Catalog permissions: how they work and how to configure them
Catalog permissions control who can see a catalog, who can see the products associated with it, and who can associate products with its categories. They represent the broadest level of control over product data: they act on the entire catalog, not on individual fields within a product card.
If you are working on products and cannot find a catalog or a reference you expected to see, the cause is almost always here.
What catalog permissions control
A catalog permission produces three distinct effects:
Catalog visibility: whether or not you see the catalog and category hierarchy.
Associated products visibility: whether products linked to that catalog appear in the product list.
Product association: whether you can link or unlink products from that catalog's categories.
Catalog permissions are a different mechanism from Access permissions on product attributes. The former decide which products you see, while the latter decide which fields you see and edit on products you already have access to. They combine together; they do not replace each other.
The four permission levels
Each catalog has only one active level at a time, which you set from the Set permissions field.
Level |
What it entails |
|---|---|
No permissions |
No one in the organization sees the catalog and its associated products |
Everyone can view only |
Everyone sees the catalog structure and related products, but no one can associate products |
Everyone can associate products |
Everyone sees the catalog and related products, and everyone can associate and dissociate products |
Specific permissions by group |
The catalog is closed to everyone except the groups you specify, with the level you choose group by group |
When you select Specific permissions by group, each group you add receives one of these two levels:
Group level |
What the group can do |
|---|---|
Can view only |
Views the catalog and associated products, without being able to associate or dissociate them |
Can associate products |
Views the catalog and can associate and dissociate products from its categories |
Access permissions are cumulative: if a user belongs to multiple groups, the highest permission applies. To reduce a user's access to a catalog, you must adjust their groups, not just the catalog itself.
Configure catalog permissions
To view and manage access permissions for a catalog, you must be an Administrator or have the "Can manage product data modeling" permission.
When creating a catalog
Go to Platform Settings → Products → Catalogs and categories
Click Add catalog
Enter the Catalog code: this is the same code used by APIs as a category path node
Click Manage access permissions to proceed to the second step and choose the level
The catalog is created as soon as the first step is completed. If you exit without completing the second step, the catalog will still exist: reopen it in edit mode to set its permissions.
On an existing catalog
In the Catalogs and categories list, click the catalog's action icon and select Edit
In the Catalog configuration panel, open the Access permissions section
Choose the level from the Set permissions field
Click Save changes in the header to confirm
Until you save, the header will indicate Unsaved changes. Use Cancel to discard everything and revert to the last saved configuration.
Assign permissions to specific groups
Select Specific permissions by group from the Set permissions field
In the Specific access field, open Add user group and check one or more groups
Choose the level to assign: Can view only or Can associate products
Click Add and repeat for other groups with a different level
Click Save changes
At least one group must be included: without it, the configuration cannot be saved. A catalog that needs to remain closed to everyone should be set to No permissions, not to Specific permissions by group without groups.
The Access permissions column in the catalog list summarizes the active level of each catalog: use it for a quick check without opening each card.
What changes for product users
Catalog permissions do not produce error messages: they directly change what you see in the platform.
Where |
Effect |
|---|---|
Product list |
A product associated with a catalog you cannot see does not appear among the results |
Product list Categories panel |
You only see catalogs for which you have view or product association permissions |
Product card Categories tab |
The Catalog filter only shows catalogs for which you have sufficient permissions |
Category association |
Without the permission to associate products in a catalog, you cannot link the product to its categories |
If a colleague sees a product that you cannot find, before checking your filters, check the permissions of the catalogs that product is associated with.
Isolating brands on a single platform
The most common use case is a multi-brand or multi-market organization working on a single THRON instance that needs each team to only see its own perimeter.
The configuration pattern is as follows:
Create a catalog for each brand or market, for example
brand-aandbrand-bSet each catalog to Specific permissions by group
Add only the working group of the corresponding brand, with the level Can associate products
Add cross-functional groups that need to consult without editing (such as a coordination team) with Can view only
The result: team members of Brand A work on products in their own catalog and do not encounter Brand B products, neither in the product list nor in category filters.
Recommended configuration
Three standard starting scenarios.
Situation |
Level to set |
|---|---|
Catalog shared across the entire organization |
Everyone can associate products |
Reference catalog that no one should alter |
Everyone can view only |
Catalog reserved for a brand, market, or channel |
Specific permissions by group |
Recommended strategy: start with Specific permissions by group on catalogs that genuinely segment work, and leave only cross-functional catalogs open. Before opening a catalog to everyone, verify that the products it contains can be viewed by anyone with access to the Products area.
Catalog permissions vs attribute permissions
Both mechanisms work on different levels and must both be configured for complete governance.
Comparison |
Catalog permissions |
Attribute permissions |
|---|---|---|
What they act on |
The entire catalog and associated products |
Individual fields in the product card |
What they determine |
Which products you see and which categories you can associate them with |
Which values you see and which you can edit |
Where to configure them |
Platform Settings → Products → Catalogs and categories |
Platform Settings → Products → Attributes |
## Additional articles
- Configure Product Catalogs and Categories
- Set access permissions on product attributes
- Configure Users and Groups
- Folder permissions: how they workNeed help?
For technical issues, write to support@thron.com.