
## Understanding lock icons

URL: https://docs.atlan.com/product/capabilities/governance/custom-metadata/references/what-happens-when-users-do-not-have-access-to-metadata

> The lock icon in Atlan indicates when users have limited access to an asset. This page explains what the icon means and how roles, connection admins, and access policies affect it.

The lock icon on an asset in Atlan indicates that the current user has limited permissions on it. The user can see the asset exists but cannot perform certain actions on it.

![Limited_access.png](https://docs.atlan.com/img/administration/access-control/how-tos/limited-access.png)

## Connection admins

Connection admins manage connectivity to a data source. Even if you are a [member](https://docs.atlan.com/llms/governance/access-control/delegate-administration/llms.txt) user, connection admin status gives you full access to assets from that connection.

Any user with connection admin status will not see the lock icon for their assets. An explicit access policy can override a connection admin's default full access.

## Access policies

Access policies often supersede the default permissions associated with connection admins and user roles. Access policies either allow or restrict access to certain assets.

For example, even as a _member_ user, you can add [tags](https://docs.atlan.com/llms/governance/tags/attach-a-tag/llms.txt) and [terms](https://docs.atlan.com/llms/governance/glossary/link-terms-to-assets/llms.txt) to an asset if you are part of a persona with a metadata policy that allows this action. Guest users in Atlan can only suggest changes to asset metadata if [enabled from the admin center](https://docs.atlan.com/llms/governance/access-control/access-control-settings/llms.txt).

Access policies can also give users full access to certain assets without making them connection admins.

## User roles

Although there are [default permissions](https://docs.atlan.com/llms/governance/access-control/delegate-administration/llms.txt) associated with each user role (_admin_, _member_, and _guest_), access to assets depends entirely on whether the user is a connection admin or part of a persona or purpose.

For example, a _member_ user who is neither a connection admin nor part of any persona or purpose will see every asset in Atlan with a lock icon.

## See also

- [How access policies work](https://docs.atlan.com/llms/governance/access-control/what-are-purposes/llms.txt)
- [Create a persona](https://docs.atlan.com/llms/governance/access-control/create-a-persona/llms.txt)
- [Create a purpose](https://docs.atlan.com/llms/governance/access-control/create-a-purpose/llms.txt)

---
