Skip to contentv0.1.0
PIMgate
FEATURE · ROLES, RIGHTS & ENTITLEMENTS2026

Every stakeholder gets their own door — and sees only their own shelves.

PIM Gate checks every page, every query and every file against an explicit set of entitlements: per tenant, portal, role, market and category, down to the single asset. Customers see their assortment, suppliers their products, sales reps their customers — and the audit log records who did what.

SIX ENTITLEMENT LAYERSFILTERED ON THE SERVERAPPEND-ONLY AUDIT
Entitlement layers: tenant, portal, role, market, category, asset.Six stacked filters narrow the full catalog down to what one user may see; the last layer scopes access down to the single asset.Signed-in userj.meier · Sales rep · CHTenantMESSARA20,418 SKUsPortal/p/sales14,902 SKUsRoleSales rep6,140 SKUsMarketCH2,208 SKUsCatalog viewAgreement 2026-B514 SKUsAsset scopeApproved media only312 SKUsThis user sees312of 20,418 SKUsEnforced server-sideEvery layer is a deny-by-default filter · nothing leaks between tenants

01 · What it does

Decide who sees what. Enforce it everywhere. Prove it later.

Layered entitlements

Six layers from tenant to single asset combine into one effective scope per user and per API token.

Enforced on the server

Portals, API responses, exports and downloads are filtered before they are built. There is no "hidden in the UI" — what is not entitled is never sent.

Recorded, append-only

Invitations, role changes, views, downloads and shares are written to an audit log that cannot be edited afterwards.

02 · Entitlement layers

Six layers that mirror how your business is organized.

Entitlements in PIM Gate are not a single list of permissions. They are layers, each answering one question — which company, which door, which role, which market, which part of the assortment, which file. A user's or token's effective scope is the intersection of all six. Markets and categories are defined through catalog views, so the same rule that builds a portal's assortment also limits what its users can reach.

  • Tenant isolation at data level
  • Catalog views with markets and languages per portalLIVE
  • Server-side entitlement filtering for portal and API
  • Configurable roles and groups2026
  • Exceptions down to the individual asset
LayerDecidesExampleStatus
TenantWhich company's data at allmessaraISOLATION ✓ · SUBDOMAINS 2026
PortalWhich door: customer, supplier, salescustomer. · sales.live
RoleWhat a user may dosales rep · reviewer2026
MarketWhich countries, prices, languagesCH · de-CH, en-GBlive
CategoryWhich part of the assortmentDruckmesstechniklive
AssetWhich individual filesatex_certificate.pdflive
03 · Tenants & portals

One tenant per brand or country. One portal per audience.

A tenant is an isolated space with its own data, users, tokens and settings — typically one per brand or country company. Inside a tenant, each portal is a door for one audience, with its own catalog view, languages and branding, under a PIM Gate subdomain or your own domain with certificate included. Portal end users are unlimited in every version; you pay for your internal team, not for your customers.

  • Tenant isolation at data level
  • Tenant subdomains and custom domains per tenant, certificate included2026
  • White-label branding and theming per portal2026
  • Branded tenants included: S 1 · M 3 · L 10 · XL unlimited; additional €1,200
  • Portal end users unlimited in every version

Tenants & portals

One tenant per brand or country. One portal per audience.

04 · Roles

Roles that match the people who need your data.

Roles bundle what a person may do — browse the catalog, see prices, download assets, submit supplier data, translate, approve, administer. Combined with the entitlement layers, the same role behaves differently per market or portal: a Swiss sales rep sees CHF prices for the Swiss assortment only. Roles and groups are yours to define; the matrix below is a starting point, not a limit.

EXAMPLE — CONFIGURABLE PER TENANT
RoleCatalogPricesAssetsSubmitTranslateApproveAdmin
Sales✓✓✓————
Service / Customer✓—✓————
Supplier——✓✓———
Translator✓———✓——
Reviewer✓—✓—✓✓—
Admin✓✓✓✓✓✓✓
  • Configurable roles and groups
  • Admin console for users, roles and portals
  • Translator and reviewer roles per language for translation workflows
  • Supplier role limited to the supplier's own products and submissions
05 · Relationship scoping

A sales rep sees their customers. Each customer sees their agreement.

In sales, entitlements follow relationships, not just roles. A rep is mapped to the customers they serve; each customer is linked to the agreement that defines their assortment and prices. When the rep opens a customer, the portal shows exactly that customer's catalog — ready to export as PDF or XLSX or to share — and nothing from the next customer's agreement.

  • Rep → customer mapping2026
  • Customer → agreement scoping of assortment and prices2026
  • Customer-specific PDF / XLSX export2026
  • Share links for customer catalogs2026
  • Activity log per customer (views, downloads)ROADMAP

Relationship scoping

A sales rep sees their customers. Each customer sees their agreement.

06 · Tokens & audit

Systems get scoped keys. Every action leaves a trace.

Machines follow the same rules as people. Each API token belongs to one tenant and is filtered by the entitlements attached to it, so a shop token for Switzerland can never read German prices. Every relevant action — invitations, role changes, token rotations, imports, automatic translations, views, downloads, shares — is written to an append-only audit log. Entries cannot be edited or deleted; retention can be extended to ten years.

  • Per-tenant API tokens with server-side entitlement filteringLIVE
  • Append-only audit log — tenant isolation and audit are part of the platform
  • Audit-log UI in the admin console, filterable and exportable2026
  • Audit-log retention of 10 years: €1,200
  • Automatic changes marked source: AUTO → AI workflows

Tokens & audit

Systems get scoped keys. Every action leaves a trace.

07 · Identity roadmap

Enterprise identity, on the roadmap.

  • SSO via OIDC & SAML Sign in with your corporate identity provider, for internal users and — where wanted — for portal users.ROADMAP
  • SCIM provisioning Users and groups created, changed and removed from your directory automatically.ROADMAP
  • MFA Second factor for administrators and internal users.ROADMAP

SSO is planned for the higher versions. See the roadmap for sequencing.

Identity roadmap

Enterprise identity, on the roadmap.

08 · Specifications

Roles & entitlements at a glance.

Roles & entitlements at a glance.
SpecValueStatus
Entitlement layersTENANT · PORTAL · ROLE · MARKET · CATEGORY · ASSETsee s3
EnforcementSERVER-SIDE · PORTAL + API + EXPORTLIVE
Catalog views per portalMARKETS · LANGUAGES · RULESLIVE
Tenant isolationDATA LEVEL—
Tenant subdomains · custom domains{tenant}.pimgate.ai · YOUR DOMAIN + TLS2026
White-label per portalLOGO · COLORS · DOMAIN2026
Roles & groups · admin consoleCONFIGURABLE PER TENANT2026
Relationship scoping (sales)REP → CUSTOMER → AGREEMENT2026
API tokensPER TENANT · ENTITLEMENT-FILTEREDLIVE
Audit logAPPEND-ONLY—
Audit-log UIFILTER · SEARCH2026
Audit retention 10 yrs€1,200—
Portal end usersUNLIMITED—
SSO OIDC / SAML · SCIM · MFA—ROADMAP

09 · Works with

Where entitlements apply.

Customer Portal · LIVESupplier Portal · 2026Sales Portal · 2026Media Portal · ROADMAPREST API /v1 · LIVEVersioned exports · LIVEShare links · 2026OIDC / SAML · ROADMAP

Put a gate between your catalog and chaos.