> ## Documentation Index
> This page is part of the Cloudinary Assets product. Fetch the complete documentation index for Cloudinary Assets at: https://cloudinary.com/documentation/llms-cloudinary-assets.txt?referrer=docpage and then use it to discover all relevant pages before exploring further.
> If your task extends beyond this product, fetch the top-level index covering all Cloudinary products and topics at: https://cloudinary.com/documentation/llms.txt?referrer=docpage

# Roles and permissions (video tutorial)

## Overview

Watch this video tutorial for a non-technical introduction to roles and permissions in Cloudinary. Learn how roles control what users, groups, and API keys can do, how account, product environment, global, and content roles differ, and how to assign roles using access bundles or individual role assignments.

This tutorial is for administrators and anyone else who manages access to Cloudinary. No development background is required.

## Video tutorial

  This video is brought to you by Cloudinary's video player - embed your own!Use the controls to set the playback speed, navigate to chapters of interest and select subtitles in your preferred language.
{videoTranscript:publicId=training/permissions_intro_non_dev}

## Tutorial contents
This tutorial presents the following topics. Click a timestamp to jump to that part of the video.### Why roles and permissions matter
{table:class=tutorial-bullets}|  |
| --- | --- |
| | As your team grows, different people need different levels of access. A designer may need to find and use approved assets, a developer may need to create transformations, configure upload presets, or set up webhook notifications, and an administrator may need to manage users, settings, and access across the product environment. |

### Roles, principals, and role types
{table:class=tutorial-bullets}|  |
| --- | --- |
| | Roles bring together the permissions needed for each responsibility. Assign roles to users or groups to control what people can do in the Console, or to API keys to control what's allowed programmatically. All accounts can use predefined [system roles](dam_admin_system_roles_permissions#system_roles), and Enterprise customers can also create [custom roles](dam_admin_role_management#manage_roles_with_granular_permissions) with the permissions that match how their organization works. |

### Account and product environment roles
{table:class=tutorial-bullets}|  |
| --- | --- |
| | Account roles control access across the account, such as who can manage account-wide users, groups, or reports. Product environment roles control access to assets and to the features used to manage and deliver them within a product environment. A role includes either account permissions or product environment permissions, not both, but you can assign someone roles from both categories. |

### Global and content roles
{table:class=tutorial-bullets}|  |
| --- | --- |
| | Product environment roles are further divided into global roles and content roles. Global roles control access to features and settings across the product environment, such as moderating assets in all folders or configuring upload presets. Content roles ([folder and collection roles](dam_admin_permissions#key_role_attributes)) control access to specific folders or collections. To understand what a role allows, click **View** to see its permissions. |

### Assigning roles to users
{table:class=tutorial-bullets}|  |
| --- | --- |
| | When you add a user, you can assign an [access bundle](dam_admin_permissions#access_bundles), which pairs account and product environment roles at the same level, or assign roles individually. Each user can have one bundle. Access is additive, so a user with several roles receives all the permissions included in each of them. If you have multiple product environments, you can assign a user different roles in each one, for example Master Admin in staging but only Admin in production. |

### Assigning roles to groups
{table:class=tutorial-bullets}|  |
| --- | --- |
| | You can also assign roles to groups, so everyone in the group receives the permissions included in those roles. See [Create and manage groups](dam_admin_role_management#create_and_manage_groups). |

### Giving access to specific folders and collections
{table:class=tutorial-bullets}|  |
| --- | --- |
| | To give users access to specific assets in the Media Library based on their folders and collections, first assign the **Media Library User** role, then add content roles from the folder or collection you want to share. See [Assign folder and collection roles to users and groups](dam_admin_role_management#assign_folder_and_collection_roles_to_users_and_groups). |

### Assigning roles to API keys
{table:class=tutorial-bullets}|  |
| --- | --- |
| | Product environment API keys have two basic roles: **Master Admin**, which provides access to all Upload and Admin API endpoints, and **Media Library User**, which limits actions to assets in shared folders. On Enterprise plans, you can create granular API key roles, for example one that allows uploading but not deleting assets. After assigning a role, share the API key with the appropriate developer. Account management keys (Enterprise only), used for account provisioning and managing roles and permissions, can also have roles. See [Assign roles to API keys](dam_admin_role_management#assign_roles_to_api_keys). |

### Summary
{table:class=tutorial-bullets}|  |
| --- | --- |
| | With roles and permissions, you can give people and integrations the access they need while keeping control of the rest. |

## Keep learning

> **READING**:
>
> * Read the [Roles and permissions overview](dam_admin_permissions) for the key concepts behind role types and access bundles.

> * Browse the full list of [system roles and permissions](dam_admin_system_roles_permissions).

> * Follow step-by-step instructions to [create custom roles](dam_admin_role_management#manage_roles_with_granular_permissions) and [assign roles](dam_admin_role_management#assign_roles) to users, groups, and API keys.

#### If you like this, you might also like...

[Asset structure - Folders](assets_onboarding_folders_tutorial)

Utilize folders for efficient asset organization and searchability

[Sharing assets - Chapter 2](assets_onboarding_sharing_assets2_tutorial)

Share assets via folders and collections.

[Dashboard and Reports](assets_onboarding_dashboard_reports_tutorial)

Leverage the dashboard and reporting features within Cloudinary

&nbsp;

&nbsp;Check out the Cloudinary Academy for free self-paced Cloudinary courses on a variety of developer or DAM topics, or register for formal instructor-led courses, either virtual or on-site.
&nbsp;