Skip to main content
Version: ILLiad 10.0 (Pre-release) 🚧

Authentication and Access Control

The ILLiad Staff Web Client provides secure authentication so only authorized staff can access your ILL operations. Your institution can enable ILLiad username/password login, single sign-on (SSO), and multi-factor authentication (MFA) in any combination that fits its security requirements.

How Authentication Works

Authentication in the Staff Web Client verifies your identity — making sure you are who you say you are. Once the system confirms your identity, it checks your permissions to determine what features and data you can access. This two-step process (authentication, then authorization) protects both your system and your patrons' information.

Your institution chooses which authentication methods to enable based on your security policies and technical infrastructure. You might have one option or several, but the goal is always the same: get authorized staff into the system quickly and securely.

Available Authentication Methods

Login Methods

Your first step is getting into the system. Depending on your institution's setup, you might use:

  • A traditional ILLiad username and password
  • Single sign-on (SSO) with your institutional credentials
  • Multi-factor authentication using an authenticator app, for enhanced security

Each method has its own benefits, and many institutions use a combination to balance security with convenience.

User Permissions

Once you're logged in, your permissions determine what you can see and do. ILLiad uses role-based access control, so your access is based on your role. Whether you're a staff user handling day-to-day tasks or a staff manager overseeing the operation, the system shows you what your role allows.

Configuring Authentication

For administrators: how to set up SSO (SAML2) and enable and manage multi-factor authentication for the Web Client — including the appsettings.json configuration and resetting a staff member's MFA.

Keeping Access Secure

A few habits keep staff access secure: use a unique ILLiad password, turn on multi-factor authentication where your institution offers it, and log out completely on shared computers. See Keeping Your Account Secure for more.

Getting Started

Ready to log in? Start with the Login Methods available at your institution. Once you're in, review your User Permissions to understand your access level.

Your ILLiad administrator is your resource for authentication questions — password resets, permission adjustments, and any access issues you encounter.