Users, roles & permissions
Tenant administrators manage access in PIM under Settings → Users & roles (exact menu labels may vary by tenant version).
Concepts
| Term | Meaning |
|---|---|
| User | Person who signs in with email + password (or SSO when enabled) |
| Role | Named bundle of permissions (e.g. Catalog Editor, DAM Admin) |
| Permission | Fine-grained action such as viewing or editing products, assets, or agents |
Users receive one or more roles per tenant. Permissions are the union of all assigned roles.
Common roles
| Role pattern | Typical access |
|---|---|
| Viewer | Read products, categories, assets |
| Catalog editor | Create/edit products and attributes |
| DAM admin | Manage folders and uploads |
| Integration operator | Connections and syndication jobs |
| Agent operator | Run and approve agent proposals |
| Tenant admin | Users, roles, tenant settings |
Your tenant may use custom role names; ask your CataZenta contact for a permission matrix export.
Service accounts (API & MCP)
For integrations, create a service account with scoped permissions instead of sharing a human password.
Brand Hub & mobile
Users need appropriate product read permissions plus Brand Hub access enabled for the tenant. If mobile sign-in fails, verify the user is assigned to the correct tenant and role.
Security overview
Platform security practices (encryption, tenancy isolation): Security
API reference
Programmatic role management: IAM API reference (when exposed for your tenant)