Insights
— Platform
Why access is defined on the asset, not on the person
moodcase defines access on the asset and on the link that leads to it, rather than on a description of the person at the other end. That is a design decision, and it follows from a plain observation: the people who need visual assets are mostly not on the org chart the roles were drawn from.

Mathias Buschor
Co-Founder at moodcase
•
4
min read

Photo:
Levi Fitze
The standard model is well understood. Decide who edits, who views, who administers. Grant the minimum each needs. Review the list on a schedule. It was designed for systems a company runs, for people a company employs, and inside that boundary it works.
Visual work sits mostly outside that boundary. That is where the model bends, and it bends quietly enough that nobody notices until an asset from a closed campaign turns out to be reachable by someone who left a year ago. This is written for the teams where that happens: mixed, external, and constantly delivering outward.
The people who touch the assets are rarely employees
Count who touches an asset between a shoot and a campaign. A photographer. A retoucher. An agency team. A licensing contact. A brand lead on the client side. Whoever is covering a leave. Almost none of them appear in the org chart the roles came from.
So the model gets stretched. Someone receives a role that approximates what they need. An account is created for a fortnight and kept for two years. A shared login appears because a proper one required an approval nobody wanted to chase.
None of that is carelessness. It is a model asked to describe a shape it was not drawn for. Work of this kind is temporary, its participants are mixed, and it ends. A role is permanent, internal, and has no end date.
Maintenance is continuous and nothing forces it
When an engagement finishes, nothing changes on its own. The account remains until someone remembers it. When a person leaves, the offboarding list covers payroll, email and the systems finance knows about. The visual library is rarely on that list. When it is, it asks which roles the person held. That is a different question from which assets they can still reach.
There is a second cost, and it lands on the people asking. Because the model is maintained centrally, every access question becomes a request. The retoucher waits. The agency waits. Someone senior is pulled in to approve something they have no context on, and grants broadly to avoid being asked twice. Least privilege does not survive contact with a deadline.
A condition attached to the asset needs no memory
The alternative is not a better role model. It is attaching the condition to the thing being shared rather than to the person receiving it.
The asset carries what may be done with it. The link carries who may open it, for how long, and in what form. Neither requires the recipient to have an identity inside the organization, which is the assumption that made the first model bend.
The difference shows at the end rather than at the start, and that is the part worth noticing. A role has to be revoked, which means somebody has to remember. A link that carried its own conditions simply stops being a route. It ends on a date set when it was created, by the person who was in the room. One decision, made once, at the only moment anyone knew the answer.
That removes the account created only so a role could be granted. It removes the periodic review whose purpose is to find access that should have ended. It does not remove the thinking. Someone still decides what a link allows and for how long. The decision simply moves to where the knowledge is.
Where this applies
An internal library only employees ever touch does not have this problem, and roles serve it well. Nor does a team small enough that every arrangement fits in one head. This matters where visual work actually happens: mixed teams, external contributors, engagements that begin and end, and assets that leave the building on purpose. There the org chart was never the right map, and access attached to the work is the only version that stays true without being maintained.

What moodcase does with this
Access control exists across all plans and is defined on the asset. Roles are not the mechanism, which is a decision rather than an open item.
Sharing carries its own conditions. On paid plans a link holds granular permissions, an expiry date, and password protection where the delivery needs it. The recipient needs no account in the workspace to receive what was meant for them, and nothing has to be revoked for the arrangement to end.
Where this fits
The symptom is specific. Not a breach and not an audit finding. It is the moment someone asks who can still see last spring's campaign, and the answer requires opening several lists.
Visual assets need more than a folder. See how moodcase handles the full workflow.
Try all features for 7 days. No credit card required.
Sharing
Marketing Teams
Agencies
RELATED

Visual asset management without DAM overhead.
Access defined on a person has to be maintained. Access defined on the asset and the link holds without anyone remembering.


When marketing teams outgrow shared folders.
Folders break for marketing teams not because the team is bad at naming. They break because folders cannot hold information about the asset.
