The following tables list all library-level default privileges and group-level privileges available in IRM Server. In most IRM implementations, the default settings for library-level privileges don't need to be modified.
Table: Library-level privileges
Library-level default privilege name | Description | Default setting |
|---|---|---|
Change own password | Denotes whether a specific user can change their own password. | true |
Manage Membership Policies | Create, edit, and delete membership policies. To manage security policies, you must have the File Plan Admin privilege or the File Part Manager privilege with at least View access to the matter. | false |
RM: Standards Admin | Create, edit, and delete standards and template folders. | false |
RM: Create Non-Templated File Parts |
| false |
RM: File Part Manager | This privilege grants delete-level permissions to file parts that exist within a matter where the user has at least view-level permissions. | false |
RM: Delete File Parts |
| false |
RM: Checkout/Checkin Records | Check-out and check-in file parts and boxes. | false |
Approve and Cancel Requests | Search for and approve or cancel other users' requests. Enables records managers and file clerks to manage the requests queue. Any user can cancel their own requests, or requests which were created on the user's behalf. | false |
RM: Retention Management | Manage retention policies and retention holds, and execute retention functions. | false |
RM: Modify Bar Codes | Modify bar code label IDs. | false |
View all Library Users and Groups | Controls if users can view and browse other users in the library. If this isn't granted, the user can't view, browse, or search for users in the system. This privilege also provides the following additional functionality in IRM Web Client:
This privilege could be granted to a user with—for example, a legal secretary position, or similar. | false |
View Audit History | Lets the user view the activity logs in the records management system. | false |
Import Data | Controls whether a user can use the Data Loader tool to import bulk information from other sources. NOTE: To add an IRM library, you must have an IRM account with the Import Data privilege. This privilege lets the account import data and is specified during library setup. | false |
RM: Allows the user to modify records and file-parts based on their security access | Denotes that a user is allowed to modify records and file-parts based on their security access. | false |
RM: Enables the user to create a file part | Denotes that a user is allowed to create file parts. | false |
RM: Enables the user to see records irrespective of supplemental markings | Denotes that a user can view records irrespective of supplemental markings. | false |
RM: Allows the user to manage supplemental markings | Denotes that a user is allowed to manage supplemental markings. | false |
RM: Enables the user to modify file parts based on their security access | Denotes that a user is allowed to modify file parts based on their security access. | false |
RM: Allows the user to perform the cutoff operation | Denotes that a user is allowed to perform the cut-off operation. | false |
RM: Allows the user to process trigger event commands | Denotes that a user is allowed to process trigger event commands. | false |
RM: Enables the user to perform vital records review update functions | Denotes that a user is allowed to perform vital records review update functions. | false |
RM: Enables the user to perform the close operation | Denotes that a user is allowed to perform a close operation. | false |
RM: Allows the user to move a record | Denotes that a user is allowed to move a record. | false |
RM: Allow the user to perform vital records review update functions on own records | Denotes that a user is allowed to perform vital records review update functions on their own records. | false |
RM: Allow the user to process disposition event commands | Denotes that a user is allowed to process disposition event commands. | false |
RM: Allows the user to access federated records | Denotes that a user is allowed to access federated records. This enables Work Servers to be browsed, for example in IRM Web Client. | false |
RM: Allows the user to perform operation on a closed record | With this privilege, a user can manage closed records, like updating metadata on the record or adding a new child record under a closed folder. | false |
RM: Allows the user to run label reports | Denotes that a user is allowed to process label reports. | true |
Allows the user to process disposition events that have a destroy event type | Denotes that user is allowed to process events for disposition that are set to destroy. | true |
Allows the user to perform bulk updates | Denotes that a user is allowed to perform bulk record updates. | false |
Table: Group-level privileges
Group-level privileges name | Description | Default setting |
|---|---|---|
File Plan Admin | This privilege grants full control to every single item in the file plan, including all clients, matters, and file parts. | Not Granted |
File Part Manager | This privilege grants delete-level permissions to file parts that exist within a matter where the user has at least view-level permissions. | Not Granted |
Box Admin | Create, edit, and delete boxes. You can print labels for boxes only if you've been granted this privilege. | Not Granted |
Location Admin | Create, edit, and delete locations. | Not Granted |
Standards Admin | Create, edit, and delete standards and template folders. | Not Granted |
Thesaurus Admin | Create, edit, and delete thesaurus entries. | Not Granted |
Create Non-Templated File Parts | Create file parts that don't use a template. Add/Remove Children or greater. | Not Granted |
Delete File Parts |
| Not Granted |
Checkout/Checkin Records | Check-out and check-in file parts and boxes. | Not Granted |
Approve and cancel request | Search for, approve, and cancel other users' requests. Enables records managers and file clerks to manage the requests queue. Any user can cancel their own requests, or requests which were created on the user's behalf. | Not Granted |
Retention Management | Manage retention policies and retention holds, and execute retention functions. | Not Granted |
Modify Bar Code | Modify bar code label IDs. | Not Granted |
Manage Membership Policies | Create, edit, and delete membership policies. To manage security policies, you must have the File Plan Admin privilege or the File Part Manager privilege with at least View access on the matter. | Not Granted |
View all Library Users and Groups | Controls if users can view and browse other users in the library. If this isn't granted, the user can't view, browse, or search for users in the system. | Not Granted |
View Audit History | Lets the user view the activity logs in the records management system. | Not Granted |
Import Data | Controls whether a user can use the Data Loader tool to import bulk information from other sources. | Not Granted |
Move Record | Denotes that a user is allowed to move a record. | Not Granted |
Create File Part | Denotes that a user is allowed to create file parts. | Not Granted |
Edit File Part | Denotes that a user is allowed to modify file parts based on their security access. | Not Granted |
Cutoff | Denotes that a user is allowed to perform the cut-off operation. | Not Granted |
Close | Denotes that a user is allowed to perform a close operation. | Not Granted |
Process Trigger Events | Denotes that a user is allowed to process trigger event commands. | Not Granted |
Process Disposition Events | Denotes that a user is allowed to process disposition event commands. | Not Granted |
Process Destroy Disposition Events | Denotes that a user can process disposition events that have a destroy event type. | Granted |
Vital Records View | Denotes that a user is allowed to perform vital records review update functions. | Not Granted |
Own Vital Records Review | Denotes that a user is allowed to perform vital records review update functions on their own records. | Not Granted |
Manage Supplemental Markings | Denotes that a user is allowed to manage supplemental markings. | Not Granted |
Disregard Supplemental Markings | Denotes that a user is allowed to access records regardless of any supplemental markings applied. | Not Granted |
View Federated Records | In addition to regular permissions and privileges, a user must have this privilege to see records. | Not Granted |
Manage Closed Records | Denotes that a user can manage closed records, like updating metadata of the record or adding a new child record under a closed folder. | Not Granted |
Run Label Reports | Denotes that a user can run a label report to print physical file part labels. | Granted |
Security Policy Manager Administrator | Denotes that Security Policy Managers are allowed to interact with the IRM Server, through a sign-in specified in Security Policy Manager's configuration. This specified sign-in must be granted this privilege and this privilege should be used only by a sign-in for SPM agent. | Not Granted |
Bulk Update | Denotes that a user is allowed to perform bulk updates. | Not Granted |
Approve Disposition | Denotes that a user is allowed to view and action disposition approvals, in IRM Web Client. Users with this privilege can view and action the approvals-related items that they are named as the responsible attorney for. NOTE: File Plan Administrators can view and action all approvals-related items without this Approve Disposition privilege. | Not Granted |