Accesses, permissions, and restrictions

Download as PDF

Accesses and access groups

How can I see which customers have view and high‑resolution download permissions, especially when “Override Group Permissions” is enabled?

A: You can check and see user’s permissions at the individual Access level.

Best practice:

For a clearer overview going forward, we recommend using Access Groups instead of overriding permissions on individual users:

  1. Go to Sales > Customers > Access Groups.
  2. Create groups such as “High‑Res Access” and “Low‑Res Access”.
  3. Assign customers to the appropriate group.

If permissions are already overridden:

  1. Go to Sales > Customers and switch the View in the top menu to Accesses.
  2. You’ll see a list of all individual customer usernames.
  3. The Permissions column displays a number that represents each user’s specific permission set. Users with permission values 612, 620, or 748 have high‑res download access.

Do new users need approval before they can log in?

A: By default, administrator needs to review and activate new web users before they can access your content. Alternatively, you can configure the registration settings to automatically approve new users and grant access immediately after they register.

  • Manual review and activation (default)
    By default new registrants require approval before activation. They are listed under Sales > Webgate > New Customers, where you can review their details, make any necessary permission changes, and activate their access before they can log in.
  • Automatic customer creation
    New registrants are automatically moved to the main Customers area after registration and can log in without requiring manual activation.

How do I manually activate new web customers?

A: If your setup requires approval for new users, you need to review and activate each registrant before they can access your content.
When someone signs up through your web registration page:

  • The registrant receives a confirmation email, and you are copied so you’re notified of the new signup.
  • The system sends the user's registration details automatically to Sales > Webgate > New Customers. Here you can review registrants, make any necessary permission changes, activate their access, and then move their data over to your main Customers area.

Note

To automatically approve new registrations and give new users immediate access, contact us at support@picturemaxx.com and we'll help configure your workflow.

To review and activate new web registrants:

  1. Go to Sales > Webgate > New Customers and open the registrant’s record.
  2. In the Access Groups panel, all new customers are assigned to Low-Res permission web access group by default.
    • Users in this group can view and download watermarked preview images only. High‑resolution files are not available.
  3. To grant high‑resolution access, remove the user from the Low‑res web access group and add them to the High‑Res permission web group.
  4. In Access for Searching and Downloading your Media, enable the Access is Active (user can login) option.
  5. Scroll down to the Activation panel:
    • If the user belongs to a company that is not yet a customer, select New Customer.
    • If the user is from a company that is an existing customer, select Add to Existing Master Data. Then, click the […] button and select the existing Master Data record to link the user to that customer.
      • This step prevents duplicate customer records.
  6. Click Save and move to Master Data, and the system will move the Customer’s record to Sales > Customers.

Important

Duplicate customer records can cause data issues, especially when using Backstage for invoicing.

Tip

You can handle records in bulk by multi-selecting them in the overview and choosing Edit > Batch Process.


Can I move a Purchasing record to Sales, or the other way around?

A: No. You can only move master data and access records within the same area and not between Purchasing and Sales.
This is because Author profiles and Customer/Partner profiles work differently. The Access rights are set during registration based on whether Sales or Purchasing is selected.

What can you do instead:

  • Delete the existing record and create a new one in the correct area.
    Example: delete the record in Sales > Partners and recreate it in Purchasing > Authors
  • Ask the user to register again and choose the correct area.

How do I get rid of duplicate customer records?

A: You can use the Move feature to merge duplicates by moving contacts and access records from one record to another.

How to do it:

  1. Open one of the duplicate records and go to the Accesses tab.
  2. Select Manage Access > Move Access.
  3. Choose the Master Data record you want to keep.
  4. Select Move Contact Person.
  5. Select Move Statistics.
  6. Click Choose to complete the move.

The contacts, accesses, and statistics will be transferred to the selected record, allowing you to safely remove the duplicate.


Why does Backstage log me out? Can I stay logged in indefinitely?

A: Backstage has a session timeout that logs you out automatically after 90 minutes of inactivity to protect your account.
This is a standard security measure based on your browser session (cookies). Staying logged in indefinitely isn’t supported or recommended for security reasons.


When I delete a Customer, are the related Contacts and Accesses deleted too?

A: When you delete a Customer, Accesses and Contacts are handled differently.
One Contact can belong to multiple Customers, but Accesses are always Customer‑specific.

  • Deleting a Customer removes its Accesses but keeps the Contacts.
  • Deleting a Contact does not remove any Accesses.

Restrictions

How do I restrict users who aren't logged in (guests) from accessing an author's media files?

A: To restrict unlogged guest users from accessing all images of a specific author or partner:

  1. Go to Purchasing > Authors or Partners and open a record you want to restrict.
  2. Switch to the Restrictions tab and select Edit Author Restrictions > New.
  3. Select the Access Username Restriction option and click Next.
  4. In the list of unselected accesses, use Quick Search for Name =  guest user webgate.
  5. Select this record and click Add.
  6. Select the No Access rule and change Priority to 0 (highest).
  7. Click Next and then Save.

How do I allow a photographer to see only their own images on my website?

A: You can grant a photographer access to view only their own images by configuring user permissions accordingly (Access Username Restriction > Limited Access (use with CAUTION).

If the photographer does not yet have login credentials, you’ll need to create them first:

  1. Go to Purchasing > Authors and open the photographer’s record.
  2. Switch to the Accesses tab and select Manage Access > New.
  3. Enter the photographer’s Name and select the Active checkbox.
  4. Enter Username and Password.
  5. Within the Access for Searching and Downloading your Media panel, enable the Webgate option and click Save to display permission options.
  6. Select the relevant Display and Download permissions you want the photographer to have.

Set up the necessary restriction:

  1. In the photographer’s record (Purchasing > Authors), open the Restrictions tab.
  2. Select Edit Author Restrictions > New.
  3. Select Access Username Restriction and click Next.
  4. Under Unselected Accesses, select the photographer’s Access username and click Add.
    • Use Quick Search to find it faster.
  5. Select the rule Limited Access (use with CAUTION).
  6. Click Next and then Save.

How can I make sure that images are only sold in German‑speaking countries (the DACH region)?

A: To restrict image sales to specific countries such as Germany, Austria, and Switzerland (DACH region), you need to set up a geographical copyright restriction.

First, specify whether users should only view the images or also download them in these countries.
Next, set up a geographical copyright restriction accordingly. You can either allow only Germany, Austria, and Switzerland, or block all other countries, both options work.

Make sure the restriction has a high priority so it overrides other settings, and specify whether it applies only to high‑resolution images or to all image sizes.


How can I make sure an photographer’s images are only visible to users in one country?

A: To limit an author or partner's images so only users from a specific country can see them:

  1. Go to Purchasing > Authors or Partners and click into their record.
  2. Switch to the Restrictions tab and select Edit Author Restrictions > New.
  3. Select Geographic Restriction and click Next.
  4. Select Allow Exclusive Access.
  5. Keep the default setting Restriction is not date limited and all image sizes Thumbnail/Preview/High-Res selected.
  6. Select the country that should get access to the author's images and click Add.
  7. Click Save.

Important

Assign offer to photographer so restrictions work correctly

When you create an Offer of the photographer’s images, always select the photographer’s name from the Author dropdown. This ensures that any existing restrictions on the author are correctly applied to the offer.

  • If you select the author:
    Users who are restricted will not see the offer at all.
  • If you do not select the author:
    Restricted users may still see the offer, but only with “no permissions” thumbnails, which can be confusing.

How can I allow a photographer to edit their own images and only give them access to specific metadata fields?

A: To make sure the photographer can manage their content without seeing or modifying restricted metadata fields:

First, create a metadata editing form that includes only the fields the user is allowed to edit.

  1. Go to Administration > Form Editor > Media Processing and select Edit > New.
  2. Enter a Name for the new form and click Save.
  3. Within the Form Configuration panel, add the fields you want this user to be able to access.
    • Make sure to include the “Preview Image” field for reference.

Next, set up the Access username:

  1. Go to Purchasing > Authors and open the photographer's record.
    • If a photographer doesn't have a record yet, create it by selecting Edit > New.
  2. Switch to the Accesses tab and select Manage Access > New.
  3. Enter the photographer's name and select the Active checkbox.
  4. Enter Username and Password.
  5. Within the Access Settings for picturemaxx Backstage panel, select the Limited Access option, and click Save to display related settings.
  6. Select Read and Write permissions for the Media Processing area.
    • Additionally, to allow the user to batch process images, select Batch Process.
  7. Click Save. This will then reveal additional fields.
  8. Within the Available Forms panel, select the new metadata-editing form you just created and click Add.
  9. Within the Available Folders panel, select Archive and click Add. Note: If you want this user to also be able to access specific folders in the Media Processing area, you would also need to add these.
  10. Select the Limit Media Processing Actions checkbox.
    • Select any Actions you want the user to be able to use (such as Replace and Edit) and click Add.
    • If needed, you can additionally add Action Runs.
  11. Click Save.

This will give the user access to your Backstage and only allow them to view and edit their own images.

Tip

Test the setup to verify that permissions and access behave as intended.


How can I force all users to download files via email instead of downloading directly?

A: You can require email‑based downloads by changing the Download Method in each Access Group.
Go to Sales > Access Groups, open an access group, and set the Download Method to Email Download.

Once this is enabled, users in that group will only be able to download via the cart. Individual download buttons will no longer appear in search results, previews, or other areas.

Important

Make sure that Override Group Permissions is not enabled for any access under Download Method & Limits.
When you enable this setting, the access uses its own Download Method & Limits instead of the settings defined by the access group. As a result, the access group's download restrictions may not apply.

To check and edit override settings:

  1. Go to Sales > Customers.
  2. Change the View to Accesses.
  3. Click Filter, select Override Group Permissions – Download Method & Limits (Accesses) in the Field list, leave Filter set to equals (=), and check the Text/Value box. Click Apply.
    This filters the list to show only the access records where the Override Group Permissions setting is enabled in the Download Method & Limits panel.
  4. (Optional) To edit all matching records at once:
    1. Select the access records and choose Edit > Batch Process.
    2. In the Accesses setup window, clear Override Group Permissions in Download Method & Limits, and click Save.
      • The Download Method & Limits section is not displayed, if any selected access in the batch does not have Webgate permission.

This ensures all users follow the email‑download rule defined by their Access Group.


Can I set download limits for each RF size?

A: Download limits apply only to Preview and High‑Res sizes.
If a user has High‑Res download access to your website (instead of purchasing images individually via PayPal), they can download both Preview and High‑Res files from the cart. It’s not possible to set separate download limits for RF cut‑down sizes.
You can control how many times a user can download an image, but you can’t set different limits for different RF sizes.


Why are "no permission" icons showing on my site?

A: When you add a restriction to published images, the restriction goes into effect immediately.

Your website’s search index updates only once per day, usually overnight. Until that update completes, images that were previously unrestricted may temporarily show a “no permission” icon.
After the nightly search index, restricted images will not appear in search results for users who don’t have permission.


Why did I receive an “IP addresses blocked” email?

A: Your system has IP‑blocking enabled to prevent repeated failed login attempts. If too many failed logins occur from the same IP within a configured time period, that IP is automatically blocked.
You can review or unlock blocked IPs under Administration > IP Restrictions > Active IP restrictions.


How can I restrict downloads so a user can only download from a verified IP address?

A: You can set up a positive IP restriction so a user can only download when accessing the system from a registered IP. Follow these steps:

  1. Go to Sales > Customers and open the relevant customer.
  2. Go to the Accesses tab and select the relevant username.
  3. In the Authentication Restrictions section at the bottom, enable Allow access only via selected IP addresses.
  4. Click Save.
  5. Scroll up to the General Data section and locate the Registered with IP Address field. It shows the IP used during the initial registration.
  6. Next to the displayed IP address, click Add Restriction for this IP.
  7. The IP Restriction setup window opens with the fields pre-populated for the selected IP address.
    • Follow the on-screen instructions to adjust the restriction settings as needed.
  8. Click Save.

The user will now only be able to download when accessing the system from that verified IP address.

Using an IP range:
If you want to allow downloads from a range of IP addresses instead of just one, you can’t use wildcards like *. Instead, you must enter the range using CIDR notation, which is.

Base IP address of the network / size of the range 

The number after the slash tells the system how large the IP range is. If you’re not sure what number to use, these common defaults are safe:

  • Use /16 for Class B networks (IP addresses starting with numbers from 128 to 191)
  • Use /24 for Class C networks (IP addresses starting with numbers from 192 to 223)

Examples:

  • 130.132.0.0/16 → allows a larger internal network
  • 192.31.236.0/24 → allows a smaller office‑size network

How do I set up subscriptions?

A: Subscriptions are typically managed using Access Groups.
Create one access group per subscription type (Sales > Customers > Access Groups) and add the relevant users. You can then configure the following options:

  • Content restrictions: Control what content each subscription can access (for example, configure Limited Access options to restrict by metadata, authors, or partners).
  • Download limits: Define how many files each user can download within a time period. Set a download limit directly within each access group, or specify download limits on the individual access usernames by selecting Override Group Permissions. Limits apply per user, not per customer (multiple users can’t share a download limit).
  • Access duration: Set user access to automatically expire for time‑limited subscriptions or trials.
  • Download History (optional): Add a page where users can see what they’ve downloaded within the subscription time period. Add the page under Web > Page Elements > Navigation with the Download Overview template.
    Note: It’s a page template, not an article template.
  • Sales Reports (available for Finance users): Invoice subscription downloads to include them in sales reports.

How do I invoice subscription downloads

A: To include subscription downloads in sales reports, invoice each download as a media item.
Only media items (actual images/files) generate royalties and appear in sales reports. Standalone Items created under Finance > Settings > Items (for example, a “subscription product”) do not generate royalties on their own.

Option 1: Invoice after the subscription period

  1. After the subscription period has ended, create an invoice and switch to the Transfer tab within the invoice.
  2. Transfer the customer’s downloads to the invoice using the “Take over all marked downloads as media items” option.
  3. Switch to the Edit tab of the invoice, multi-select the transferred items, and use Edit Items > Batch Processing to either:
    • Assign a price for each download (subscription price ÷ number of downloads), or
    • Spread the total subscription price evenly across all downloads (Distribute a pro-rated amount).
  4. You can then post the invoice.

Option 2: Pre‑bill the subscription
To bill the customer upfront:

  1. Create an invoice for a standalone subscription item, but do not post it yet.
  2. When the subscription period ends, open the invoice and go to the Transfer tab.
  3. Transfer the customer’s downloads into the invoice using the “Take over all marked downloads as media items” option.
  4. Switch to the Edit tab of the invoice, multi-select the transferred items, and use Edit Items > Batch Processing to either:
    • Assign a price per download (subscription price ÷ number of downloads), or
    • Spread the total subscription price evenly across all downloads (Distribute a pro-rated amount).
  5. You can then remove the standalone subscription item if desired and post the invoice.

What has the highest priority: a Batch Restriction, an Author Restriction, or a Metadata Restriction?

A: Batch Restrictions and Metadata Restrictions usually have higher priority than Author Restrictions.

When more than one restriction applies to an image, the restriction with the highest priority (lowest number) takes effect. You can change the priority of any restriction if needed.

By default, Batch and Metadata Restrictions override Author Restrictions:

  • Author Restrictions have priority 3
  • Batch Restrictions and Metadata Restrictions have priority 2

Important

If priorities are the same

If two or more restrictions have the same priority, a “No Access” restriction always wins over other types.


Batch restriction

Can I associate a media file with more than one Batch Restriction?

A: Each media file can only be linked to only one Batch Restriction at a time. However, a Batch Restriction can include multiple individual restrictions, so you can still manage several restriction rules within a single batch.


Can I grant a user download rights using a Batch Restriction?

A: A Batch Restriction cannot give download rights. It can only limit or restrict access.

To allow a user to download files, they must already have download permission. You set this up on the user’s Accesses tab.


Can I apply a Batch Restriction to all of an Author’s media?

A: To restrict all media from a specific author, use Author Restrictions instead.

Go to Purchasing > Authors and open the record’s Restrictions tab to apply restrictions at the author level. This lets you manage restrictions in one place, without needing to apply them to each media file individually.


Can I create a Batch Restriction that only allows my internal staff to access certain media files?

A: Yes. You can do this by using an Access Group for your internal staff.

First, make sure you have an Access Group (under Administration > Access Groups) that includes all internal staff users. Then, create a Batch Restriction with the Allow (positive) rule and select only the internal staff Access Group.

This ensures that only internal staff can access the media files associated with that Batch Restriction.


Is there a way to automatically apply a Batch Restriction to incoming files?

A: Yes. You can automate this by creating an Action Run that applies the Batch Restriction for you.

  1. Go to Media Management > Action Runs and select Edit > New.
  2. Enter a Name, set the action to Active, and click Save.
  3. In the Configure Action Run panel, click New Metadata Action > Replace and Edit.
    • Set the metadata action to Active.
    • In the Edit Metadata panel:
      • Select Restriction from the Database Field dropdown
      • Keep the Action dropdown set to Overwrite.
      • From Text, Value, select the Batch Restriction name.
      • Click Save Settings.
  4. In Media Processing, right-click the folder where you want this action to apply, select Settings from the context menu, and activate the Action Run.

Once enabled, the Batch Restriction will be automatically applied to new files added to that folder.


Why don’t batch-restricted images show any restriction text on my site?

A: Batch Restriction controls access to an image, but it does not add any visible text or metadata to the image itself.
If you want text to appear (for example, “Restricted Use” or similar), add that text separately as metadata, typically in the Special Instructions field.

You can add this metadata in several ways, including:

  • Batch Process
    • Select the images, then choose Edit > Batch Process.
    • By default, the system appends metadata. You can change this with the contextual menu next to any field (Add to End, Add to Beginning, Replace).
  • Action Runs
    • Use a Replace and Edit Action to automatically add or update the text.

Once the text is added as metadata, it will display on your site as expected.