smart access rules, watermarks, share-link controls, and dashboards. Run a busy library without the busywork.
Access control, asset protection, and visibility, wired into every layer of your library.
Seventy-seven distinct permissions across assets, collections, brand, AI, admin, and operations. Compose roles that match how your team actually works.
Nest groups inside groups. Assign roles once at the parent and let inheritance handle the rest. Onboarding scales without per-user fiddling.
Combine user attributes with asset filters to drive policy automatically. Optional request workflow when someone needs an exception.
Dynamic watermarks with placeholders for user, date, and custom text, applied on previews, downloads, and shares.
Passwords, expiry, allowed emails or domains, embed allow-lists, and watermark binding, every external link is configured, not improvised.
See what your team actually did, uploads, edits, deletes, shares, alongside dashboards covering asset performance and search trends.
Seventy-seven granular permissions across every meaningful action. Pick the ones a role needs, save it, assign it. Nobody gets “admin or nothing.”
Role assignments themselves are audited. When a permission is granted or revoked, you know who, when, and why.
Permission groups
Group hierarchy
Path
Marketing → Brand Studio → Photographers
Inherited from parent groups
Set on this group only
Hierarchical groups inherit permissions down the tree. Assign a role at “Marketing” and every team inside it gets it, unless you override deliberately.
Groups work on every plan. Single sign-on through your existing identity provider, Google Workspace or Microsoft Entra, comes with the Business plan, so onboarding a new hire is the same workflow as the rest of your stack.
Rules combine user conditions with asset filters to enforce policy automatically. Hide embargoed assets from contractors, route requests through approval, or quietly apply different watermarks to different audiences.
Rules are prioritized, named, and testable, not a tangle of one-off ACLs that nobody can read.
Access rule
Name
Hide unreleased product imagery from external contractors
When
Then
Watermarks and share-link controls compose together. The link decides who comes in; the watermark decides what they take with them.
Optional password on any external share, bcrypt-hashed and never stored in plain text.
Restrict who can open the link by email address or by email domain. Both lists, or either, or neither, your call.
Every share can carry an expiration date. Expired links return a clean 410, not a leaked download.
Bind a watermark to the share itself, every download from this link is stamped, no matter who pulls it.
Decide which hostnames may iframe-embed the share. Browsers refuse to render it elsewhere.
Every visit logged, who, when, from where. Full audit trail for the lifetime of the link.
Sharing inside the organization is its own surface, with its own audit log. Permission grants, group changes, and access events are all captured, even when the asset never leaves the building.
Built-in dashboards across asset performance, search behaviour, ingestion workflows, and AI spend. Custom dashboards when leadership wants their own slice.
Every meaningful action your team takes is captured here. Different from the rights audit log: that one answers “was this allowed?”, this one answers “what happened, and who did it?” Both live side by side.
Programmatic access has its own audit log too, every API token call recorded, scoped, and filterable by ability.
Production-grade · Start free today
Permissions, groups, watermarks, share controls, and dashboards, all in one place, from day one.