---
title: "Permissions"
url: "https://helpdesk.kontainer.com/article/permissions/"
type: "article"
category: ["Admin settings", "Users, groups &amp; permissions"]
tags: ["Admin users only", "Core feature", "PIM", "DAM"]
language: "en"
published: "2023-02-23T11:56:11+00:00"
updated: "2026-07-23T08:46:34+00:00"
summary: "Setting up and managing access in Kontainer is simple. You can easily give, edit, and remove rights for user groups or individual users. &nbsp; MANAGING ACCESS Depending on user types and permissions,…"
---

# Permissions

![Permissions hero](https://helpdesk.kontainer.com/wp-content/uploads/2023/04/Permissions-hero.png?v=1763368898)

Setting up and managing access in Kontainer is simple. You can easily give, edit, and remove rights for user groups or individual users.

---

## MANAGING ACCESS

Depending on user types and permissions, there are different ways to access Kontainer. You can see and edit everything when you log in as an admin user.

What your end users see can range from a single image to your entire asset library, from view only to delete rights.

Access to files is granted via folders, or you might call them areas. There are five levels of access:

1. None
2. View
3. Download
4. Upload
5. Delete

![Kontainer Permissions 1](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-1.png?v=1763368897)

Permission can always be changed, and any changes are instant. Users can have a sum of permissions granted via group memberships and individual settings. More on that further down.

In addition, to file access, there are two other aspects to consider:

- Download options – determine how users can download images (if they are allowed to download)\
   ![](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-2-216x300.png?v=1763368897)
- Tag visibility – manage the visibility of tagged information\
   ![](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-3-214x300.png?v=1763368897)

A user will never have access upon creation. All-access is actively granted or determined by rules.

This guide covers the basics of different user types and permissions you can set in your Kontainer.

---

## PRESETS FOR PERMISSIONS

Before you even start setting up users, there are three types of presets to consider:

- Which tags to expose
- What download templates to create
- Do you want a brand section

Have a look at these tools when you are setting up users and user groups. You can always come back and add/edit these presets.

### Field Sets

**Pro+ feature**

With Custom Fields, you can tag your images with attributes, data and information. [See the guide on Custom Fields here](https://helpdesk.kontainer.com/article/tagging-filtering-advanced-search).

However, often our customers want to vary the information exposed to different users. This is managed under Field Sets.

In your Admin menu on the far left, select **Access → Field Sets** to make presets to activate on groups or individual users.

![Kontainer Permissions 4](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-4.png?v=1763368897)If you are setting up from a demo profile, there are a few demo field groups to delete before you start. Click on the **three dots** of each group and **Delete**.

**Create New** field sets from the top right button. Start by giving the set a name.\
 It could be role-based, like:

- German Distributors
- Internal Customer Service
- External Agency

Or maybe purpose-based, like:

- Copyright
- Products Information
- Consent

Users can have access to more than one set of fields.

![Kontainer Permissions 5](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-5.png?v=1763368897)\
 Once created, click on your new field set to select field access.

![Kontainer Permissions 6](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-6.png?v=1763368897)

Make as many field groups/sets as you see fit. And then, let’s move on to download options.

### Download Options

Duplicated images are a headache, so we aim to avoid duplicates in Kontainer. We encourage you to store only your originals and use templates and customize any additional download options needed.

For this reason, you can set up download templates. [Check out this guide here](https://helpdesk.kontainer.com/article/a-guide-to-download-templates/) if you don’t know how to set them up.

![Kontainer Permissions 7](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-7.png?v=1763368897)

Once you have created your download options, they are easy to activate for your users. We’ll get back to that further down.

### Brand Section

The last thing to touch on is the Brand Section which you can add to the left-hand menu (not visible to Admin users).

You can activate this section on your users to display contact details, Social Media links, and more.

![Kontainer Permissions 8](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-8.png?v=1763368897)

[We have a complete guide here](https://helpdesk.kontainer.com/article/add-a-brand-section/) if you want to set that up.

Now, let’s have a look at creating users and user groups.

---

## SETTING UP USER GROUPS

**Pro+ feature**

Okay, so user access can be set up on two levels:

1. User groups
2. Individual users

Permissions are set in the same way for individual users and groups.

When access is set on a group level, it’s quick to add new users and make changes. The initial effort will give you a better overview and save time on user management as you grow.

### What Are Groups?

You can approach groups from different angles. You can think of them as user types, like:

- Sales Team
- Distributors
- Press
- Agency

And as an access type, such as:

- Brand Guide Internal
- Brand Guide External
- German Market
- Danish Market

Users can be added to multiple groups.

**For example**, a German marketing agency gets access to the groups:

- German Market
- Agency
- Brand Guide External

### Set Up Groups

Go to: **Access & Groups**.

Here you might find some demo groups. To remove these:

1. Click on the group
2. Go to **Group settings** in the group menu
3. **Delete Group** in the top right corner.

You click on **New Group** (in the top right corner) on the Groups page to create a new one.

![Kontainer Permissions 9](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-9.png?v=1763368897)

Give the group a name that makes sense to you. It could be for your Sales Team, Distributors, Customer Service, etc.

Tick the box Active and then **Save**.

![Kontainer Permissions 10](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-10.png?v=1763368897)

You will be taken to the Permissions menu of your new group. Here, you start by selecting folder access.

![Kontainer Permissions 11](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-11.png?v=1763368897)

First, have a look at the permissions grid below to get an idea of the different types of access.

---

## PERMISSIONS GRID

Here is an overview of the folder permissions and user access types.

|  | **View Rights** | **Download Rights** | **Upload Rights** | **Delete Rights** | **Admin User** |
| --- | --- | --- | --- | --- | --- |
| **View files in folders** | x | x | x | x | x |
| **Share files in folders*** | x | x | x | x | x |
| **Comment on files*** | x | x | x | x | x |
| **Download files** |  | x | x | x | x |
| **Add files to Album** |  |  | x | x | x |
| **Edit file data/tags*** |  |  | x | x | x |
| **Rename files** |  |  | x | x | x |
| **Upload files** |  |  | x | x | x |
| **Create new folders** |  |  |  | x | x |
| **Use CDN links*** |  |  |  | x | x |
| **Move files** |  |  |  | x | x |
| **Delete files & folders** |  |  |  | x | x |
| **Use Page Editor** |  |  |  | x | x |
| **Restore files from Trash** |  |  |  |  | x |
| **Manage settings** |  |  |  |  | x |
| **Create & manage users** |  |  |  |  | x |
| **Create & manage groups** |  |  |  |  | x |
| **Create Download Templates** |  |  |  |  | x |
| **Create tags/values*** |  |  |  |  | x |
| **Manage user permissions** |  |  |  |  | x |
| **Configure Smart Folders** |  |  |  |  | x |

*This feature needs to be activated before use and could include additional costs.

---

## SET PERMISSIONS

Depending on your setup, there are generally two or three aspects of access you need to consider:

1. Folder access
2. Download options
3. Field visibility

The latter is applicable if you have set up Custom Fields.

Let’s have a look at folder access.

### Folder Access

Fundamentally, you need to give groups or individual users access rights to folders. There are five permission levels:

1. None
2. View
3. Download
4. Upload
5. Delete

With **Delete rights**, a user can also create new folders. They can create subfolders in the specific folders they have Delete rights to.

Please note that **subfolders automatically inherit** access unless manually overwritten. Below, you can see an example where the inheritance has been manually revoked in one subfolder:

![Kontainer Permissions 12](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-12.png?v=1763368897)

Permissions can also be accessed from the top right corner of a folder.

![Kontainer Permissions 13](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-13.png?v=1763368897)

This shortcut is to check or edit access to that specific folder.

![Kontainer Permissions 14](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-14.png?v=1763368897)

The next step is to look at download options.

### Download Options

Go to **Access → Users** and click on a user to change their settings.

In the Download Options, you can select which download templates the user should be able to choose when downloading files.

Furthermore, you can disable custom editing when downloading.

![Kontainer Permissions 15](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-15.png?v=1763368897)

Download options is a universal setting. You can use the download options for any file you have download (or more) access to.

The last thing to look at is file data/field visibility.

### Field Visibility

**Pro+ feature**

To edit access to the Field Sets you set up earlier in this guide, go to **Access → Users** and select a group or user.

![Kontainer Permissions 16](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-16.png?v=1763368897)

Under **Field Visibility,** select the field sets you want to activate on the group or user.

Any field also set up as a search filter will appear in the advanced search.

![Kontainer Permissions 17](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-17.png?v=1763368897)

And the user will also see the tagged information underneath an image when they hover over it, as below.

![Kontainer Permissions 18](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-18.png?v=1763368897)

### Access to PIM Channels

Any user or user group can also be given access to PIM.

Access is managed by channels and can be accessed from the top-right menu.

![Kontainer PIM: Accessing Permissions by channel](https://helpdesk.kontainer.com/wp-content/uploads/2026/01/Kontainer-PIM_Managing-access-and-permissions-by-channel-scaled.png?v=1767869870)

In the Permissions tab, you can give users and user groups different levels of access:

- View
- Download
- Edit
- Delete

![Kontainer PIM: Give users and user groups access to a channel](https://helpdesk.kontainer.com/wp-content/uploads/2026/01/Kontainer-PIM_Managing-access-and-permissions_users-and-groups--scaled.png?v=1767869846)\
 Learn more about [***Basic PIM functions here***](https://helpdesk.kontainer.com/article/basic-pim-functions/).

---

## CREATE USERS

Go to **Access → Users → New User** for individual user setup. Quickly add them to a group and/or select individual Permissions.

![Kontainer Permissions 19](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-19.png?v=1763368897)

There are 4 types of users:

- **Admin Users**
- **Normal User**
- **Open Portal**
- **Shared User**

And an additional option to add a:

- **Delegated Admin**

Each has unique functionalities that we’ll dive into below.

### User Count

In your Kontainer plan, you have a certain number of users included. You find that count in your user list.

![Kontainer Permissions 20](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-20.png?v=1763368897)

It’s important to mention that Open Portals and Shared Users only count as one user.

Example: I set up an Open Portal called ‘Brand Portal.’ I can use that link in as many places as I want. It will ever only count as one user.

To add more users to your plan, [click here](mailto:mail@kontainer.com).

### Create an Admin User

Admin users see and manage everything. They can receive notifications when new comments and files are added.

This user type is the only one with the rights to create and manage other users.

To create a **New User**, go to **Access → Users**, and find the button in the top right corner.

Select Admin User and fill out the form.

Send out an email invitation upon user creation by ticking the box in the form. The user will create their password.

![Kontainer Permissions 21](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-21.png?v=1763368897)

The invitation email can also be sent out later from the user profile.

If relevant, set up notifications on the user profile.

![Kontainer Permissions 22](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-22.png?v=1763368897)

Users can also add it themselves under Profile Settings. In the same view, they can edit their email signature used when they share files.

![Kontainer Permissions 23](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-23.png?v=1763368897)

### Create a Normal User

A Normal User can, like an Admin, subscribe to notifications when new files are added to folders, the ones they can see (see above).

The normal user is tied to an email address and password. The password is set by the user and can be reset on their request.

To create, go to **Access → Users**, and find the **New User** button in the top right corner.

Select Normal User and fill out the form.

![Kontainer Permissions 24](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-24.png?v=1763368897)

The normal user cannot access files and folders upon creation, so you can skip the invite option, click on **Create normal user and set permissions**.

![Kontainer Permissions 25](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-25.png?v=1763368897)

Now set permissions by:

- Adding the user to a group to inherit access from there
- And/or manually setting individual permissions

**NOTE:** Remember to go through the **[Download Options](#chapter10)** and [**Field Visibility**](#chapter11) settings on the user or group. These are important to ensure users can access files as well as data and download formats. Select settings regarding folder/file sharing and brand section on the user or group profile.

If relevant, set up notifications on the user profile.

![Kontainer Permissions 26](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-26.png?v=1763368897)

Users can also add it themselves under Profile Settings. In the same view, they can edit the email signature used when they share files.

![Kontainer Permissions 27](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-27.png?v=1763368897)

Once happy with the access setup, you can go to the user profile and send out the email invitation. From the invitation, the Normal User sets up their password and logs in for the first time.

### Create an Open Portal

With an Open Portal, no login is required. The link takes you straight into the solution.

Customers typically use it to create public portals for external brand guides, a press kit, or an image bank.

It’s also a great way to send out an upload link for a photographer.

An infinite number of users can use an Open Portal, and you can always edit the user access.

To create, go to **Access → Users**, and find the **New User** button in the top right corner.

Select **Open Portal** and fill out the form.

Create the Open Portal and set permissions by:

- Adding the user to a group to inherit access from there
- And/or manually setting individual permissions

**NOTE:** Remember to go through the **[Download Options](#chapter10)** and [**Field Visibility**](#chapter11) settings on the user or group. These are important to ensure users can access files as well as data and download formats. Select settings regarding folder/file sharing and brand section on the user or group profile.

![Kontainer Permissions 28](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-28.png?v=1763368897)

To retrieve the user URL, go to the three-dotted menu on the right-hand side of your user overview.

![Kontainer Permissions 29](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-29.png?v=1763368897)

Click on **Get direct URL**.

Or click on the Open Portal and find the URL from the user profile.

![Kontainer Permissions 30](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-30.png?v=1763368897)

### Create a Shared User

The Shared User is similar to an Open Portal with the addition of a login with **username and password**.

An infinite number of users can use a Shared User, and you can always edit the user access.

To create a **New User**, go to Access → Users, and find the button in the top right corner.

Select Shared User and fill out the form. Create the Shared User and set permissions by:

- Adding the user to a group to inherit access from there
- And/or manually setting individual permissions

**NOTE:** Remember to go through the **[Download Options](#chapter10)** and [**Field Visibility**](#chapter11) settings on the user or group. These are important to ensure users can access files as well as data and download formats. Select settings regarding folder/file sharing and brand section on the user or group profile.

Once you are happy with your setup, you can share the username and password details with as many users as you want.

And/or you can activate a direct URL on the user profile.

![Kontainer Permissions 32](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-32.png?v=1763368897)

To retrieve the user URL, go to the three-dotted menu on the right-hand side of your user overview.

![Kontainer Permissions 33](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-33.png?v=1763368897)

Click on **Get direct URL**.

Or click on the Direct User and find the URL from the user profile.

![Kontainer Permissions 34](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-34.png?v=1763368897)

### Add Users to Groups

When you add users to a group, they inherit the group's permissions. This makes it quick to add new users and ensure they have the appropriate access.

The user can be a member of more than one group. Additionally, you can grant individual permission.

### Create Single-Sign-On Users (SSO)

**Premium+ feature**

Set up users in Kontainer via SSO to create a secure and seamless experience for your internal users.

We have a standard setup for multiple providers, e.g., Microsoft Entra ID/Azure, AD FS, Google, Okta, Abraxas, etc.\
 [**Get in touch for other setups**](mailto:js@kontainer.com?subject=SSO%20Enquiry).

We create a ‘’Trust’’ between your AD groups (managed by your IT) and Kontainer. This means the user will automatically be created and assigned predetermined groups when they log in for the first time. Like any other group in Kontainer, you can manage access settings on an ongoing basis. The settings include:

- Folder access
- Download options
- Field visibility

You can read more about settings in the respective sections of this guide.

To keep your user list manageable, you can determine rules that will deactivate or delete users who have not been logged in for a certain amount of time, like 2, 4 or 6 months. If a user logs in again after being auto-deleted, their user is simply reactivated.

In addition to SSO users, you can manually add other users and groups.

Get in touch with Jesper Sandberg, **[js@kontainer.com](mailto:js@kontainer.com?subject=SSO%20Enquiry)**, if you are interested in using SSO.

### Edit user type

As circumstances change, you may need to update the user type.

A Normal user can be upgraded to an Administrator, and an Administrator can be downgraded to a Normal user.

Simply go to the three-dotted menu on the right side of your user list, and you will find the option.

![Kontainer Permissions_changing user type](https://helpdesk.kontainer.com/wp-content/uploads/2026/01/Kontainer-DAM-Permissions_changing-user-type-scaled.png?v=1767872624)

### Delegated admin

**Premium+ feature**

Managing access can become time-consuming for larger organizations with many users across teams and locations. In this case, we offer the Delegated Admin option.

A Delegated Admin is a Normal User with the rights to create Normal Users and manage their access.

A Delegated Admin can never give access to anything they can’t access. It is a controlled way of allowing colleagues to manage the access of their teams.

[**Get in touch**](mailto:mail@kontainer.com?subject=Delegated%20Admin%20Enquiry)to learn more.

### Set Expiry Dates

When you create or edit users, you can set an expiry date. At the time of the expiry date, the user will be deactivated. You will find these users in your user list under **Inactive Users**.

To reactivate, go to the three-dotted menu button on the right.

![Kontainer Permissions 36](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-36.png?v=1763368897)

Or click on the user, tick the box **Active** and set a new expiry date, if relevant.

![Kontainer Permissions 37](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-37.png?v=1763368897)

### Impersonate a User

Try the Impersonate feature to check a user's access. In your user list, click on the **three-dotted menu** on the right and select **Impersonate.**

![Kontainer Permissions 38](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-38.png?v=1763368897)

You are logged out of your admin account when you impersonate another user. To get back in, log out and then in again.

**NOTE:** No passwords will be compromised, as you will never be prompted to enter passwords.

---

## USER LANDING PAGES/FOLDERS

Where a user lands when they enter the platform is important. The first folder/page they see might need custom text or design to introduce the user to your platform. See our guide on how to **[Make Custom Landing Pages here](https://helpdesk.kontainer.com/article/custom-landing-pages/)**.

![Kontainer Permissions 39](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-39.png?v=1763368897)

If a user has access to any of your main folders, their landing page will be the same as yours (your root folder, we call it).

If a user only has access to subfolders, the outermost layer will become their landing page. There is an exception with Open Portals and Shared User.

### Change Landing Page on Links

You can change the landing page for an **Open Portal** and **Shared Users**. The access/user is still the same, but the folder/page they land in is changed. Typical uses include:

- Product launch
- Press release
- Link for a newsletter

To get the link, open the information section to the right and then the **Direct URL** section. Select the user you want, and a unique URL will appear.

![Kontainer Permissions 40](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-40.png?v=1763368897)

Copy the URL and insert it in an email, news story or other.

### User Statistics

Keep an eye on how often users log in and what they download under **Access → Statistics**.

If user statistics is important to you, be aware that shared users (Open Portal and Shared User) will not give you exact data on who is downloading files. The data collected is per user.

Filter and download data by

- Folder
- User
- Date Range

![Kontainer Permissions 41](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-41.png?v=1763368897)

To view download statistics on a specific asset via the info bar to the right. You open the information bar from the **three-dotted More** menu on the image or in the drop-down banner at the top. Here you select **View Details**.

![Kontainer Permissions 42](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-42.png?v=1763368897)

---

## REGISTER FORM

**Pro+ feature**

You can allow users to self-register by activating the feature on your Kontainer.

![Kontainer Permissions 43](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-43.png?v=1763368897)

Go to **Settings → User Registrations** and enable user registrations.

You need to define to which user group self-registered users will belong. And whether they are automatically added or manually after approval.

You can edit the text in the register email notifications. Be aware not to change the %automated% text.

![Kontainer Permissions 44](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-44.png?v=1763368897)

---

## UPDATE ACCESS

You will need to adjust access from time to time. Go to the Access menu or click on the Permissions button in the folder to edit.

### Edit Folder Permission Locally

After the initial setup, you can always edit the group and user access to your folders.

**NOTE:** By default, access is inherited by subfolders. Also, newly created subfolders will inherit access rights unless manually changed.

### Release Dates

**Premium+ feature**

We have that option available if you need to set specific release dates for folders/content.

A new option will appear in the folder Permission feature. Here you can manage the release dates for different groups.

![Kontainer Permissions 45](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-45.png?v=1763368897)

[**Get in touch**](mailto:support@kontainer.com?subject=Release%20date%20function%20enquiry) if you want that activated or included in your plan.

---

## SHARE FUNCTION

To share files via a simple share link or email, use Kontainer’s Share function. Select files or folders and click on the Share button.

![Kontainer Permissions 46](https://helpdesk.kontainer.com/wp-content/uploads/2023/02/Image-46.png?v=1763368897)

Be aware that download and user statistics do not cover the share function.

You can read more about the share function **[in our guide here](https://helpdesk.kontainer.com/article/share-files-and-folders/)**.

## –––

Thank you for visiting the Permissions guide here on the Kontainer helpdesk!

Please let us know how you get on, and don't hesitate to [***contact customer support***](mailto:support@kontainer.com) if you have any further questions.

## Other languages

- [Deutsch](https://helpdesk.kontainer.com/de/article/berechtigungen/index.md)

## Related articles

- [Semantic Search for DAM](https://helpdesk.kontainer.com/article/semantic-search-for-dam/index.md): Set up Kontainer's semantic search for DAM — the DAM Search Agent — so users can search by describing an asset instead of guessing keywords. Covers choosing an AI provider, the setup checklist and how…
- [Strapi Integration Guide](https://helpdesk.kontainer.com/article/strapi-integration-guide/index.md): With Kontainer's Strapi integration, you can easily insert images, videos, and files directly from your DAM into Strapi's admin panel — without manually downloading and uploading.
- [Multi-Brand Guide](https://helpdesk.kontainer.com/article/multi-brand-guide/index.md): The Multi-Brand feature allows you to create and manage multiple branded experiences within a single Kontainer account. Each brand can have its own logo, colors, fonts, styling, and login experience,…
- [Shopify Integration Guide](https://helpdesk.kontainer.com/article/shopify-integration-guide/index.md): The integration allows you to manage your product data, images, and other digital assets in Kontainer, and synchronize them directly to your Shopify store. This ensures consistent product information…
