The following tables list all library-level default privileges and group-level privileges available in IRM Server. In most IRM implementations, the default settings for library-level privileges don't need to be modified.

Table: Library-level privileges

Library-level default privilege name

Description

Default setting

Change own password

Denotes whether a specific user can change their own password.

true

Manage Membership Policies

Create, edit, and delete membership policies. To manage security policies, you must have the File Plan Admin privilege or the File Part Manager privilege with at least View access to the matter.

false

RM: Standards Admin

Create, edit, and delete standards and template folders.

false

RM: Create Non-Templated File Parts

  • Create file parts that don't use a template.

  • Add/Remove Children or greater.

false

RM: File Part Manager

This privilege grants delete-level permissions to file parts that exist within a matter where the user has at least view-level permissions.

false

RM: Delete File Parts

  • With this privilege, a file part can't be deleted if it contains another file part, unless the child file part has the same retention schedule and the same trigger date as the parent. A child file part that has no retention schedule falls under the retention rules of its parent and can be deleted.

  • The user must have both the privilege and view-level permissions to the file part for it to be destroyed.

false

RM: Checkout/Checkin Records

Check-out and check-in file parts and boxes.

false

Approve and Cancel Requests

Search for and approve or cancel other users' requests. Enables records managers and file clerks to manage the requests queue. Any user can cancel their own requests, or requests which were created on the user's behalf.

false

RM: Retention Management

Manage retention policies and retention holds, and execute retention functions.

false

RM: Modify Bar Codes

Modify bar code label IDs.

false

View all Library Users and Groups

Controls if users can view and browse other users in the library. If this isn't granted, the user can't view, browse, or search for users in the system.

This privilege also provides the following additional functionality in IRM Web Client:

  • Create Delivery Request for (on behalf of) other users.

  • Reassign physical records to other users.

  • Apply additional filters pertinent to the additional visible content.

This privilege could be granted to a user with—for example, a legal secretary position, or similar.

false

View Audit History

Lets the user view the activity logs in the records management system.

false

Import Data

Controls whether a user can use the Data Loader tool to import bulk information from other sources.

NOTE: To add an IRM library, you must have an IRM account with the Import Data privilege. This privilege lets the account import data and is specified during library setup.

false

RM: Allows the user to modify records and file-parts based on their security access

Denotes that a user is allowed to modify records and file-parts based on their security access.

false

RM: Enables the user to create a file part

Denotes that a user is allowed to create file parts.

false

RM: Enables the user to see records irrespective of supplemental markings

Denotes that a user can view records irrespective of supplemental markings.

false

RM: Allows the user to manage supplemental markings

Denotes that a user is allowed to manage supplemental markings.

false

RM: Enables the user to modify file parts based on their security access

Denotes that a user is allowed to modify file parts based on their security access.

false

RM: Allows the user to perform the cutoff operation

Denotes that a user is allowed to perform the cut-off operation.

false

RM: Allows the user to process trigger event commands

Denotes that a user is allowed to process trigger event commands.

false

RM: Enables the user to perform vital records review update functions

Denotes that a user is allowed to perform vital records review update functions.

false

RM: Enables the user to perform the close operation

Denotes that a user is allowed to perform a close operation.

false

RM: Allows the user to move a record

Denotes that a user is allowed to move a record.

false

RM: Allow the user to perform vital records review update functions on own records

Denotes that a user is allowed to perform vital records review update functions on their own records.

false

RM: Allow the user to process disposition event commands

Denotes that a user is allowed to process disposition event commands.

false

RM: Allows the user to access federated records

Denotes that a user is allowed to access federated records. This enables Work Servers to be browsed, for example in IRM Web Client.

false

RM: Allows the user to perform operation on a closed record

With this privilege, a user can manage closed records, like updating metadata on the record or adding a new child record under a closed folder.

false

RM: Allows the user to run label reports

Denotes that a user is allowed to process label reports.

true

Allows the user to process disposition events that have a destroy event type

Denotes that user is allowed to process events for disposition that are set to destroy.

true

Allows the user to perform bulk updates

Denotes that a user is allowed to perform bulk record updates.

false

Table: Group-level privileges

Group-level privileges name

Description

Default setting

File Plan Admin

This privilege grants full control to every single item in the file plan, including all clients, matters, and file parts.

Not Granted

File Part Manager

This privilege grants delete-level permissions to file parts that exist within a matter where the user has at least view-level permissions.

Not Granted

Box Admin

Create, edit, and delete boxes. You can print labels for boxes only if you've been granted this privilege.

Not Granted

Location Admin

Create, edit, and delete locations.

Not Granted

Standards Admin

Create, edit, and delete standards and template folders.

Not Granted

Thesaurus Admin

Create, edit, and delete thesaurus entries.

Not Granted

Create Non-Templated File Parts

Create file parts that don't use a template.

Add/Remove Children or greater.

Not Granted

Delete File Parts

  • With this privilege, a file part can't be deleted if it contains another file part, unless the child file part has the same retention schedule and the same trigger date as the parent. A child file part that has no retention schedule falls under the retention rules of its parent and can be deleted.

  • The user must have both the privilege and view-level permissions to the file part for it to be destroyed.

Not Granted

Checkout/Checkin Records

Check-out and check-in file parts and boxes.

Not Granted

Approve and cancel request

Search for, approve, and cancel other users' requests. Enables records managers and file clerks to manage the requests queue. Any user can cancel their own requests, or requests which were created on the user's behalf.

Not Granted

Retention Management

Manage retention policies and retention holds, and execute retention functions.

Not Granted

Modify Bar Code

Modify bar code label IDs.

Not Granted

Manage Membership Policies

Create, edit, and delete membership policies. To manage security policies, you must have the File Plan Admin privilege or the File Part Manager privilege with at least View access on the matter.

Not Granted

View all Library Users and Groups

Controls if users can view and browse other users in the library. If this isn't granted, the user can't view, browse, or search for users in the system.

Not Granted

View Audit History

Lets the user view the activity logs in the records management system.

Not Granted

Import Data

Controls whether a user can use the Data Loader tool to import bulk information from other sources.

Not Granted

Move Record

Denotes that a user is allowed to move a record.

Not Granted

Create File Part

Denotes that a user is allowed to create file parts.

Not Granted

Edit File Part

Denotes that a user is allowed to modify file parts based on their security access.

Not Granted

Cutoff

Denotes that a user is allowed to perform the cut-off operation.

Not Granted

Close

Denotes that a user is allowed to perform a close operation.

Not Granted

Process Trigger Events

Denotes that a user is allowed to process trigger event commands.

Not Granted

Process Disposition Events

Denotes that a user is allowed to process disposition event commands.

Not Granted

Process Destroy Disposition Events

Denotes that a user can process disposition events that have a destroy event type.

Granted

Vital Records View

Denotes that a user is allowed to perform vital records review update functions.

Not Granted

Own Vital Records Review

Denotes that a user is allowed to perform vital records review update functions on their own records.

Not Granted

Manage Supplemental Markings

Denotes that a user is allowed to manage supplemental markings.

Not Granted

Disregard Supplemental Markings

Denotes that a user is allowed to access records regardless of any supplemental markings applied.

Not Granted

View Federated Records

In addition to ‌regular permissions and privileges, a user must have this privilege to see records.

Not Granted

Manage Closed Records

Denotes that a user can manage closed records, like updating metadata of the record or adding a new child record under a closed folder.

Not Granted

Run Label Reports

Denotes that a user can run a label report to print physical file part labels.

Granted

Security Policy Manager Administrator

Denotes that Security Policy Managers are allowed to interact with the IRM Server, through a sign-in specified in Security Policy Manager's configuration. This specified sign-in must be granted this privilege and this privilege should be used only by a sign-in for SPM agent.

Not Granted

Bulk Update

Denotes that a user is allowed to perform bulk updates.

Not Granted

Approve Disposition

Denotes that a user is allowed to view and action disposition approvals, in IRM Web Client. Users with this privilege can view and action the approvals-related items that they are named as the responsible attorney for.

NOTE: File Plan Administrators can view and action all approvals-related items without this Approve Disposition privilege.

Not Granted