User Roles, Permissions & Sharing Logic
As your network grows, you may need to invite additional team members to help manage content or screens. Citadel uses a secure, role-based system to ensure users only access what they need.
1. User Roles#
There are three distinct levels of authority in a Citadel account:
The Account Owner (Creator)#
This is the single user who originally created the Citadel account.
Capabilities: Full access to every feature, screen, and setting.
Exclusive Right: Only the Owner can access the Billing page to view invoices, update credit cards, or change subscription plans.
Administrators#
Admins are your trusted operational managers.
Capabilities: They can see and do everything the Owner can do (manage screens, delete content, change settings).
Limitation: They cannot see billing information or invoices.
Standard Users#
Users are restricted by default. They start with access to nothing.
Capabilities: They can only view or edit specific items (Screens, Channels, Playlists) that have been explicitly shared with them.
Use Case: Perfect for a "Regional Manager" who should only update screens in their specific city, or a "Graphic Designer" who only needs to upload assets.
2. Sharing & Access Levels#
When you invite a Standard User, you don't just give them a login; you must share specific resources with them. When sharing an item, you choose between two permission levels:
View Only: The user can see the item and its settings but cannot change anything.
Edit: The user can modify the item (e.g., add videos to a playlist, change a screen's schedule).
3. The "Cascade" Rule (Inheritance)#
Citadel’s sharing logic follows a "Top-Down" hierarchy. This is designed to save you time so you don't have to share every single image file individually.
The Rule: If you share a high-level item (like a Playlist or Channel), the user automatically gains View Access to all the items contained within it.
Example Scenario:#
You share a Playlist named "Lobby Loop" with a user and give them Edit access.
Playlist Access: They can now add or remove items from the "Lobby Loop" playlist.
Asset Access (Automatic): The system automatically gives them View Access to every video and image inside that playlist.
Result: They can see the assets to know what is playing, but they cannot delete the original asset files from the library or change the asset's tags.
Key Takeaway: You only need to share the "Container" (Channel or Playlist), and the system handles the permissions for the "Ingredients" (Assets) automatically.
4. How to Invite & Manage Users#
Navigate to the Team & Users tab (found at the top right of the portal).
Click Create New User.
Enter their email address/details and select their Role (Admin or User).
Once a user is created you can begin sharing access to your content!