Access, Sharing & Permissions

A collection photograph is not merely an attractive picture. It may be proof of ownership, a condition record, an authentication aid, a map to where an object is stored, or a source of serial numbers and unique marks valuable to a fraudster. Access control therefore belongs to the evidential and security architecture of a collection, not just to the settings menu of a gallery.

The governing principle is controlled disclosure: the right person should see the right version, for the right purpose, with the right permissions, for no longer than necessary. “Private or public” is too crude for serious collecting because viewing, downloading, editing, publishing and keeping a copy are different acts with different consequences.

Collector scenario

The six-image valuation that quietly exposed the collection

A collector sends an appraiser a link to six photographs of a rare boxed set. The link actually opens the whole cloud folder. Other images show the room, shelving, insurance schedule and complete serials for several unrelated objects. The appraiser is trustworthy, but the disclosure is still excessive: the wrong scope, the wrong version and too much metadata were made available for longer than the task required.

Good access control would have created a named, time-limited share containing only the selected item photographs, with comments enabled, downloads decided separately and the event recorded. The lesson is not “never share”. It is to shape the share around the purpose.

Three decisions, not one

Access

Can they reach it?

Access decides whether a person or system can reach the image at all: privately, through a named account, through a group, by link, publicly or under delegated authority.

Sharing

Why is it being disclosed?

Sharing is the deliberate act of making an image available for a defined purpose such as valuation, authentication, sale, research, conservation or estate administration.

Permission

What may they do next?

Permission governs actions after access: view, comment, download, upload, edit metadata, publish, share onward, delete or administer other users.

Myth versus reality

Myth: “View-only means they cannot copy it.”

Disabling download reduces casual copying, but it cannot prevent screenshots, screen photography or manual transcription.

Reality: control changes after delivery.

Once a file is downloaded, revoking the link does not remove the recipient’s copy. Access and possession must be treated separately.

What a photograph can disclose beyond the object

The risk rarely sits in the object image alone. It often appears when the photograph is combined with its background, filename, account, embedded metadata or neighbouring records. Review the complete disclosure, not just the central subject.

Ownership

The image may prove that a named collector possesses a rare, valuable or culturally sensitive object.

Location

Backgrounds can reveal shelving, doors, windows, safes, alarms, storage facilities, vehicle registrations and the layout of a home.

Collection scale

Filenames, albums, profiles and visible shelves can connect one apparently harmless image to a much larger holding.

Identifiers

Serial numbers, grading labels, certificates, signatures and unique damage can support authenticity but can also be copied into fraudulent listings.

Personal information

Names, addresses, correspondence, receipts, children, payment details and shipping labels may appear in the frame or in attached metadata.

Security pattern

A run of images may disclose when objects were present, where they were kept and how a collection is protected or moved.

Choose the access model deliberately

Default state

Private

Only the collector can reach the image. Use this for new uploads, masters, receipts, insurance evidence, storage-location photographs and unpublished material.

Accountable access

Named person

A specific person is invited and can be individually removed. This suits appraisers, insurers, authenticators, conservators and trusted family members.

Shared responsibility

Defined group

Access is granted to a maintained group such as household co-owners, trustees or collection staff. The danger is stale membership after roles change.

Convenient but fragile

Link-based

Anyone holding the link may gain access. Links should be scoped, revocable, protected from indexing and normally time-limited.

Publication decision

Public

The image is openly available without authentication. Public visibility should be intentional and should normally use a prepared derivative rather than the master.

Authority-based

Delegated or inherited

An executor, attorney, trustee or successor gains access because responsibility has transferred. This requires evidence, governance and a clearly defined trigger.

Private by default

Newly uploaded images should normally begin private. This is especially important for masters, insurance evidence, receipts, certificates, storage photographs and any image whose sensitivity has not yet been reviewed.

Public access should be an affirmative publication decision. It should never arise merely because a privacy field was omitted, a folder inherited the wrong setting or an original file happened to sit behind a public thumbnail.

Permission is a set of capabilities

A mature system does not grant a vague category called “access”. It separates ordinary inspection from actions that alter, duplicate or redistribute the record.

View

The recipient may inspect the image. View-only reduces casual copying but cannot prevent screenshots or a photograph of the screen.

Comment or annotate

The recipient may add an opinion without changing the original image or authoritative metadata. Record author and date.

Download

The recipient receives a copy outside the system. Revoking access later does not retrieve that copy, so download must be a separate decision.

Upload

A collaborator may contribute new photographs. Preserve contributor identity, upload date and relationship to the object.

Edit metadata

This can change discovery, attribution, provenance, item linkage and insurance reporting. It is more consequential than commenting.

Replace or delete

Restrict destructive actions. Prefer soft deletion, recovery periods and version history because a removed photograph may have been evidence.

Share onward

A recipient may invite others or create new links. Never assume that permission to view includes permission to redistribute.

Administer

Administrative users can alter roles and security settings. These privileges should be rare, reviewed and logged.

Apply least privilege at the narrowest useful level

Least privilege means granting only what is needed to complete the agreed task. It reduces deliberate misuse, accidental mistakes and the damage caused by a compromised account.

Collection level

Broadest scope

The recipient sees every approved image in a collection. Suitable for a co-owner or collection manager, but usually too broad for a transaction.

Item or image level

Task-shaped scope

The recipient sees one object or a selected set of views. This is normally the best fit for valuation, sale, authentication and claims.

Field level

Separate image from metadata

Different viewers may see different captions, prices, serials, owner identities or storage information even when viewing the same image.

A useful test

Ask not “Can this person be trusted?” but “What is the smallest useful package this role requires?” A trusted appraiser still does not need unrelated receipts; a trusted buyer still does not need the storage shelf; a trusted photographer may need upload permission without any ability to edit acquisition or provenance records.

Share a suitable derivative, not automatically the master

Preservation master

Retain maximum evidence

Keep the highest-quality file with complete colour, resolution, technical metadata and unredacted detail. This is the archival source, not the routine sharing copy.

Access derivative

Prepare for purpose

Create a smaller, cropped, redacted, watermarked or metadata-stripped version that reveals enough for the recipient’s task and no more.

Thumbnail

Navigate, do not judge

A thumbnail supports browsing but is rarely adequate for authentication, detailed condition assessment, restoration comparison or proof-grade documentation.

Action hierarchy: before sharing an original

  1. Use a selected crop or derivative if it answers the question.
  2. Remove unnecessary location, device and workflow metadata from the distributed copy.
  3. Redact visible personal, security or anti-counterfeit details where appropriate.
  4. Decide separately whether download is required.
  5. Release the master only when resolution, colour or evidential completeness genuinely demands it.

Build the share around the collector’s purpose

Authentication

Evidence needed

High-resolution details, colour accuracy, serials, construction evidence and comparison views.

Usually unnecessary

Home address, exact storage location, unrelated collection photographs and full financial history.

Permission pattern

View, comment and perhaps upload supporting images; no deletion or onward sharing by default.

Valuation

Evidence needed

Overall views, condition details, dimensions, provenance documents and relevant market evidence.

Usually unnecessary

Unrelated holdings and security information. State the date and purpose of the valuation.

Permission pattern

Selected view access, controlled download and annotation where a written opinion is required.

Insurance

Evidence needed

Evidence of existence, ownership, identity, condition, value and—where requested—security arrangements.

Usually unnecessary

Never place security details in the same public gallery used to display the collection.

Permission pattern

Private, recipient-specific access with an expiry aligned to the policy or claim process.

Sale

Evidence needed

Clear public-facing images that establish identity and condition while supporting buyer confidence.

Usually unnecessary

Consider masking complete serials or anti-counterfeit details until a serious private enquiry.

Permission pattern

Public derivative for marketing; controlled originals and complete identifiers supplied privately.

Conservation

Evidence needed

Technical images before, during and after treatment, plus permission for the professional to add treatment photographs.

Usually unnecessary

Unrelated financial and household information.

Permission pattern

High-resolution access, upload and limited metadata contribution, with publication rights agreed separately.

Research or publication

Evidence needed

A defined research set, contextual metadata and an explicit answer on citation, reproduction and publication.

Usually unnecessary

Owner identity or collection location unless disclosure is necessary and authorised.

Permission pattern

Inspection is not publication. Grant reproduction and reuse rights explicitly rather than by implication.

Temporary access has a lifecycle

1

Grant

Name the recipient, purpose, scope, permissions and start date.

2

Use

Allow only the actions required and record significant activity.

3

Review

Check whether the transaction, claim, valuation or research task is still active.

4

Expire or revoke

Remove access, group membership, active links and related credentials when the purpose ends.

Distinguish three outcomes. Access expired means the system no longer serves the file. Copy withdrawn means the recipient has been told not to use a retained copy. Copy deleted means deletion has been confirmed. Only the first is routinely enforceable by the system itself.

Authentication strength should match the consequence

Anonymous link

Fastest and least accountable. The system may know the link was used but not by whom.

Password-protected link

Reduces casual access but weakens quickly when link and password travel together or are shared by several people.

Verified email

Confirms control of an address and supports individual revocation, but does not prove real-world identity.

Named account

Supports roles, history, individual revocation, terms acceptance and multifactor authentication.

Per-request authorisation

Checks permission whenever a file is requested rather than relying on a durable address that remains valid indefinitely.

Signed and expiring URLs

Private cloud images are often delivered through a temporary signed address. This keeps the underlying storage private and allows access to expire, but the address can still be copied and reused until its token ends.

Match duration to use: minutes for routine in-app display, hours for a controlled download, days for a professional review, and longer only where the workflow genuinely needs it. A signed URL is a delivery control, not proof that the intended individual is the person using it.

Revocation and audit are part of sharing

Revocation should reach every route

  • User and role permissions
  • Group membership
  • Future signed links and downloads
  • Active sessions where risk warrants it
  • API or integration credentials
  • Public publication state

Audit events worth retaining

  • Share created, changed, expired or revoked
  • View, download and export events where proportionate
  • Metadata edits, replacements and deletion requests
  • Public publication and withdrawal
  • Who acted, when, on which image and for what case or reason

An audit trail does not prove misconduct by itself. It creates an evidential chronology: whether a condition image existed before shipment, when a photograph became public, who changed a permission, or whether metadata was edited after a specialist opinion.

Rights, privacy and redaction

Six separate questions can exist in one image

  1. Who owns the physical collectible?
  2. Who possesses the digital file?
  3. Who owns copyright in the photograph?
  4. What rights exist in the artwork, packaging or documents depicted?
  5. Has publication been permitted?
  6. May a recipient reproduce, reuse or redistribute the image?

Paying a photographer does not automatically settle every usage right. A commission should address copyright ownership, the collector’s licence, portfolio use, commercial and sale-listing use, attribution, confidentiality, delivery of originals, retention and sublicensing.

Visible review

Inspect people, children, names, addresses, receipts, signatures, payment details, interiors, keys, alarm panels, safes, licence plates and shipping labels.

Crop, blur, mask, redact, replace with a public derivative or withhold the image entirely.

Embedded review

Inspect location, device, creator, date, application and workflow metadata before distributing the file.

Apply redaction to the actual distributed copy. A visual black box in an editable interface may leave the underlying information recoverable.

Watermarks: deterrent, not control

Visible, invisible or personalised watermarks can discourage casual reuse, communicate source and sometimes trace a recipient. They may also obscure condition details, interfere with authentication and disappear through cropping, screenshots or format conversion.

Use a watermark where it serves the purpose, but never treat it as a substitute for authentication, permission control or a clear usage agreement.

Common sharing failures

“Anyone with the link” becomes permanent security

The link is forwarded, saved and left active for years. Convenience quietly turns into uncontrolled publication.

The whole folder is shared

A recipient who needed six images receives unrelated objects, receipts, storage photographs and private notes.

Original download is enabled by habit

A medium-resolution review would have been enough, but the preservation master is distributed without necessity.

Visibility is inherited incorrectly

A private image is placed in a public album or a public record links directly to a supposedly hidden original.

Redaction exists only on screen

The interface covers information, but the distributed or downloadable file remains unredacted.

Former collaborators remain active

An appraiser, employee or family helper keeps access after the role or transaction has ended.

A practical role matrix

The following compact matrix is a starting pattern, not a universal rule. Each capability should be decided against the actual purpose, sensitivity and relationship rather than granted because a person belongs to a broad category.

RoleViewDownloadContributeEdit or delete
Collector-ownerAllYesYesYes
Household co-ownerAll or broadOptionalYesLimited
Appraiser / authenticatorSelectedOptionalComment / reportNo
InsurerSelectedControlledNoNo
ConservatorSelectedYesTreatment imagesLimited metadata
Prospective buyerSale setUsually limitedNoNo
ResearcherResearch setLicensed onlyCommentNo
Public visitorPublished setPolicy-dependentNoNo
ExecutorBroad after authorityYesYesRestricted

Collector’s pre-sharing check

Purpose

  • Why is the image being shared?
  • What decision or task must the recipient complete?
  • Would a written answer or crop achieve the same result?

Scope

  • Does the recipient need one image, one item or a complete collection?
  • Is all attached metadata necessary?
  • Are unrelated documents or images included by folder inheritance?

Version

  • Is a thumbnail, crop or access derivative sufficient?
  • Does the recipient genuinely need the unaltered master?
  • Has the distributed copy been checked at full size?

Sensitivity

  • Are addresses, people, security details, receipts or complete identifiers visible?
  • Does embedded metadata reveal location, device or workflow information?
  • Should the image be cropped, redacted or withheld?

Rights

  • Who took the photograph and who owns the photographic copyright?
  • Is publication, resale use or redistribution permitted?
  • Does the image contain third-party copyright or personal information?

Control and evidence

  • May the recipient view, download, annotate, publish or share onward?
  • When should access expire and who will review it?
  • Will the system record the share, permission changes and later activity?

When specialist input is warranted

Routine family sharing rarely needs formal advice. Escalate when the consequences extend beyond an ordinary private exchange.

  • A commissioned photographer’s rights or confidentiality terms are unclear.
  • The image includes personal data being handled by a business, institution, charity or public body.
  • A researcher, publisher, auction house or platform wants reproduction or sublicensing rights.
  • The collection includes culturally sensitive, restricted or security-sensitive material.
  • Legacy access depends on incapacity, death, power of attorney, trust or executor authority.
  • A leak, fraudulent listing or disputed deletion may require preservation of logs and evidence.

Key takeaways

  • Access, sharing and permission are different decisions.
  • Private by default is safer than trying to repair accidental publication later.
  • Scope access to the smallest useful collection, item, image and metadata set.
  • Share derivatives when the recipient does not need the preservation master.
  • Viewing is not downloading, and inspection is not permission to publish.
  • Every temporary share needs an expiry, revocation route and responsible owner.
  • Downloaded files cannot reliably be recalled, which is why download must be explicit.
  • Keep the image connected to its item, version, creator, rights, events and permissions.

Continue learning

Related topics