---
title: "User audit, roles, and asset security"
date: "2026-06-29T07:59:18+00:00"
summary: "Optimize Acquia DAM security with a full user audit, role management, and asset access controls to keep your system clean and secure."
image:
type: "page"
url: "/acquia-dam/user-audit-roles-and-asset-security"
id: "bdc90e9d-a98d-4c6b-b26a-b5ea7dd53b47"
---

Table of contents will be added

In Acquia DAM (Widen), security is controlled by the following closely related configurations:

*   Roles
*   Asset Groups
*   Upload Profiles

Map Users to Roles, Roles to Asset Groups, and Asset Groups to Upload Profiles.

This page provides information about how to optimize users, roles, and security in Acquia DAM (Widen).

User management
---------------

This section provides information on methods to audit users and optimize your user registration process.

Use the following steps:

1.  [Define your users and user governance](#define-users-user-governance)
2.  [Audit current users in your DAM](#audit-current-users)
3.  [Define and review your user registration process](#define-review-user-registration-process)

### Define your users and user governance

Define your DAM users by asking questions such as:

*   Which assets should the user have access to?
*   How and where will they access those assets?
*   What should they be able to do with the assets they access?

Define your DAM user governance by asking questions such as:

*   Who will manage or admin the DAM? 
*   Who are your superusers? Influencers? Decision makers?
*   What departments use digital assets? 
*   Do external parties such as distributors, partners, or agencies require access to assets? 
    
    These groups frequently are contributors to the DAM. They upload assets using upload profiles and roles specifically configured to control DAM access and experiences.
    
*   What are your definitions of active and inactive users? How often must users log in to the DAM to remain active, weekly, monthly, or yearly?

Define your DAM user types by asking questions such as:

*   Which assets should these users have access to?
*   How and where will they access those assets?
*   What should they be able to do with the assets they access?

Document the answers to these questions. For help with organizing your answers to these questions, visit [Acquia DAM Configurations mapping](https://docs.google.com/spreadsheets/d/1uT01k0eHeIbFx3XkTcV2ywnvGnVAtWlnoMR9OCEttuU/edit?pli=1&gid=2117765835#gid=2117765835).

### Audit current users in your DAM

Apply the governance that you created when you evaluated the activity of users within your DAM, specifically the definitions for user types and login frequency. For more information, visit [Can I edit default user settings?](/acquia-dam/can-i-edit-default-user-settings "Can I edit default user settings?") 

If this is your first user audit in at least 12 months, follow these steps in the Admin module:

1.  Navigate to **User Settings** > **User Administration**.
2.  Sort the view by Logins, Last Logins, or both the columns to identify your low-activity users. 
    
    You can also export your user list to create a spreadsheet. The export includes details about your DAM users, including their roles, last login dates, and login frequencies. For instructions on how to do an export, visit [How do I add users to my site and expire users?](/acquia-dam/how-do-i-add-users-my-site-and-expire-users "How do I add users to my site and expire users?").
    
3.  Identify users who have never logged into the DAM or those who have not logged in within the time period you use to define active users.
4.  Send an email to the inactive users with an alert that their DAM account will be deleted in **N** days due to inactivity.
5.  Delete users who do not reply within the timeframe. 

Acquia recommends that you schedule comprehensive user audits at least twice each year. To monitor logins between audits, create an Insights logins report that provides a chart and exportable table that shows user login activity. Use these configurations to build your report:

**Report title**: Active user Insights logins report:

*   Report type: Logins
*   Date range: Last 6 months
*   Group by: User
*   Chart type: Bar
*   Showing: Top 25 or Top 10
    
    It only affects the chart, but not the detailed table under the chart.
    

Consider adding filters for Login Type or User Role for deeper analysis. For more information, visit [How do I create an Insights report?](/acquia-dam/how-do-i-create-insights-report "How do I create an Insights report?").

Note

Insights retains user data even after inactive users are deleted.

### Define and review your user registration process

Consider a typical user journey to access the assets and your DAM system.

*   How do my superusers and general users access the DAM?
*   Should all company employees access the DAM the same way?
*   How do clients, partners, agencies, and external stakeholders access the DAM assets?

Use the login screen from Acquia’s demo DAM, Eudaimonia, for insights about how your users register and access the DAM.

![acquia-dam\_partners-distributors](https://acquia.widen.net/content/pcmybarqzu/web/ee85d_acquia-dam_partners-distributors.png?h=480&v=fa5e7124-bbbe-4104-9f6a-f5e3c629dbe6&itok=P_yplgVc)

*   New users who do not log in with SSO must select **Create Account**.
    
    For instructions, visit [How do I create a Site account?](/acquia-dam/how-do-i-create-site-account "How do I create a site account?").
    
    *   Acquia recommends that DAM Admins create [registration codes](/acquia-dam/what-are-registration-codes "What are registration codes?") to reduce the administrative burden of approving new users and assigning them to roles. Use the template in the linked Registration Codes article to plan communication of registration codes to your new users.
    *   For users who choose to create accounts without entering registration codes, Admins can find and approve registration requests found from bell notifications at the top of the DAM UI and/or from the Pending Registration Requests queue on the Admin dashboard.
        
        For more information, visit:
        
        *   [As an Admin, what alerts or email notifications can I get?](/acquia-dam/admin-what-alerts-or-email-notifications-can-i-get "As an admin, what alerts or email notifications can I get?")
        *   [What user-related tasks are on the Admin dashboard?](/acquia-dam/what-user-related-tasks-are-admin-dashboard "What user-related tasks are on the Admin dashboard?")
    *   When user registration requests are approved, users can visit the **Partners & Distributors** section of the Eudaimonia login screen and log in to the DAM with their email address and password.
        
        Acquia uses this method to allow external parties to access the demo DAM.
        
*   Many customers choose to use an SSO method to create new users and assign user roles.
    
    This is the most efficient method to create users and assign roles.
    
    *   Learn about three options on [how to use SSO to create new users](/node/67776).
    *   Work with an SSO admin from your IT department to help [configure your DAM SSO](/acquia-dam/what-sso-setup-process "What is the SSO setup process?").
    *   For an example of the SSO registration and login experience, click **Eudaimonia Users - Go** on the Acquia demo DAM image.
        
        Acquia Support can add a similar SSO login button to your DAM login page. For instructions, visit [How do I create a case for the Support team?](/acquia-dam/how-do-i-create-case-support-team "How do I create a case for the Support team?").
        
*   If you already use an SSO method, ensure that you do an audit of existing registration codes and SSO configurations to create optimized DAM user registration and login experiences.
    
    *   Review registration codes and delete or disable any codes that are no longer applicable.
    *   Review the registration page requirements.
    *   Review, delete, and update the roles assigned to registration codes and SSO values as needed.
    
    If your DAM is connected to a well-integrated tech ecosystem, many users might find assets without ever accessing the DAM. Ask your Acquia account manager for help with mapping your marketing technology to identify high-value DAM integrations that allow your users to find assets without leaving their most used systems.
    
    For more information about SSO, visit:
    
    *   [How do I set up SAML SSO?](/acquia-dam/how-do-i-set-saml-sso "How do I set up SAML SSO?")
    *   [How do I configure a simple one-way SSO?](/acquia-dam/how-do-i-configure-simple-one-way-sso "How do I configure a simple one-way SSO?")
    *   [How do I integrate Okta with the Acquia DAM?](/acquia-dam/how-do-i-integrate-okta-acquia-dam "How do I integrate Okta with Acquia DAM?")
    *   [Acquia DAM Simple one-way SSO](https://widensimpleonewaysso.docs.apiary.io/#)

#### User governance and cleanse checklist

*   **User Login Audit**:
    *   Define user governance standards.
    *   Assess current users against those standards, active vs. inactive.
    *   Determine to which roles users/departments are assigned and how users are assigned to roles.
    *   Understand how users access and log in to the DAM.
*   **Delete Inactive Users**:
    *   Delete users who do not meet your active user governance standards.
*   **Registration Process Review**:
    *   Review the current registration process.
    *   Review registration codes and delete/disable codes that are no longer applicable.
    *   Review the registration page requirements.
*   **User Related Tasks found on the Admin dashboard in the Admin module**:
    *   Address expired/expiring users.
    *   Manage pending registration requests.
    *   Resolve unapproved orders.
    *   Identify users without roles.

Role management
---------------

Roles are one of the primary configurations that govern DAM and asset security. Each DAM user falls into a role, commonly called user groups in other systems. Roles control how users access assets that are assigned to asset groups. With Acquia DAM, you can create as many roles as you need at no additional cost. For more information, visit [How do I create roles?](/acquia-dam/how-do-i-create-roles "How do I create roles?")

Broadly consider your asset security and the relationship Roles have to Asset Groups and Upload Profiles. Consider the key roles that you need in order to audit, maintain, and document user and role governance. For more information, visit [What are asset groups and how do I create them?](/acquia-dam/what-are-asset-groups-and-how-do-i-create-them "What are asset groups and how do I create them?")

The following list contains general role and permission level templates used by many customer DAMs:

*   **Global/System Administrator**: Oversees overall DAM governance
*   **User Admin**: Manages user accounts and roles
*   **Asset Contributor/Editor**: Uploads assets and maintains metadata
*   **Reviewer/Approver**: Ensures quality and compliance of new and updated assets

You might choose from various Roles configuration strategies such as by region, department, brand, and so on. When you consider what strategy to use, try to incorporate expected permissions into your planning. One goal of optimized DAMs is to clarify roles and permissions and try to avoid too many access levels. Use the [configuration mapping workbook](https://docs.google.com/spreadsheets/d/1uT01k0eHeIbFx3XkTcV2ywnvGnVAtWlnoMR9OCEttuU/edit?gid=2117765835#gid=2117765835) to aid your planning and organization. 

There is no right or wrong amount of roles. However, most Acquia customers use fewer than 25 roles. Common practices observed across the Acquia customer base include:

*   Customers with 50 DAM users, or less: 1-5 roles
*   Customers with 51-100 DAM users: 5-10 roles
*   Customers with 101-500 DAM users: 10-20 roles
*   Customers with 500+ DAM users: 30-45 roles

When you create roles, consider what roles to assign to each user group and what roles to assign to each permission level. Remember that you can use the **Description** field on roles to document permission levels and/or the user groups who share that role’s permissions when you optimize your DAM role structure. For more information, visit [What does each permission mean?](/acquia-dam/what-does-each-permission-mean "What does each permission mean?").

### Insights reporting

This section provides instructions on how to use Insights reporting in combination with your analysis of users assigned to roles.

Navigate to the Insights application and create two reports that provide a high-level analysis of how users within current roles interact with your DAM.

**Report: Logins by role, past 12 months**

Analyze roles that log in most and least frequently:

*   Open a second browser tab and navigate to the Admin application and click **Permission Settings** > **Roles**. Are there Roles in Admin that do not appear on the Logins report? Does that indicate that the Role should be deleted? Or that the users within the Role require DAM enablement?
    
    ![acquia-dam\_login-by-role](https://acquia.widen.net/content/1hblbt2pxr/web/6d9f1_acquia-dam_login-by-role.png?v=9e5e092c-314a-4d87-94a5-c5a0368f3c89)
    

**Report: Asset Views and Downloads** 

Create this report with the User Role filter to further analyze how users within current roles use the DAM.

### Role analysis within the Admin application

Analyze your DAM roles with the following steps:

1.  Navigate to **Admin** > **Permission Settings** > **Roles**.
2.  Look for roles with zero or very few assigned users. 
3.  Determine if those roles can be removed or combined with other roles that share asset permissions. The number next to the roles shows how many users are in the roles.
    
    You can click on that number to edit users individually or in batches or those users from the DAM if you did not delete them during your user audit. Ensure that you check the permissions of the role before you add or remove users. 
    

Resources 

The following are additional resources for DAM Roles:

*   [Recorded Tutorial: DAM Security Structure](https://www.acquiaacademy.com/learn/courses/1485/permission-settings/lessons/9515/dam-security-structure)
    
    Requires free Acquia Academy registration.
    
*   [Recorded Tutorial: Configure Roles](https://www.acquiaacademy.com/learn/courses/1485/permission-settings?hash=a41e4b5f4dfa46560d340f47467a466cf9e99b18&generated_by=23462)
*   [What are role templates?](/acquia-dam/what-are-role-templates "What are role templates?")

Asset group management
----------------------

An [asset group](/acquia-dam/what-are-asset-groups-and-how-do-i-create-them "What are asset groups and how do I create them?") is a combination of assets that share common characteristics and permissions. Users interact with assets based on the roles assigned to [asset group permissions](/node/67606). If an asset is assigned to more than one asset group, asset group permissions are cumulative. 

To do an audit of asset groups, consider the following questions:

*   Are all of the current asset groups still relevant and necessary?
*   Can some asset groups be consolidated or deleted?
*   Are there asset types that are not clearly represented with your asset groups?
*   Do all admins understand the asset groups that are currently used in your DAM? 

When you update and create asset groups, use Flags and Descriptions to clearly document the asset types and related roles with permission to access assets. Use these asset group configurations to present your DAM governance within the DAM.

For more information about how to audit and optimize asset groups, visit [How do I determine roles and asset groups?](/acquia-dam/how-do-i-determine-roles-and-asset-groups "How do I determine roles and asset groups?").

### Upload profiles: Who can add assets to your DAM?

Upload profiles are an important part of your asset workflow and security.

This section provides information about how to determine who can add assets to your DAM.

When you create upload profiles, consider the following questions:

*   Should assets that are uploaded with this upload profile require admin review before they are released?
*   Should assets added with an upload profile automatically create new versions or should detected duplicates move to the conflicted asset queue to be resolved from the Admin dashboard?
    
    For more information, visit [What asset-related tasks are on the Admin dashboard?](/acquia-dam/what-asset-related-tasks-are-admin-dashboard "What asset-related tasks are on the Admin dashboard?")
    
*   When assets are uploaded through profiles, which asset groups should they be added to?
*   Are assets that are uploaded through this profile considered final assets or in-progress assets that require limited access?
*   What additional permissions should users of this upload profile have? Should they be able to view and edit assets after the assets are uploaded to the DAM?

For instructions on how to apply upload profile configurations that achieve the standards and outcomes defined in your optimized DAM governance guide, visit [How do I create upload profiles?](/acquia-dam/how-do-i-create-upload-profiles "How do I create upload profiles?"). For more information about upload profiles, visit [User engagement and asset lifecycle](/acquia-dam/user-engagement-and-asset-lifecycle "User engagement and asset lifecycle").

### Putting the configurations together

The following example provides a general idea of how these configurations relate to each other:

1.  First, register a user account with a second email address to assist with testing configurations. This provides you a separate account to use to impersonate other user roles.
    
    ![acquia-dam\_put-configurations-together](https://acquia.widen.net/content/mrmbwhkjgu/web/300bf_acquia-dam_put-configurations-together.png?w=480&v=9ca2e219-4660-4892-8b91-09731a27e6eb&itok=62neKTwu)
    
2.  Create your permission mapping outside of the DAM, on paper, a whiteboard, or a sketch app. Estimate the number of users in each role and the number of assets per asset group. Use an advanced search in the DAM to discover the number of assets within each asset group. For instructions, visit [How do I perform an advanced search?](/acquia-dam/how-do-i-perform-advanced-search "How do I perform an advanced search?").
    
    ![acquia-dam\_permission-mapping](https://acquia.widen.net/content/glbcx6j8ma/web/34a72_acquia-dam_permission-mapping.png?w=480&v=417c8e85-0e8e-453d-94cb-7a2a9787624b&itok=1IY_4Opn)
    
3.  Map Users to Roles, Roles to Asset Groups, and Asset Groups to Upload Profiles.
    
    ![acquia-dam\_mapping-configurations](https://acquia.widen.net/content/eyfwcaf23q/web/fffe8_acquia-dam_mapping-configurations_0.png?w=480&v=3781b5f2-f284-4d9b-a139-d869e773b24b&itok=7KwOzT7G)
    
4.  Remember that your mapping is specific to your business needs and may require more complexity than is shown in these examples.
    
    ![acquia-dam\_mapping-configurations-2](https://acquia.widen.net/content/6uguxztgyx/web/20ceb_acquia-dam_mapping-configurations-2.png?w=480&v=49bd3d6f-ff7c-4746-acca-5e7192df9bc1&itok=KtmESLh5)
    

For more information, visit [How to audit DAM permissions](https://acquia.widen.net/s/zqxkzbffqp) for a recorded tutorial that guides you through your DAM permissions audit.

### User enablement and feedback

Your DAM is only helpful if your users adopt the system. Customers with the strongest adoption and user engagement employ a variety of methods to assess their user’s DAM experience. This section provides instructions on how to measure DAM interactions and request and handle feedback.

#### Conduct user research with surveys and interviews

Conduct in-person or survey-based interviews to understand user needs and pain points. For examples of questions to ask your users, visit [DAM Survey Questions for Collecting User Feedback](https://www.acquia.com/blog/sample-questions-for-dam-user-feedback-survey).

#### Measure DAM interactions

This section provides methods you can use to measure quantitative and qualitative aspects of DAM interactions to get a better understanding of user satisfaction levels.

*   Quantitative assessment begins with data found in Insights reports, where you analyze user and role logins, popular search terms, and asset interactions like downloads and shares.
*   Qualitative assessment validates and expands upon themes identified in your Insights analysis.
*   Your goal is to understand the DAM interactions (login/access, search experience and results, intuitiveness of the upload and tagging process, and so on) of both frequent and infrequent users.
    *   Ask users how they feel about their interactions with the system.
    *   Are your users confused? Can they find what they need? What prevents them from using the system?

#### Leadership and stakeholder feedback

This section provides methods you can use to evaluate leadership and stakeholder feedback.

*   Understand your organizational leadership and DAM stakeholder expectations. 
*   How will leaders measure the outcomes and performance of the DAM?
*   How will leaders measure the value of your DAM and the return on your DAM investment?
*   How does your DAM connect to your organization’s strategic priorities and vital objectives?
*   What Insights reports can you build to measure your DAM’s contributions to organizational achievement?

#### Use Audits and reviews to expand DAM access

This section helps you understand how to use the information gained to expand DAM access and implement best practices.

*   Review your organization’s structure. Have you, or will you, expand globally? Are there plans to acquire companies? Is a company restructuring on the roadmap?  
*   Will those changes require access and enablement for new users? With what DAM permissions?
*   Create a user onboarding experience to ensure that global users get what they need from the DAM. You may also want to add a 2-minute tutorial and a well-labeled dashboard message at the top of your DAM dashboard.
*   For an example of how you can apply user onboarding and enablement best practices, visit [Crayola’s case study](https://www.acquia.com/resources/customer-stories/crayola).

#### DAM coalition

It is a best practice to have a DAM coalition that meets monthly or quarterly. It could consist of super users, key stakeholders, or other individuals that rely on the DAM for their workflow. This is a way to share updates on feature changes and policy updates and ensures that you stay in touch with the needs of the user base.

### Security and maintenance

The User and Role decisions and updates you have made should reflect and support your organization’s secure management of your content. 

This section provides a list that you can use to assess and advance the maturity of your DAM’s security.

*   Key roles you defined during audit and maintenance (add your own)
    *   System Administrator: Oversees overall DAM governance.
    *   User Admin: Manages user accounts and roles.
    *   Asset Contributor/Editor: Responsible for uploading and maintaining metadata.
    *   Reviewer/Approver: Ensures quality and compliance of new and updated assets.
*   Security recommendations
    *   Audit user permissions at least once each year.
        *   Ensure that only authorized users have access.
            
            [How to audit DAM permissions](https://acquia.widen.net/s/zqxkzbffqp)
            
        *   Turn on Single Sign-On (SSO).
    *   Consider the cost and security benefits of a secure login experience that automates user role assignments.
    *   Review your user list every six months.
        *   Remove users who have not logged in recently or have never logged in.
    *   Review roles and asset groups.
        *   Ensure they remain relevant to your business and are clearly identifiable in the DAM.
    *   Ensure that active registration codes are relevant and consistent with DAM governance.
    *   Require external user referral.
        *   Require new external users to list a contact or referral within the company.
    *   Assign expiration dates to roles created to provide temporary access.
    *   Implement an End-User License Agreement (EULA) that requires all users to agree to the site’s terms and conditions.

### Additional resources

This section provides alternate links to the articles that support DAM security and maintenance as mentioned in this article:

*   [What are the available features and their permissions?](/acquia-dam/what-are-available-features-and-their-permissions "What are the available features and their permissions?")
*   [What does each permission mean?](/acquia-dam/what-does-each-permission-mean "What does each permission mean?")
*   [How do I create an Insights report?](/acquia-dam/how-do-i-create-insights-report "How do I create an Insights report?")
*   [What are asset group permissions?](/acquia-dam/what-are-asset-group-permissions "What are asset group permissions?")
*   [What is the SSO setup process?](/acquia-dam/what-sso-setup-process "What is the SSO setup process?")
*   [How do I manage users through SSO?](/acquia-dam/how-do-i-manage-users-through-sso "How do I manage users through SSO?")
*   [What are Registration Codes?](/acquia-dam/what-are-registration-codes "What are registration codes?")
*   [How do I add users to my site and expire users?](/acquia-dam/how-do-i-add-users-my-site-and-expire-users "How do I add users to my site and expire users?")
*   [Can EULAs be used on my site?](/acquia-dam/can-eulas-be-used-my-site "Can EULAs be used on my site?")
*   [How do I create a site account?](/acquia-dam/how-do-i-create-site-account "How do I create a site account?")
*   [As an Admin, what alerts or email notifications can I get?](/acquia-dam/admin-what-alerts-or-email-notifications-can-i-get "As an admin, what alerts or email notifications can I get?")
*   [What user-related tasks are on the Admin dashboard](/acquia-dam/what-user-related-tasks-are-admin-dashboard "What user-related tasks are on the Admin dashboard?")
*   [Can I edit default user settings?](/acquia-dam/can-i-edit-default-user-settings "Can I edit default user settings?")
*   [What is the SSO setup process?](/acquia-dam/what-sso-setup-process "What is the SSO setup process?")
*   [How do I set up SAML SSO?](/acquia-dam/how-do-i-set-saml-sso "How do I set up SAML SSO?")
*   [How do I configure a simple one-way SSO?](/acquia-dam/how-do-i-configure-simple-one-way-sso "How do I configure a simple one-way SSO?")
*   [How do I integrate Okta with Acquia DAM?](/acquia-dam/how-do-i-integrate-okta-acquia-dam "How do I integrate Okta with Acquia DAM?")
*   [How to audit DAM permissions?](https://acquia.widen.net/s/zqxkzbffqp)
*   [Acquia DAM configuration mapping workbook](https://docs.google.com/spreadsheets/d/1uT01k0eHeIbFx3XkTcV2ywnvGnVAtWlnoMR9OCEttuU/edit?gid=2117765835#gid=2117765835)
*   [What are asset groups and how do I create them?](/acquia-dam/what-are-asset-groups-and-how-do-i-create-them "What are asset groups and how do I create them?")
*   [Recorded Tutorial: DAM Security Structure](https://acquiaacademy.com/learn/courses/1485/permission-settings/lessons/9515/dam-security-structure)
*   [How do I create roles?](/acquia-dam/how-do-i-create-roles "How do I create roles?")
*   [Recorded Tutorial: Configure Roles](https://www.acquiaacademy.com/learn/courses/1485/permission-settings?hash=a41e4b5f4dfa46560d340f47467a466cf9e99b18&generated_by=23462)
*   [What are role templates?](/acquia-dam/what-are-role-templates "What are role templates?")
*   [How do I determine roles and asset groups?](/acquia-dam/how-do-i-determine-roles-and-asset-groups "How do I determine roles and asset groups?")
*   [How do I create upload profiles?](/acquia-dam/how-do-i-create-upload-profiles "How do I create upload profiles?")
*   [DAM Survey Questions for Collecting User Feedback](https://www.acquia.com/blog/sample-questions-for-dam-user-feedback-survey)
*   [Crayola’s case study](https://www.acquia.com/resources/customer-stories/crayola)
*   [What asset-related tasks are on the Admin dashboard?](/acquia-dam/what-asset-related-tasks-are-admin-dashboard "What asset-related tasks are on the Admin dashboard?")