Skip to main content
Level 1
September 9, 2026
Question

Create button not appearing in Assets View with granular JCR permissions (works in Admin View)

  • September 9, 2026
  • 2 replies
  • 46 views

Hi team,

 

I am trying to configure permissions for a user so that they have create access but not delete access. I have granted the following privileges:

 

- jcr:versionManagement
- jcr:modifyProperties
- jcr:read
- jcr:addChildNodes
- crx:replicate
- jcr:lockManagement
- jcr:nodeTypeManagement

 

With these permissions, the Create button appears and works as expected in Admin View. However, the same permissions do not work in Assets View — the user is unable to create assets there.

 

Note: If I replace the above privileges with jcr:all, it works correctly in both Admin View and Assets View. However, jcr:all also grants delete access, which I need to avoid.

 

Could you please advise which additional privileges (or paths) are required for create functionality to work in Assets View without granting delete permissions?

Thanks,

Asmit

    2 replies

    A_H_M_Imrul
    Community Advisor
    Community Advisor
    September 16, 2026

    Hi ​@Asmit 

    The privileges you listed are generally sufficient for creating nodes from the repository perspective, but Assets View has some additional requirements compared with the Admin View.

    I would first check the permissions on the actual DAM path where the user is trying to create the asset, for example /content/dam/<project>. In particular, make sure the user/group has jcr:addChildNodes, jcr:modifyProperties, jcr:nodeTypeManagement and the required version/lock privileges on that path.

    Also, Assets View can perform additional repository operations as part of asset creation (folder/asset node creation, metadata updates, versioning, etc.), so the easiest way to identify the missing privilege is to check the AEM error log while reproducing the issue. Look for AccessDeniedException or OakAccessControlException; it should show the exact path and privilege that is being denied.

    I would avoid granting jcr:all just to make Assets View work, especially since you explicitly want to prevent deletion.

    If you can share the AccessDeniedException from the AEM error.log when clicking Create in Assets View, we should be able to identify the exact missing privilege/path.

    AmitVishwakarma
    Community Advisor
    Community Advisor
    September 17, 2026

    Hi ​@Asmit ,

    This is a known limitation of the current Assets View permission model, not a missing JCR privilege or DAM path.

    Your granular privileges are sufficient for creating assets in Admin View. However, Assets View uses simplified permissions such as Can View, Can Edit, and Owner. Can Edit includes create, update, and remove assets. Therefore, denying jcr:removeNode or jcr:removeChildNodes can cause Assets View to treat the user as read-only and hide the Add Assets option.

    There is currently no supported additional privilege or path that enables create/upload in Assets View while preventing delete. Do not use jcr:all as a workaround.

    Recommended options:

    • Use Admin View with the existing granular ACLs for strict create without delete.
    • Use Can Edit in Assets View only if delete access is acceptable.
    • Evaluate Content Hub/limited-user access if the use case permits it.

    https://experienceleague.adobe.com/en/docs/experience-manager-assets-essentials/help/get-started-admins/folder-access/manage-permissions

    https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-26928

    Amit Vishwakarma - Adobe Commerce Champion 2025 | 17x Adobe certified | 6x Adobe SME