Create and Manage Users
To create and manage users, run the IRM Library Manager installer on the administrative user's device. The Library Manager of this user installation can then be connected to the IRM server running in the Cloud. For more information about setting up this connection, refer to Setting up Library Manager for connection to IRM Cloud Service.
Task | Application |
|---|---|
Install and connect Library Manager to IRM Cloud Service | Library Manager |
Configure the Library | Library Manager |
Install Records Manager Components | Various |
- Add a Trustee
- Add a Person
- Account Tab-Add Person
- Libraries Tab-Add Person
- Profile Tab
- Extended Properties Tab
- Add a Trustee Container
- Account Tab-Trustee Container
- Libraries Tab-Trustee Container
- Trustee Managers Tab
- Add a Group
- Account Tab-Group
- Members Tab
- Privileges Tab
- Assign a Default Home Location to Individual Users
Add a Trustee
Expand the Realms Settings node, right-click the master realm, and select Add. The Add Trustee dialog opens.
The tabs and options in the Add Trustee dialog change depending on the selected Class:
For Person, the Account, Libraries, Profile, and Extended Properties tabs are displayed.
For Group, the Account, Members, and Privileges tabs are displayed.
For System Admin Group and Tooluser Group, the Account and Members tabs are displayed.
For Organizational Unit (OU), Country, Domain, and Locality, the Account, Libraries, and Trustee Managers tabs are displayed.
For more information, refer to the following guidelines when adding trustees:
A person is a trustee. A trustee is a user account. Trustees may be added to a master realm, or to a trustee container (such as an OU, Country, Domain, and Locality). A trustee can also be added as a member to a group, including System Admin Group and Tooluser Group, which conveys corresponding privileges. Within a realm, each trustee must be unique (have a unique UID).
Groups provide a way to organize trustees based upon membership. Unlike trustee containers, you can't add trustees, groups, or trustee containers to a group; instead, you can control membership in the group using the Members tab. A trustee can be a member of multiple groups.
Selecting Group, System Admin Group, or Tooluser Group as the Class type disables most of the Account tab options because members don't inherit properties from groups.
Trustee containers function as the name implies and can contain additional trustee containers, groups, and trustees.
Add a Person
A Person class is a trustee. You can add trustees to a realm or trustee container, or to the membership list in a group. Information about the fields on each tab is provided in the following sections:
Account Tab-Add Person
The Account tab contains the following options:
RDN is the relative distinguished name of the realm, which can be up to 128 characters in length.
Class determines what you're adding, which can be a Person, Group, or trustee container (OU, Domain, Country, or Locality). Changing this option changes the tabs that are displayed in the Add Trustee dialog.
Label lets you enter a text string, which can be used by client applications for sorting. By default, this is the first letter of the Class type.
UID is the user ID.
Domain is your company domain name (such as yourcompany.com). If you enter a domain name, users will be required to enter the same domain name when logging into IRM Server.
Location is the default location for this user. This location is used for the circulation of records in a IRM implementation.
Parent is the name of the immediate parent realm or trustee container.
Password and Confirm Password allow you to specify the sign-in password for the account.
If Password never expires is checked, IRM Server never prompts the user to change the password.
If Force password change is checked, IRM Server prompts the user to change their password during the next sign-in attempt.
Account disabled determines if the user is active. If checked, the trustee can't sign in to the library.
Change own password can be set to one of the following:
Inherited: This is the default privilege level when adding a master realm. Selecting Inherited tells IRM Server to grant or deny a trustee the ability to change their password based upon the parent realm or trustee container settings. If IRM Server can't determine whether this privilege is granted or revoked for this user, IRM Server checks the Change own password library privilege. For more information about configuring default library privileges, refer to Library-Level Default Privileges in Configure User Privileges.
Grant: This privilege level explicitly grants a trustee the ability to change their password.
Revoke: This privilege level explicitly denies a trustee the ability to change their password.
Change own profile can be set to one of the following:
Inherited: This is the default privilege level when adding a master realm. Selecting Inherited tells IRM Server to grant or deny a trustee the ability to change their profile based upon the parent realm or trustee container settings. If IRM Server can't determine whether this privilege is granted or revoked, IRM Server checks the Change own profile library privilege. For more information about configuring default library privileges, refer to Library-Level Default Privileges in Configure User Privileges.
Grant: This privilege level explicitly grants a trustee the feature to change their profile.
Revoke: This privilege level explicitly denies a trustee the feature to change their profile.
NOTE: Revoke supersedes grant. Revoking a privilege at the realm-level revokes the privilege for all trustees and trustee containers in that realm, even if the trustee or trustee container privilege is set to grant.
Libraries Tab-Add Person
The Libraries tab contains the following options:
The Preferences Facility is where trustee-related information (such as user configurable options) is stored. You must have created at least one facility if you want to select the preferences facility. Select Inherit to use the preferences facility specified in the parent realm or trustee container.
The Homepage WorkSpace setting and its corresponding check box are now deprecated and can be ignored.
The Trustee Accessible Libraries identifies the libraries available to the trustees in the realm. You can select additional libraries (if available) from the Realm Accessible Libraries list to add to the Trustee Accessible Libraries. A realm may have several accessible libraries, but you may choose to limit the libraries available to the trustees in the realm. Select Inherit to use the accessible libraries specified in the parent realm or trustee container.
Profile Tab
The Profile tab contains the following options:
General trustee information, including name and email
Phone numbers associated with the trustee, including business, mobile, and fax
Default language
Timezone
Extended Properties Tab
The Extended Properties tab contains the following options:
Several predefined properties
Any additional properties you applied to the Trustee object
Add a Trustee Container
Trustee containers include OU (organization unit), Country, Domain, and Locality. Information about the fields in each tab is provided in the following sections:
Account Tab-Trustee Container
The Account tab contains the following options:
RDN is the relative distinguished name of the trustee container, which can be up to 128 characters in length.
Class determines what you are adding, which can be a Person, Group, or trustee container (OU, Domain, Country, or Locality). Changing this option changes the tabs that are displayed in the Add Trustee dialog.
Label lets you enter a text string, which can be used by client applications for sorting. By default, this is the first letter of the Class type (first two letters for OU).
Parent is the name of the immediate parent realm or trustee container.
Entry disabled determines if trustees can be added to the container.
Change own password can be set to one of the following:
Inherited: This is the default privilege level when adding a master realm. Selecting Inherited tells IRM Server to grant or deny a trustee the ability to change their password based upon the parent realm or trustee container settings. If IRM Server is unable to determine if this privilege is granted or revoked for this user, IRM Server checks the Change own password library privilege. For more information about configuring default library privileges, refer to Library-Level Default Privileges in Configure User Privileges.
Grant: This privilege level explicitly grants a trustee the ability to change their password.
Revoke: This privilege level explicitly denies a trustee the ability to change their password.
Change own profile can be set to one of the following:
Inherited: This is the default privilege level when adding a master realm. Selecting Inherited tells IRM Server to grant or deny a trustee the ability to change their profile based on the parent realm or trustee container settings. If IRM Server can't determine whether this privilege is granted or revoked, IRM Server checks the Change own profile library privilege. For more information about configuring the default library privileges, refer to Library-Level Default Privileges in Configure User Privileges.
Grant: This privilege level explicitly grants a trustee the ability to change their profile.
Revoke: This privilege level explicitly denies a trustee the ability to change their profile.
Class: Determines what you're adding, which can be a Person, Group, or trustee container (OU, Domain, Country, or Locality). Changing this option changes the tabs displayed in the Add Trustee dialog.
NOTE: Revoke supersedes grant. Revoking a privilege at the realm-level revokes the privilege for all trustees and trustee containers in that realm, even if the trustee or trustee container privilege is set to grant.
Libraries Tab-Trustee Container
The Libraries tab contains the following options:
The Preferences Facility is where trustee-related information, such as user configurable options is stored. You must have created at least one facility if you want to select the preferences facility. To use the preferences facility specified in the parent realm or trustee container, select Inherit.
The Homepage WorkSpace setting and its corresponding check box are now deprecated and can be ignored.
The Trustee Accessible Libraries identifies the libraries available to the trustees in the realm. You can select additional libraries (if available) from the Realm Accessible Libraries list to add to the Trustee Accessible Libraries. A realm may have several accessible libraries, but you may choose to limit the libraries available to the trustees in the realm. To use the accessible libraries specified in the parent realm or trustee container, select Inherit.
Trustee Managers Tab
The Trustee Managers tab contains the following options:
Selecting Realms displays all the available realms under Trustee Selection.
Selecting a realm or trustee container under Realms displays all the available members of the selected realm or container under Trustee Selection.
Use Add to designate one or more trustees as trustee managers.
Add a Group
Groups provide a way to organize trustees based on membership. Unlike trustee containers, you can't add trustees, groups, or trustee containers to a group; instead, you control membership in the group using the Members tab. A trustee can be a member of multiple groups.
The System Admin Group and Tooluser Group are predefined groups which can be used to provide users with privileges corresponding to the System Admin account and Tooluser roles, as follows:
System Admin Group members have access to Library Manager, Records Manager Data Loader, and LDAP Sync. As part of this group, you can manage and reset administrative access for member user accounts.
Tooluser Group members can add libraries, access Application Designer, and access Data Model Loader.
Information about the fields on each tab is provided in the following sections:
Account Tab-Group
The Account tab contains the following options:
RDN is the relative distinguished name of the group, which can be up to 128 characters in length.
Class determines what you're adding, which can be a Person, Group, or trustee container (OU, Domain, Country, or Locality). Changing this option changes the tabs displayed in the Add Trustee dialog.
Label lets you enter a text string, which can be used by client applications for sorting. By default, this is the first letter of the Class type (first two letters for OU).
Parent is the name of the immediate parent realm or trustee container.
Entry disabled determines if trustees can be added to the group.
Members Tab
The Members tab contains the following options:
Selecting Realms displays all the available realms under Trustee Selection Tree.
Selecting a realm or trustee container under Realms displays all the available members of the selected realm or container under Person Selection.
To add one or more trustees to the group membership list, select Add.
Privileges Tab
The Privileges tab contains individual privileges which can be granted or revoked at the group level. These privileges apply to manually created groups or groups imported from LDAP. These privileges are explained in detail in Group-Level Privileges in Configure User Privileges.
Assign a Default Home Location to Individual Users
To simplify the circulation of records, IRM Server lets you define a default location for each user. You must create the locations for your organization in the IRM Desktop Client for Records Managers before you can associate the location to a specific user. For information about adding locations, refer to IRM Desktop Client for Records Managers User Guide.
To associate a location to a specific user
Locate the trustee (user) in the master realm.
Right-click the trustee and select Edit.
In the Edit Trustee dialog, next to the Location field, select .
In the Select Home Location dialog, select the specific location for the user and then select OK.
To save the changes made to this user's details, select OK again.