Configuring metadata-based ABAC rules in Adobe Experience Manager Assets Content Hub

In Adobe Experience Manager (AEM) Assets Content Hub, administrators configure Attribute-Based Access Control (ABAC) rules to restrict asset visibility for user groups based on asset metadata properties. For example, a group only views assets where the asset-src metadata property equals Brand Assets and doesn’t see assets tagged as Templates or Campaign Assets. To fix this issue, configure ABAC rules that match the required metadata values.

Description description

Environment

Adobe Experience Manager Assets Content Hub (all versions)

Symptoms

  • User groups see assets they should not have access to, or do not see assets they should.
  • Asset visibility does not match the intended ABAC rule configuration.
  • No error messages are displayed, but asset counts or visibility are incorrect.

Cause

  • ABAC rules may not match the exact metadata values stored on assets (e.g., case sensitivity or formatting differences).
  • Multiple or conflicting ABAC rules may be active for a group.
  • By default, ABAC rules may only apply to assets with certain approval statuses (such as ‘contenthub’) and not to others (such as ‘delivery’).

Resolution resolution

Follow the steps below to resolve the issue:

  1. Verify the exact metadata values stored on your assets. For example, check that the value for the property, such as asset-src, matches exactly, including case and spaces, with the value you intend to use in your ABAC rule.
  2. Remove any existing ABAC rules for the affected user group to prevent conflicts. Keep only one active rule per group for a given restriction.
  3. Create a new ABAC rule for the group. Set the resource type to ASSET, define the subject condition for the target group using the correct Group ID, set the resource condition to match the desired metadata property and value, such as ./metadata/asset-src EQUALS Brand Assets, use the global environment condition, and grant READ access.
  4. Save and apply the rule.
  5. Validate asset visibility by logging in as a user from the affected group. Confirm that only assets with the specified metadata value are visible and that assets with other values, such as Templates and Campaign Assets, are hidden.
  6. If asset visibility doesn’t match expectations, double-check for typographical errors and case sensitivity, and ensure that only one rule remains active for the group.

Note: If you need ABAC rules to apply to assets with approval statuses other than contenthub, such as delivery, consult Adobe documentation or Support for the latest capabilities. Additional configuration could be required.

recommendation-more-help
experience-cloud-kcs-help-kbarticles