Skip to main content

Users, roles & permissions

Tenant administrators manage access in PIM under Settings → Users & roles (exact menu labels may vary by tenant version).

Concepts

TermMeaning
UserPerson who signs in with email + password (or SSO when enabled)
RoleNamed bundle of permissions (e.g. Catalog Editor, DAM Admin)
PermissionFine-grained action such as viewing or editing products, assets, or agents

Users receive one or more roles per tenant. Permissions are the union of all assigned roles.

Common roles

Role patternTypical access
ViewerRead products, categories, assets
Catalog editorCreate/edit products and attributes
DAM adminManage folders and uploads
Integration operatorConnections and syndication jobs
Agent operatorRun and approve agent proposals
Tenant adminUsers, roles, tenant settings

Your tenant may use custom role names; ask your CataZenta contact for a permission matrix export.

Service accounts (API & MCP)

For integrations, create a service account with scoped permissions instead of sharing a human password.

Service account recipe

Brand Hub & mobile

Users need appropriate product read permissions plus Brand Hub access enabled for the tenant. If mobile sign-in fails, verify the user is assigned to the correct tenant and role.

Security overview

Platform security practices (encryption, tenancy isolation): Security

API reference

Programmatic role management: IAM API reference (when exposed for your tenant)