Users can be assigned roles to allow for the easy management of usage privileges on your Canto tenant. Canto provides you with three preset roles – Administrators, Contributors, and Consumers – and the option to create up to three custom roles to meet your specific needs.
The number of seats available for each role is determined by your account plan. Administrators, Contributors and custom roles are considered power users and share their seat allocation, while Consumers and guests have a separate pool of seats. Should you require additional seats, please reach out to your account manager for assistance.
What is the difference between roles and groups?
While roles and groups can work in tandem to create efficient workflows, they are distinct systems.
A role defines the actions a user is able to perform in Canto, such as approving content, managing portals, or view certain types of documents. Each user can have only a single role, and if they require different permissions, they must be assigned a different role.
Groups are used to manage access restrictions. When the access to an asset, portal, or workspace is restricted, it is still possible to grant access to individual users or entire user groups by adding them to the appropriate access list. Unlike roles, users can be part of multiple groups at once.
The following example illustrates how groups and roles interact.
Example: User A is assigned the default Contributor role. User B is assigned a custom role based on the Consumer profile, but with the exception that they may not view PDF files. Both need to access a PDF asset. However, this asset is inside a restricted album, which can only be accessed by Group 1. As long as User A and User B are not part of Group 1, they will not be able to access the restricted album, regardless of the permissions granted by their role. Even if they are added to Group 1, User B would still be unable to view the PDF, as their custom role does not include the ability to do so. In order to fully access the asset, User B must not only be a member of Group 1 but also have their current role modified to include the ability to view PDFs. Alternatively, their role could also be changed to Contributor, giving them the same permissions and privileges as User A. |
Role Privileges
Canto enables you to customize user roles to fit your business needs. However, as each role in Canto is designed for a specific use-case, not all privileges are available for every role. The sections below offer a quick overview of each role and its privileges.
To learn details about each privilege, please visit the article "User privileges index".
To learn how to adjust the privileges of a role, please visit the article "How to: Manage user roles".
Administrators
The role of Administrator is the most powerful role available in Canto. Administrators are not only able to access a variety of reports about the inner workings and activity on a tenant, but are also able to change settings, manage users and groups, and have full access to restricted items. The privileges of an Administrator cannot be revoked.
Content | Viewing | Sharing | Advanced |
|
|
|
|
Contributors
The role of contributor comes with the ability to upload, share, and manage assets. Additionally, Contributors can be granted limited access to the settings of a tenant, further enabling them to manage portals, upload links, social media connections, and cloud services.
Content | Viewing | Sharing | Advanced |
|
|
|
|
Consumers
The role of Consumer serves as a view-only access to your tenant. Consumers are unable to upload, edit, or manage content, but are still able to download, share, and comment on assets. Their visibility is limited to assets marked as "Approved", and they are unable to remove the watermark from assets when Digital Rights Management is enabled. To learn more about Approval status and watermarks, please visit the articles "Approval Status Options" and "Apply Watermarks - for Images and Videos".
Content | Viewing | Sharing | Advanced |
|
|
|
|
Custom Roles
In addition to the standard roles, each Canto tenant can support up to three custom roles. Custom roles can be named freely, and their privileges can be assembled from all options available to the Contributor and Consumer roles.
Content | Viewing | Sharing | Advanced |
|
|
|
|
Video Tutorial: Understanding different user types in Canto
The below video contains a summary of the roles defined above, and briefly touches on how to assign a role to a user. For more details on role management, please visit the article "How to: Manage user roles".