Skip to main content
Version: ILLiad 10.0 (Pre-release) 🚧

Understanding User Permissions

Once you're logged into the ILLiad Staff Web Client, what you can see and do depends on your permissions. Permissions give you the tools your role requires while protecting sensitive data and system functions you don't need to touch.

How Permissions Work

The Staff Web Client combines two layers of access control:

  1. A role you're assigned to.
  2. The fine-grained permissions set on that role, which control access to individual workflow areas and actions.

A Staff Manager creates roles, sets their permissions, and assigns you to one when they set up your account, so most users never need to configure anything themselves. Your permissions affect what appears throughout the interface: which menu items you see, which buttons you can click, which queues you can open, and which data fields you can view or edit. You only see what's relevant to your work.

Staff Roles

The Staff Web Client uses role-based access control. It includes a Staff Manager role and a Staff role, and a Staff Manager can create additional roles of their own. For each role, a Staff Manager sets the permissions it grants and assigns staff members to it — so you can shape access around how your department works (for example, a circulation-desk role or a student-worker role).

Staff Manager

Staff Managers have the highest level of access. In addition to operational work, they can reach the Admin area of the client, where they create and manage roles, set each role's permissions, and assign staff members to roles. The Admin area is available only to Staff Managers. They are typically the ILL department heads or designated system administrators.

If you're a Staff Manager, you're responsible for ensuring other staff have appropriate access. Because you can make changes that affect others, take care when editing roles, accounts, and permissions.

Staff and Custom Roles

Everyone who isn't a Staff Manager works in a role a manager has assigned them — the built-in Staff role or a custom role the manager created. The role's permissions determine what that person can do (for example, processing borrowing requests, handling lending, or working with user records). Staff in these roles do not have access to the Admin area.

Setting up a student-worker role

To give student workers a limited, task-focused view, create a role for them, assign the students to it, and grant only the permissions the work requires — for example, borrowing circulation only. They'll see just the tasks their role allows.

Permission Categories

Beyond your role, capability is controlled by fine-grained permissions organized around ILLiad's main workflow areas. Understanding these helps you know why you might or might not see certain features. The permission areas are:

Borrowing

Permissions for processing requests for items your library wants to borrow. This area is subdivided so an administrator can grant exactly what a person needs — for example, the ability to read borrowing requests, process them, route them, edit them, or work with borrowing billing, copyright, flags, notifications, and circulation (checking borrowed items in and out to patrons is a borrowing-circulation permission).

Document Delivery

Permissions for processing requests for article copies and chapter scans your library fills locally. As with borrowing, this can be granted at the level of reading, processing, routing, editing, billing, flags, and notifications.

Lending

Permissions for handling requests from other libraries that want to borrow your materials. Sub-permissions cover reading, processing, routing, editing, billing, external requests, flags, and notifications.

Users

Permissions for working with patron records — reading user information, editing it, clearing user history, and controlling whether a user may log on to the web.

Each area starts with a Read permission that acts as a gate: without read access to an area, the more specific actions in that area don't apply. This is why two people can have very different capabilities — the permissions on their roles differ.

How Administrators Manage Permissions

Permissions are managed by Staff Managers in the client's Admin area, not by individual users. A Staff Manager creates roles, sets each role's permissions through an editor that lists every area (Borrowing, Document Delivery, Lending, Users) and its individual actions, and assigns staff members to roles. Turning off an area's read permission removes the more specific permissions within it.

Multi-Site Considerations

If your ILLiad server is shared by more than one library (multiple sites), your access can be site-specific. Sites are a first-class concept in the client: you log on to a particular site, your permitted sites are remembered, and — if you have more than one — you can move between them using Change Site in the account menu. If you try to reach a site you're not permitted to use, the client tells you that permission was not granted for that site.

Because access is tied to sites, two people in the same role may have different capabilities depending on which site they're working in.

Reading Permission Cues in the Interface

The Staff Web Client is designed to show only what you can use — it doesn't render buttons you can't click or menus you can't open. This creates a cleaner, less frustrating interface. Here's how to read the visual cues:

Missing Menu Items — If you don't see an expected menu option, you probably don't have permission for that feature. The system hides inaccessible options rather than showing them grayed out.

Available Actions — Buttons and links only appear if you can use them. If you can view a request but not edit it, you won't see an Edit button.

Form Fields — Field visibility and editability are controlled by the client's field-customization system, so fields you're not permitted to see or change may be hidden or shown as read-only.

This behavior is consistent across screen sizes: the interface is responsive and adapts to smaller screens, but it presents the same permission-based view of what you're allowed to do.

When You Lack a Needed Permission

The Staff Web Client does not include a self-service page for reviewing your own permissions. If you reach an area you're not permitted to use, the client displays a message indicating that access is restricted and, where applicable, which permission is required.

If you find you can't do something your job requires, before assuming it's a permission issue:

  1. Make sure you're in the right area of the system.
  2. Check whether the item is in a status your permissions allow you to work with.
  3. Verify you're working at the correct site (in multi-site systems).
  4. Try refreshing your browser in case of a display glitch.

If you genuinely lack a needed permission, contact your Staff Manager or ILLiad administrator. Explain what you're trying to accomplish and why you need the access. After a Staff Manager updates your permissions, you may need to log out and back in to see the change reflected in your menus.

Common Permission Scenarios

Here are illustrative setups an administrator might assign. Actual permissions vary by institution.

Circulation desk staff might be assigned a role with borrowing read and borrowing-circulation permissions (to check items in and out), and little else — enough to serve patrons at the desk without touching billing or administration.

ILL processing staff typically get a role with full read/processing/routing/write permissions in the workflow areas they handle (borrowing, lending, or document delivery), plus the associated billing and user permissions their work requires.

Student workers are assigned a student-worker role with a deliberately narrow set of permissions — for example, borrowing circulation only — so the interface shows just the tasks they've been trained on.

Department managers are usually assigned the Staff Manager role so they can manage roles, staff accounts, and permissions in addition to full operational work.

Guidance for Staff Managers

When assigning permissions, grant the minimum a role needs, review access when job responsibilities change, and update it promptly when staff leave or change positions. Keeping access current is both an operational and a security practice.

If You Need More Access

If something you need is inaccessible, it's usually a permission tied to your role. Ask your Staff Manager or ILLiad administrator to adjust it — after they do, you may need to log out and back in for the change to appear.