Content Restrictions

Download as PDF

Overview

Whether you're sharing your images globally or with a selected group, Backstage gives you full control over what media files are published, where, and for whom.

This guide explains the different restriction types and how to configure them step by step to suit your needs:

  • Author/Partner Restrictions: Restrict files from a specific media supplier.
  • Batch Restrictions: Restrict specific files.
  • Metadata Restrictions: Restrict content based on metadata within your files.

A screenshot of the Purchasing Partner setup window showing the Restrictions tab. Navigation elements to access available restrictions are highlighted.
Available Restrictions: Purchasing Partner > Restrictions tab

These restriction features let you control which users can view and download specific media. You can choose from the following options:

  • Time-based restrictions that start and end automatically.
  • Different permission types based on countries, individual accesses, or access groups.
  • Positive (grant) or negative (restrict) rights.
  • A hierarchical structure where higher-priority permissions override lower ones.

Note

Admin-only restriction

If you use the pm_admin_only metadata field to apply the Only for Admins restrictions to your media files, the files will not appear on the website. These files are only visible to system users in Backstage.

Restricted media files are marked with a lock icon (Only for admins) on their thumbnails. Additionally, their Restriction tab displays the message: “This medium is only visible to admins.”

Available restriction features

Set up restrictions when you want to override the standard distribution rights for your media.

Note

Permissions vs Restrictions
To control access precisely, keep permissions general and use restrictions for exceptions.

Permissions grant access by default. You can configure view, download, and watermark permissions individually for every access in the Accesses tab of the user master data. You can assign them directly or inherit them from an access group.

Restrictions are used to limit or block access in specific situations, even when permissions are granted in general.

picturemaxx Backstage offers the following restriction features:

Author/Partner Restrictions

  • Purchasing > Authors or Partners > Tab Restrictions
  • Media Management > Restrictions > Author Restrictions (view only)

You can set restrictions for each of your media suppliers (Authors, Partners, Author Pools), and the restrictions will be in effect for all of their media.

This is a very broad type of restriction, allowing you to centrally control a supplier’s media distribution.

Use this restriction when your restriction should affect all the media files from a certain supplier.

Example use cases:

  • Restrict Agency ABC’s media files, so only users from the United Kingdom can access them.
  • Restrict Agency X’s media files from users in Japan.
  • Restrict Bob Smith, so he is only able to access the media files from Agency X.
  • Restrict the media files of Agency Y, so they’re only available to your “Gold Star” Access Group.

Set up these restrictions in the Purchasing module, in the Restrictions tab of any media supplier. Any restriction you put in place will affect all files that are tagged with that supplier’s Author Code.

A screenshot of Author master data showing the Restrictions tab. Navigation elements to access Authors in the Purchasing module are highlighted.
Author master data > Restrictions tab

Important

Author Restrictions: Always Start Here

Author Restriction is fundamental and should be the first type of restriction you consider and put in place when setting up your Backstage.

Don’t use a Batch Restriction when an Author Restriction will do.

Learn how to set up this feature in Define Author/Partner restriction.

Batch Restrictions

Media Management > Restrictions > Batch Restrictions

You can restrict specific media files using the Batch Restriction feature, controlling rights at the level of individual media files.

Example use cases:

  • You have a series of images that should only be visible to your internal staff.
  • Due to an exclusive sale, a specific image needs to be embargoed in the UK for 30 days, and you want to allow your UK clients to continue to see the image in search results but not be able to download it.
  • You have a specific collection that you want to restrict from your “Scandal Publications” group, since the images can’t be published in those types of magazines.
  • You have a specific batch of files that you only want to make available to a specific customer.

For the setup steps refer to Define Batch restriction.

The screenshot shows the setup window of a batch restriction in the Media Management area.

Batch Restrictions

Metadata Restrictions

Media Management > Restrictions > Metadata Restrictions

The Metadata Restrictions feature allows you to control access to media files based on the metadata they contain. You can create rules that apply automatically when media includes specific metadata Adding or removing the relevant metadata updates the associated permissions in real time.

Example use case:

You want to offer a “Sports” subscription. Add the subscribers into a specific Access Group and then restrict that group to only be able to access images that contain “Sport” in the Supplement Categories field.

Important

We strongly recommend using metadata permissions only when batch permissions are not an option.

Learn how to set up this feature in Define Metadata restrictions.

Tip

Tooltips
When setting up a restriction, if you’re not sure what each setting does, mouse over the question-mark icons to see a brief description.

A screenshot of a Restriction setup window. UI elements to select a restriction type and a tooltip with brief description of a restriction type are shown.n.

Guest users and geographic restrictions

These key points explain how country-based restrictions affect users who access the website without logging in:

  • Country restrictions apply to all users, including guest (not logged‑in) users.
  • For visitors who are not logged in, access depends on the country set in the guest user configuration. The visitor’s real location is not used for guest access.
  • If the guest user’s country is restricted, the content will not be visible to any guest users.
  • To show restricted content to guest users, link the guest user to an allowed country.

Define Author/Partner restriction

Purchasing > Authors > (Author) > Restrictions

Purchasing > Partners > (Partner) > Restrictions

Purchasing > Authors Pools, Syndicates > (Author Pool) > Restrictions (if activated)

When your restriction should affect all the media files from a certain supplier, create an Author/Partner restriction. Here’s how:

Step 1. Create new restriction

  1. Go to Purchasing, select a media supplier’s record, and click the Restrictions tab.
  2. Select Edit Author Restrictions > New.

A screenshot of a Purchasing Partner setup window showing the Restrictions tab. Navigation elements to create a new partner or Author restriction are shown.
Create Partner restriction

Step 2. Configure restriction

  1. Select a restriction type:
    • Geographic Restriction: Restriction based on countries.
    • Access Username Restriction: Restriction based on individual users.
    • Access Group Restriction: Restriction based on groups of users.
  2. Click Next and select the restriction’s rule:Select how the rule should control access. Choose the option that best fits your goal:
    • No Access (negative): Block selected countries, accesses, or access groups from viewing the author’s content.
    • Allow Exclusive Access (positive): Grant access only to the selected countries, accesses, or access groups. Deny access to all others.
    • Allow Access (positive): Grant access to selected countries, accesses, or access groups even if other rules would normally block them from this content.
      • Important: When using this rule, set Priority to 0, so the restriction has a higher priority than other restrictions.
    • Limited Access (use with CAUTION): Allow selected countries, access groups, or accesses to see only the assigned media files and sizes. Deny access to any other media files. However, the assigned media remains visible to all other users as well.
  3. Select a Priority between 0 and 3 (highest priority = 0). In case of a conflict, the rule with the higher priority (lower number) takes effect.
  4. Check the boxes for the media sizes you want the restriction to apply to.
  5. Select the countries, accesses, or access groups you want to apply the rule to, and click Add.
    • The available list (countries, accesses, or access groups) depends on the previously selected restriction type.
  6. If needed, configure a date range restriction.
    • Enter either the number of days or a date range for each selected media size.
  7. In the Comments field, optionally add internal notes about the restriction.
  8. Click Save. If needed, create additional restrictions for this media supplier.

A screenshot of a Partner/Author restrictions setup window showing the Restrictions tab.UI elements to support applying geographic restriction are shown.
Geographic restriction setup

Define Batch Restriction

Media Management > Restrictions > Batch Restrictions

Use batch restrictions when you need to restrict a specific selection of media files.

To configure a new batch restriction, follow these steps:

Step 1. Create new restriction

  1. Go to Media Management > Restrictions > Batch Restrictions.
  2. Select Edit > New.
  3. Enter a descriptive name and make sure the Batch Restriction is Active option is on.
  4. (Optional) Enter internal notes into the Comments field.
  5. Click Save.

A screenshot of a batch restriction setup window. UI elements to name and activate a restriction are shown.
New batch restriction

Step 2. Add the media files you want to restrict

  1. Select Edit Media > Add Media. The Archive Search window opens.
  2. Enter a search term in your Archive and click Search.
  3. Pick the images you want to add to the restriction:
    • For consecutive items: Shift + Click.
    • For non-consecutive items: Ctrl + Click (PC); CMD + Click (Mac)
  4. Click Choose to confirm your selection.
  5. Click Save to add the images to the batch restriction.

A screenshot of a batch restriction setup window. UI elements to add media to the restriction are shown.
Add media to batch restriction

Step 3. Configure restriction

  1. Switch to the Restrictions tab and select Edit Restrictions > New.
  2. Select a restriction type:
    • Geographic Restriction: Restriction based on countries.
    • Access Username Restriction: Restriction based on individual users.
    • Access Group Restriction: Restriction based on groups of users.
  3. Click Next and select the restriction’s rule:
    • No Access (negative): Block selected countries, accesses, or access groups from viewing the associated media files.
    • Allow Exclusive Access (positive): Grant access only to the selected countries, accesses, or access groups. Deny access to all others.
    • Allow Access (positive): Grant access to selected countries, accesses, or access groups even if other rules would normally block them from this content.
      • Important: When using this rule, set Priority to 0, so the restriction has a higher priority than other restrictions.
    • Limited Access (use with CAUTION): Allow selected countries, access groups, or accesses to see only the assigned media files and sizes. Deny access to any other media files. However, the assigned media remains visible to all other users as well.
  4. Select a Priority between 0 and 3 (highest priority = 0). In case of a conflict, the rule with the higher priority (lower number) takes effect.
  5. Check the boxes for the media sizes you want the restriction to apply to.
  6. Select the countries, accesses, or access groups you want to apply the rule to, and click Add.
    • The available list (countries, accesses, or access groups) depends on the previously selected restriction type.
  7. If needed, configure a date range restriction.
    • Enter either the number of days or a date range for each selected media size.
  8. Click Save. If needed, add more rules to this batch restriction.

Important

A media file can only belong to one batch restriction at a time.
If you assign a media file to a new batch restriction, the previous assignment is overwritten. The media will then only be linked to the new batch restriction. However, each batch restriction can include multiple restriction rules.

Other ways to apply a batch restriction

Media Processing > Fast Functions

Fast Functions allow you to add images to a new or existing batch restriction directly within your Media Processing area. First, activate Fast Functions in the Settings of the relevant folder or archive:

  1. In Media Processing tree, right-click a folder or archive to view the context menu.
  2. Select Settings from the context menu.
  3. Open the Fast Functions tab.
  4. From the list of available functions, select Batch Restrictions, and click Add.
  5. Click Save.

A screenshot of folder management window showing the Fast Functions tab. UI elements to enable Batch Restrictions option within the Fast Functions menu of the folder are shown.
Folder context menu: Settings > Fast Functions tab: Add Batch Restrictions

The Fast Functions you activate will then be available from the Fast Functions dropdown and in the Fast Functions panel in the sidebar. Pick the images you want to restrict and then select Batch Restrictions from one of the menus. You can now either add the selected images to an existing batch restriction or create a new one.

A screenshot of a media processing folder showing Fast Functions menu options.
Fast Functions menus

Media Processing > Metadata Entry Form

Make sure the “Restriction” field is activated on your Metadata Entry form. If it’s not, you can change this in Administration > Form Editor > Media Processing.
You can then select existing batch restrictions for each media file directly in the form:

A screenshot of the Restrictions menu in the metadata entry mask in a Media Processing folder showing a dropdown list of available restrictions activated for the folder.
Metadate Entry tab in Media Processing: Restriction field

Media Processing > Replace and Edit

You can add a batch restriction to selected media files with the standard Replace and Edit action:

A screenshot of the Replace and Edit action and its Configure Action dialog in Media Processing. A screenshot of a computer AI-generated content may be incorrect.
Replace and Edit action in Media Processing: Configure Action dialog

Define Metadata Restriction

Use this restriction type when you want to restrict images based on their metadata

Step 1. Create a restriction

  1. Go to Media Management > Restrictions > Metadata Restrictions.
  2. Select Edit > New.
  3. Enter a descriptive name.
  4. Make sure the Metadata Restriction is Active option is on.

A screenshot of a Metadata restriction setup window. UI elements to name and activate metadata restriction are shown.
New metadata restriction: General Data

Step 2. Specify the metadata to which this restriction applies

  1. Select a field from the Database Field dropdown.
  2. Enter the actual metadata in the Value field. The field must contain that exact value.
  3. Click the [+] button to add more conditions.
  4. Click Save.

A screenshot of a Metadata restriction setup window. UI elements to support defining the metadata the restriction should apply to.
New metadata restriction: Define Metadata

Step 3. Configure the restriction

  1. In the Restrictions tab, click Edit Restrictions > New and select a restriction type:
    • Geographic Restriction: Restriction based on countries.
    • Access Username Restriction: Restriction based on individual users.
    • Access Group Restriction: Restriction based on groups of users.
  2. Click Next and select the restriction’s rule:
    • No Access (negative): Block selected countries, accesses, or access groups from the media files that contain the specified metadata.
    • Allow Exclusive Access (positive): Grant access only to the selected countries, accesses, or access groups.
    • Allow Access (positive): Grant access to selected countries, accesses, or access groups even if other rules would normally block them from this content.
      • Important: When using this rule, set Priority to 0, so the restriction has a higher priority than other restrictions.
    • Limited Access (use with CAUTION): Allow selected countries, access groups, or accesses to see only the assigned media files and sizes. Deny access to any other media files. However, the assigned media remains visible to all other users as well.
  3. Select a Priority between 0 and 3 (highest priority = 0). In case of a conflict, the rule with the higher priority (lower number) takes effect.
  4. Make sure to check the boxes for the media sizes you want the rule to apply to.
  5. Select the countries, accesses, or access groups you want to apply the rule to, and click Add.
  6. Click Next.
  7. If you need a date range restriction, configure it.
    • Enter either the number of days or a date range for each selected media size.
  8. Click Save.

Note

Only the selected media sizes will be restricted.

Test the configured restriction

Test your setup using user accounts that match the restriction criteria defined in your rule. Ensure that each test account is correctly configured in the master data (e.g., country, username, or access group).

Test Scenarios by Restriction Type

Geographical Restriction

  • Log in with a German account to verify that German users can view the content (if allowed).
  • Log in with or impersonate an Italian account to confirm the content is blocked for Italian users (if restricted).

Access Username Restriction

  • Log in with a specific user access included in the rule to confirm access behaves as expected.
  • Log in with a user access not included in the rule to verify that restrictions apply correctly.

Access Group Restriction

  • Log in with a user access who belongs to the allowed/restricted access group to validate the rule.
  • Log in with a user from a different group to ensure the rule is enforced properly.

Tip

Impersonate user (secure and credential‑free):

This feature lets Admins temporarily step into a user’s view, without ever needing the user’s credentials. To use it:

  1. Open a user record in Sales, Purchasing, or Administration.
  2. Go to the Accesses tab, open the Manage Access menu, and select Login with this Webgate access or Login with this Backstage access.