3DM Cloud - Users, Roles & Permissions

Named Users

A Named User has reserved access to 3DM Viewer and her/his personal Catalog. Named Users is known by a unique email address and is belongs to 1 organization.
The User can View Resources and publications for which they have explicit permission.

Named Users are individually defined users, they are known to the system and belong to a 3D Mapping Cloud Account. They are identified by their unique email address and are part of one Account. These users can sign in and have access to the Console and the Viewer.

Named Users have full access to the Viewer and all its capabilities, and they can view Resources for which they have permission. Depending on their Role, they can additionally manage Resources, Publications, Shares on Resources and Publications, Users, and the organization’s Subscription.

Named Users having the User Role “User Manager” can invite other Named Users to join the organization’s Account. Invited users receive an email to accept and complete the invitation process. There can be as many active Named Users as the organization’s Subscription permits. It is possible to upgrade or downgrade the subscription at any time. Named Users set to inactive are not counted.

Named User Admin Roles

A Named User can have no, one ore more Amin Roles

User Manager

  • Invite, activate, deactivate, and delete the Named Users
  • Create, edit, and delete Teams
  • Manage User access & Admin Roles
  • Consult Statistic Dashboards


  • Import, upload, edit, tag, download & delete her/his Resources
  • View her/his Resources

Resource Manager

  • Import, upload, edit, tag, download & delete all Company Resources
  • Create, edit & tag Resource Groups & Publications
  • View all Company Resources and Publications
  • Take ownership of Resources and Publications
  • Consult Statistic Dashboards

Sharing Manager

  • share Resources, Publications, and Bookmarks
  • Consult Statistic Dashboards


Teams are groups of Named Users. A Named User can belong to multiple Teams. Teams can be used to share Resources and Publications. There are no Roles assigned to Teams. Named Users keep their Role in whichever Team they reside.

Guest Users

Guest Users have no reserved access, no access to the Console, and can open pre-defined and explicitly shared Publications only. A Guest User is not associated with a 3DM Cloud Organization. A Guest User can have Public access or is required to log in using her/his Orbit GT or Bentley IMS account.

Single sign On

Orbit 3DM Cloud supports Bentley IMS to achieve SSO.
Orbit 3DM Cloud can rely on Bentley IMS for authentication (who you are), but not for authorization (what you can do).
User access and user roles are required to be set within 3DM Cloud by the User Administrator.

Publication Access and User identification

It is possible to access a publication as A) Named User or B) Guest User.
Guest User access can be B.1) anonymous or B.2) requiring User Identification.

A Named User can have a specific Role and has reserved access to 3DM Cloud at all times.
A Guest User access consumes a session from a pool of sessions.

User Identification for Named Users (Option A) and Guest Users (Option B.2) can use the legacy Orbit Account Service or the Bentley IMS.
To provide a Guest user with User Identification (Option B.2) access to a Publication, the 3DM Cloud Sharing Manager needs to add the user's email address to the Guest Users list of the Publication Share page.

Depending on how a Publication is configured for sharing, there will be different prompted pop ups, indicating how a user should login. See example senario below:

Last modified:: 2024/04/25 19:23