Skip to main content
Version: 26.0.29

Staff Roles

Staff Roles define what staff can view and do. Libcodesk uses role permissions for menu visibility, page access, and actions such as create, update, delete, import, renew, batch edit, and audit history.

Real library systems commonly separate permissions by job responsibility. Libcodesk follows the same principle: each staff account receives a role, and that role controls which workflows are available.

Screenshot To Add

Add screenshots of the Staff Roles table, Add Role popup, permission groups, active/inactive status, and audit history.

Role Controls

  • Menu visibility.
  • Page access.
  • Actions such as create, update, delete, import, and batch tools.
  • Audit log access.
  • Member, membership plan, member type, library, and staff administration permissions.

If a staff role is inactive, the staff user can sign in only far enough to see an access message.

Permissions And Access Control

Most features use two layers of permission:

Permission TypeWhat It ControlsExample
Menu/view permissionWhether the menu or page is visible and directly accessible.Members menu appears.
Action permissionWhether a button or operation can run inside a page.Add Member, Import Members, Batch Delete, Renew.

Give both permissions when a role needs to perform a workflow. For example, a librarian who imports members needs access to the Members page and the import action.

Use the minimum permission set that matches the job:

  • Admin: organization setup, staff roles/accounts, member setup, imports, and batch operations.
  • Librarian: the default editable operational role. It starts with day-to-day member, collection, circulation, accounts, label, and reporting permissions, while excluding administrator-only settings, security administration, and policy configuration.
  • Data Entry Operator: add/import records but not delete, role setup, or organization settings.
  • Volunteer: narrow desk tasks only, usually no settings or batch delete.
  1. Open Settings > Staff Roles.
  2. Select Add Role.
  3. Enter a clear role name and optional description.
  4. Review every permission group and select only the menus and actions that the role needs.
  5. Save the role, then assign it from Staff Accounts.
  6. Use audit history when reviewing role changes.

For normal library operations, assign the default Librarian role instead of recreating it. You can edit its description, permissions, and active status to match the responsibilities in your organization. Libcodesk does not overwrite those changes when the page is opened again. The protected Admin role remains locked.

The permission list covers organization and library administration, staff roles and accounts, members, library cards and labels, collections, circulation, accounts, notifications, calendar, reports, audit history, and the matching menu visibility controls. The Cloud setup receives this catalog from Libcodesk services. The Local setup provides the same permission set from the Standalone app.

Staff members may create, edit, or delete roles only when their own role includes the matching Staff Roles action permission. A role may grant role-management responsibility without granting unrelated organization-owner access.

Testing A Role

After creating or editing a role:

  1. Assign it to a test staff account.
  2. Sign in as that staff user or ask the staff user to verify.
  3. Confirm the menu is visible only where expected.
  4. Confirm action buttons are visible and enabled only where expected.
  5. Adjust the role if a workflow is missing or too broad.

Also check a permission-protected URL directly. Hidden buttons improve usability, while direct page and service checks prevent a staff member from bypassing the assigned role.

Do And Don'ts

Do
  • Start with a limited role and add permissions only when needed.
  • Use menu permissions and action permissions together.
  • Deactivate a role when access should pause without deleting its history.
  • Keep one protected admin role available at all times.
  • Use the built-in Librarian role for staff who need broad daily access without organization settings.
  • Review the default Librarian permissions before assigning the role, then adjust them for your workflow if required.
Don't
  • Don't give every staff member admin-level access.
  • Don't remove your own ability to manage roles unless another admin can restore it.
  • Don't use staff roles for member membership rules.
  • Don't create many almost-identical roles unless the permission difference is meaningful.

FAQ

What is a staff role?

A staff role is a permission profile. It controls which menus, pages, and actions a staff account can use.

Can a librarian have member permissions but not admin settings?

Yes. Give the role member permissions while leaving organization settings, staff role management, and license settings unavailable.

Why are menu permissions separate from action permissions?

Menu permissions control visibility. Action permissions control what can be done inside a page. A useful role should include both where needed.

What happens when a role is inactive?

Staff assigned to an inactive role are blocked from normal work and see an access message instead of continuing into the app.

Can I delete a protected role?

No. The protected Admin role exists to keep core administration safe. The default Librarian role is editable and can be assigned to staff accounts.

Can I change the default Librarian role?

Yes. Open Staff Roles, edit Librarian, select the permissions appropriate for your librarians, and save. Those changes are used when the role is assigned from Staff Accounts.

How should I build a new role quickly?

Start with the closest job responsibility, select only required menus and actions, save, then test with a staff account before assigning it broadly.

Do roles work in both Cloud setup and Local setup?

Yes. Libcodesk keeps the same role workflow shape in WebApp and Standalone app where staff roles are available.

Why is audit history useful for roles?

Permission changes can affect access immediately. Audit history helps admins inspect who changed a role and when.