---
title: Assigning permissions to media libraries
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

The permissions model built around the **Media libraries** application allows you to configure access to the application and the media libraries defined within. See the following sections for details:

- [Creating a role to manage media libraries](#creating-a-role-to-manage-media-libraries) – the media libraries security model is mainly based on [role](https://docs.kentico.com/13/managing-users/role-management.md) assignments. [Users](https://docs.kentico.com/13/managing-users/user-management.md) are authorized to perform certain actions based on the roles assigned to them. This section shows how to create a role in the system and assign users to it.
- [Configuring permissions for the Media libraries application](#configuring-permissions-for-the-media-libraries-application) – shows how to assign permissions for the **Media libraries** application to roles.
- [Configuring media library permissions](#configuring-media-library-permissions) – shows how to configure permissions for separate media libraries.

## Creating a role to manage media libraries

This section explains how to create a role in the system and assign users to it. If you already know how to create roles in the system, you can skip this section and move to [Configuring permissions for the Media libraries application](#configuring-permissions-for-the-media-libraries-application).

1. Open the **Roles** application.
2. Click **New role**.
3. Fill in the **Role display name** and **Role description** fields, for example:

   ![Creating a new role](https://docs.kentico.com/docsassets/13/assigning-permissions-to-media-libraries/creating_media_library_admin_role.png "Creating a new role")
4. **Save** the role.

The **General** tab of the role that you just created opens.

### Assigning users to a role

1. Switch to the Users tab.
2. Click on **Add users**. The **Select users** dialog opens.
3. Select the check box next to the users that you wish to assign.
4. **Save** **& Close** the dialog.

Now that you created the role and assigned users to it, you can set its permissions.

![Users assigned to a role](https://docs.kentico.com/docsassets/13/assigning-permissions-to-media-libraries/users_assigned_to_role.png "Users assigned to a role")

## Configuring permissions for the Media libraries application

This section explains how to configure permissions related to the **Media libraries** application.

1. Open the **Permissions** application.
2. In the **Site** drop-down list, select the site for which you wish to configure media library permissions.
3. In **Permissions for** select **Module** and **Media libraries**.
4. Grant required permissions to the site's roles.
   - **Read** – allows users to access the **Media libraries** application and view the content of media libraries.
   - **Manage** – allows users to create, configure, and delete media libraries. Also allows them to manipulate media files in all of the site's media libraries.
   - **Destroy** – allows users to delete media file version history, provided [object versioning](https://docs.kentico.com/13/configuring-xperience/managing-sites/configuring-settings-for-sites/settings-versioning-synchronization/settings-object-versioning.md) for media files is enabled.

> **Note:** **Permissions for individual media libraries**
>
> Module-level permissions grant access to the _Media libraries_ application and all media libraries it contains. If you wish to provide a more restrictive permissions model for your site, individual media libraries allow you to [configure permissions](#configuring-media-library-permissions) per file operation. Note, however, that all roles need to at least have the **Read** permission to access the _Media libraries_ application.

## Configuring media library permissions

Media library permissions offer a more granular alternative to global _Media library_ [application-level permissions](#configuring-permissions-for-the-media-libraries-application) (granted via the **Permissions** application). For example, if a role has the **Manage** permission granted to it via the _Permissions_ application, all users belonging to that role can freely manipulate media files across all media libraries on a given site. This can be offset by configuring permissions for specific file operations (create, update, delete) per media library instead.

1. Open the **Media libraries** application.
2. **Edit** () the Media library you wish to configure.
3. Switch to the **Security** tab.
4. Set permissions for the _Create file_, _Create folder_, _Delete file_, _Delete folder_, _Modify file_, _Modify folder_, and _See library content_ actions according to your requirements.
   - **Nobody** – no one but global administrators or users with the **Manage** permission for the _Media libraries_ module can perform the corresponding action. By default, all newly created media libraries use this permission level for every action.
   - **All users** – everyone can perform the corresponding action.
   - **Authenticated users** – all signed-in users can perform the corresponding action.
   - **Authorized roles** – users belonging to allowed roles or with the **Manage** permission for the _Media libraries_ module can perform the corresponding action. A list of all roles available for the current site is listed in a separate matrix underneath.

     ![Configuring media library permissions](https://docs.kentico.com/docsassets/13/assigning-permissions-to-media-libraries/modifying_media_library_security.png "Configuring media library permissions")

## Permissions Grid

The following table shows which permissions need to be assigned to allow users to perform particular actions. Users with the Global administrator [privilege level](https://docs.kentico.com/13/managing-users/user-management.md) can perform all of these actions for all media libraries on the site.

| Action/Permission                                                                                                                                                                        |      |        |    | File   | Folder |        |        |        |        |                     |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---- | ------ | -- | ------ | ------ | ------ | ------ | ------ | ------ | ------------------- |
|                                                                                                                                                                                          | Read | Manage |    | Create | Delete | Modify | Create | Delete | Modify | See library content |
| Files                                                                                                                                                                                    |      |        |    |        |        |        |        |        |        |                     |
| upload or import                                                                                                                                                                         |      |        | or |        |        |        |        |        |        |                     |
| modify file properties                                                                                                                                                                   |      |        | or |        |        |        |        |        |        |                     |
| delete                                                                                                                                                                                   |      |        | or |        |        |        |        |        |        |                     |
| copy                                                                                                                                                                                     |      |        | or |        |        |        |        |        |        |                     |
| move                                                                                                                                                                                     |      |        | or |        |        |        |        |        |        |                     |
| Folders                                                                                                                                                                                  |      |        |    |        |        |        |        |        |        |                     |
| create                                                                                                                                                                                   |      |        | or |        |        |        |        |        |        |                     |
| rename                                                                                                                                                                                   |      |        | or |        |        |        |        |        |        |                     |
| delete                                                                                                                                                                                   |      |        | or |        |        |        |        |        |        |                     |
| copy                                                                                                                                                                                     |      |        | or |        |        |        |        |        |        |                     |
| move                                                                                                                                                                                     |      |        | or |        |        |        |        |        |        |                     |
| Administration                                                                                                                                                                           |      |        |    |        |        |        |        |        |        |                     |
| Access the Media library application                                                                                                                                                     |      |        | or |        |        |        |        |        |        |                     |
| Modify media library properties and content                                                                                                                                              |      |        | or |        |        |        |        |        |        |                     |
| Live site                                                                                                                                                                                |      |        |    |        |        |        |        |        |        |                     |
| See and browse library content<br>([displayed using the appropriate API](https://docs.kentico.com/13/developing-websites/retrieving-content/displaying-content-from-media-libraries.md)) |      |        | or |        |        |        |        |        |        |                     |

> **Note:** By default, the Xperience API does not check the **See library content** permission for visitors on the live site. To force the system to check this permission, you need to enable the **Check file permissions**setting in the **Settings** application (**Content** -> **Media** category).
