Under "Admin" > "Users" you can manage users and assign permissions to the users. User administration is divided into 3 areas:
- Roles: Using roles, the system administrator defines the permissions that can be assigned to users and user groups.
- User groups: Different roles and patron access can be collected into user groups, which makes it easier to manage multiple users who have the same permissions.
- Users: A user is the person who logs in to Cicero with their personal username and password. This is typically an employee.
Roles
Roles control which permissions users have in Cicero Mobile. The permissions are divided into read and write permissions. Read permissions determine which parts of Cicero Mobile the user has access to, while write permissions determine which data the user can create, edit, and delete.
By default, the roles table only shows roles that have associated Cicero Mobile permissions. However, by deselecting "Show only user roles", it is possible to see all roles that exist in Cicero - including all roles created for CMS users (see CMS setup).
It is thus possible to use the same role in several different contexts. However, we recommend that a role is only used for either CMS users or Cicero Mobile users.
Create role
- Click ”Create role”, which opens a detail view.
- Enter role name
- Specify permissions
- Permissions are shown in tables divided by the different areas in Cicero Mobile. The permissions the role should have are selected by checking them in the table. To read more about a specific permission, hold the cursor over the info icon
. The info icon will also mention if branch permissions need to be set up for the user (see Setting up branch permissions).
- Permissions are shown in tables divided by the different areas in Cicero Mobile. The permissions the role should have are selected by checking them in the table. To read more about a specific permission, hold the cursor over the info icon
- Click "Save"
User groups
User groups can be used to collect different roles into one group. For example, if several users need both librarian and purchasing permissions, these roles can be collected into one group. The selected users are then assigned this group. The users will thereby have both permission sets.
In addition, user groups can be used to restrict access to viewing patrons' information at the branch level. Users who gain access to patrons' information through user groups gain access to the branches selected for the user and the user group.
Create user group:
- Click "Create user group", which opens a detail page.
- Fill in the relevant information
- Name of the user group
- Description
- Associated roles
- Patron access
- Click ”Save”
Users
Users that have been created in Cicero are shown in a table with information about which roles and user groups the user is associated with. It is also from this page that you create new users or edit existing ones.
Create user:
- Click "Create user", which opens a detail page.
- Fill in the relevant information.
- Enter a username, name, and password.
- Specify which branches the user should have access to view patrons' information on by checking them in the "Patron access" table.
- Specify which roles and user groups the new user should be associated with. Roles and groups are selected by checking them in the tables. It is the roles and groups that determine which permissions and access the user should have in Cicero Mobile, so the roles must be created before the user can have access to Cicero Mobile.
- Click ”Save”.
Once the user has been saved, the "Permissions" tab provides an overview of which permissions the user has been given as a result of the assigned roles and/or user groups. A user can be associated with multiple roles or user groups, and will in that case have access to the combined set of those permissions.
Setting up branch permissions
When a user has been created with associated roles and user groups, the user's combined permissions are shown in the "Permissions" tab. For some of these permissions, branch-specific permissions must be set up for the permission to function correctly.
Branch permissions are set up by clicking the branch icon next to the respective permission . This opens a detail page where you can select which branches the user should have access to for this specific permission. By default, no branches are selected, so branch permissions must always be set up manually for the permission to become functional (Branch permissions can, however, also be set up via SSO against a local IdP).
NB: It may take up to 5 minutes before changes become active.