{"id":2319,"date":"2024-06-12T15:35:17","date_gmt":"2024-06-12T12:35:17","guid":{"rendered":"https:\/\/www.collectionpro.fi\/ohjeet\/groups\/"},"modified":"2025-03-18T12:26:31","modified_gmt":"2025-03-18T10:26:31","slug":"groups","status":"publish","type":"ht_kb","link":"https:\/\/www.collectionpro.fi\/en\/help\/groups\/","title":{"rendered":"Groups"},"content":{"rendered":"\n<p>Each CollectionPro installation comes with some predefined system groups that cannot be removed but can be used to assign system rights and permissions. You can add your <strong>own<\/strong> groups by clicking the <strong>plus<\/strong> button in the bottom left corner. To <strong>delete<\/strong> a group, select it and click the <strong>minus<\/strong> button. To <strong>copy a group, <\/strong>select it and click on &#8220;<strong>Copy<\/strong>&#8221; in the bottom right corner of the group settings. Use the search filter to search for the name, internal name, internal comment, or reference of groups. You can also filter for the group types &#8220;easydb&#8221; and &#8220;system&#8221;.     <\/p>\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups.png\" alt=\"\" class=\"wp-image-2332\"\/><figcaption class=\"wp-element-caption\"><em><sup>Manage groups<\/sup><\/em><\/figcaption><\/figure>\n\n<p>Typical groups include:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Administrators<\/li>\n\n\n\n<li>Content Editors \/ Power Users<\/li>\n\n\n\n<li>Readers \/ Staff<\/li>\n<\/ul>\n\n<p>For example, because users can be associated with multiple groups, you can create a &#8220;Reader&#8221; group (which gives them access to records without download permissions) and a &#8220;Authorized to download&#8221; group (which additionally gives them download permissions).<\/p>\n\n<p>If you are working with different departments \/ projects that should only work on in their own pools, you should create a separate group of editors and readers for each department \/ project.<\/p>\n\n<h2 class=\"wp-block-heading\">System groups<\/h2>\n\n<p>Each CollectionPro installation has the following predefined system groups that are automatically assigned to users:<\/p>\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Group<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>All users<\/td><td>This group includes all users. Also system users, anonymous users, LDAP and SSO users, and local users. <\/td><\/tr><tr><td>All but system users<\/td><td>This group includes all users except system users, such as &#8220;deep_link&#8221; and &#8220;oai_pmh&#8221;.<\/td><\/tr><tr><td>Anonymous users<\/td><td>This group includes all users who use the system without a user account.  <br\/>Note! External access must be enabled in the base configuration. <\/td><\/tr><tr><td>Anonymous Collection Users (formerly &#8220;Pseudo users to see single collections&#8221;)<\/td><td>This group includes all users that were created when a collection was shared with external users who don&#8217;t need to sign in.<\/td><\/tr><tr><td>Fallback Group<\/td><td>This group does not include any users. When the group that is the owner of the records is deleted, this &#8220;Fallback Group&#8221; is set as the owner instead. <\/td><\/tr><tr><td>LDAP users<\/td><td>This group includes all users who log in via LDAP.<\/td><\/tr><tr><td>Normal users<\/td><td>This group includes all users created locally in CollectionPro.<\/td><\/tr><tr><td>Self-registered users<\/td><td>This group includes all users who have registered.<br\/>Note! Registration must be enabled in the base configuration. <\/td><\/tr><tr><td>SSO users<\/td><td>This group includes all users who sign in via SSO.<\/td><\/tr><tr><td>Users invited by e-mail<\/td><td>This group includes all users who were created when a collection or export was shared to an e-mail address.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Group settings<\/h2>\n\n<p>It is possible to extend the group settings with custom plugins.<\/p>\n\n<h3 class=\"wp-block-heading\">General<\/h3>\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"873\" src=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_general.png\" alt=\"\" class=\"wp-image-2321\" srcset=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_general.png 1000w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_general-600x524.png 600w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_general-768x670.png 768w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_general-50x44.png 50w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><figcaption class=\"wp-element-caption\"><em><sup>The general settings of a group<\/sup><\/em><\/figcaption><\/figure>\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Field<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>ID<\/td><td>The group identifier. Given automatically. <\/td><\/tr><tr><td>Owner<\/td><td>The name of the user who created the group.<\/td><\/tr><tr><td>Type<\/td><td>The type of group. Local groups are of the &#8220;easydb&#8221; type. Groups of type &#8220;system&#8221; cannot be deleted.  <\/td><\/tr><tr><td>Name<\/td><td>Name of the group.<\/td><\/tr><tr><td>Internal Name<\/td><td>The internal name of the group. Not shown anywhere else. <\/td><\/tr><tr><td>Comment<\/td><td>Internal comment of the group. Not shown anywhere else. <\/td><\/tr><tr><td>Reference<\/td><td>Group reference. Must be unique. <\/td><\/tr><tr><td>IP Subnet Filter<\/td><td>Add an IP subnet filter if the user should only belong to this group if they log in from specific IP subnets. CIDR notation is accepted, example: <mark style=\"background-color:#abb8c3\" class=\"has-inline-color\"> 192.168.0.0\/16, 2001:db8::\/32 <\/mark>. For more information, see the documentation <a href=\"https:\/\/pkg.go.dev\/net#ParseCIDR\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/pkg.go.dev\/net#ParseCIDR<\/a>  <\/td><\/tr><tr><td>Invert IP Subnet Filter<\/td><td>Yes \/ No<\/td><\/tr><tr><td><div class=\"cui-form-td cui-form-key\"><label>Preferences for new users<\/label><\/div><\/td><td>Displays the default settings for new users in this group. If nothing is set, the default system settings will be used.<br\/>Includes:<br\/>&#8211; search result settings<br\/>&#8211; pools for the search<br\/>&#8211; object types for the search<br\/>&#8211; data languages<br\/>&#8211; search languages<br\/>&#8211; filter on\/off <br\/><br\/>If a user belongs to multiple groups that have preferences, they will receive the preferences of the first group.<\/td><\/tr><tr><td>Created<\/td><td>The date and time the group was created.<\/td><\/tr><tr><td>Last Updated<\/td><td>The date and time the group was last updated<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h3 class=\"wp-block-heading\">System rights<\/h3>\n\n<p>Define which sections users in the user group should have access to and which features they are allowed to use. <\/p>\n\n<h3 class=\"wp-block-heading\">Permissions<\/h3>\n\n<p>Define which other users or user groups should be able to access (read, write, delete) this group and\/or the users in this group.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_permissions.png\" alt=\"\" class=\"wp-image-2334\"\/><figcaption class=\"wp-element-caption\"><em><sup>Group permissions<\/sup><\/em><\/figcaption><\/figure>\n\n<h3 class=\"wp-block-heading\">Pseudonymization<\/h3>\n\n<p>Define which data of a user in this group is retained, deleted, or pseudonymized when archiving.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"393\" src=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_pseudo.png\" alt=\"\" class=\"wp-image-2323\" srcset=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_pseudo.png 1000w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_pseudo-600x236.png 600w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_pseudo-768x302.png 768w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_pseudo-50x20.png 50w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><figcaption class=\"wp-element-caption\"><em><sup>Pseudonymization settings<\/sup><\/em><\/figcaption><\/figure>\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Option<\/th><th>Description<\/th><th>Available for field<\/th><\/tr><\/thead><tbody><tr><td>Keep<\/td><td>When a user is archived, the contents of the field are preserved.<\/td><td>&#8211; Login<br\/>&#8211; First name<br\/>&#8211; Last name<br\/>&#8211; Display name<br\/>&#8211; Department<br\/>&#8211; Email<\/td><\/tr><tr><td>Randomize<\/td><td>When a user is archived, the contents of the field are replaced with a random string.<\/td><td>&#8211; Login<br\/>&#8211; First name<br\/>&#8211; Last name<br\/>&#8211; Display name<br\/>&#8211; Department<\/td><\/tr><tr><td>Clear<\/td><td>When a user is archived, the contents of the field are deleted.<\/td><td>&#8211; Login<br\/>&#8211; First name<br\/>&#8211; Last name<br\/>&#8211; Display name<br\/>&#8211; Department<br\/>&#8211; Email<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h3 class=\"wp-block-heading\">Authentication Services<\/h3>\n\n<p>If you are using a third-party user management such as LDAP or SSO, you can define a group mapping here and automatically map groups used in SSO or LDAP to groups in CollectionPro whenever a user logs in.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_authentication.png\" alt=\"\" class=\"wp-image-2336\"\/><figcaption class=\"wp-element-caption\"><em><sup>Group authentication services<\/sup><\/em><\/figcaption><\/figure>\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Method<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>Group name (eq)<\/td><td>The group name from LDAP\/SSO must match this string exactly.<\/td><\/tr><tr><td>Regular expression (regexp)<\/td><td>Group names from LDAP\/SSO must match a regular expression. Example: students.* corresponds to the LDAP\/SSO group students and the group students-alumni, but not to the group named student. For more information, see <a href=\"https:\/\/pkg.go.dev\/regexp#Match\" target=\"_blank\" rel=\"noreferrer noopener\">the documentation https:\/\/pkg.go.dev\/regexp#Match<\/a>.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h3 class=\"wp-block-heading\">Users<\/h3>\n\n<p>Displays all users who belong to this group.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"993\" height=\"277\" src=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_users.png\" alt=\"\" class=\"wp-image-2325\" srcset=\"https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_users.png 993w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_users-600x167.png 600w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_users-768x214.png 768w, https:\/\/www.collectionpro.fi\/wp-content\/uploads\/2025\/03\/groups_users-50x14.png 50w\" sizes=\"(max-width: 993px) 100vw, 993px\" \/><figcaption class=\"wp-element-caption\"><em><sup>Users in a group<\/sup><\/em><\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>CollectionPro has predefined groups that can be used to manage permissions and permissions. Users can be assigned to multiple groups, which makes it possible to combine different permissions. For example, you can create a &#8220;Reader&#8221; group that gives users access to records without download permissions, and a &#8220;Download permissions&#8221; group that additionally grants download permissions. If you&#8217;re working with different departments or projects, it&#8217;s recommended that you create a Editor and Reader group for each department or project. Managing groups is done through the user interface, where you can add, delete and copy groups and filter groups with different criteria.    <\/p>\n","protected":false},"author":2,"comment_status":"open","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[86,77],"ht-kb-tag":[],"class_list":["post-2319","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-permissions","ht_kb_category-for-administrators"],"_links":{"self":[{"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/ht-kb\/2319"}],"collection":[{"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/comments?post=2319"}],"version-history":[{"count":3,"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/ht-kb\/2319\/revisions"}],"predecessor-version":[{"id":2330,"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/ht-kb\/2319\/revisions\/2330"}],"wp:attachment":[{"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/media?parent=2319"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/ht-kb-category?post=2319"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.collectionpro.fi\/en\/wp-json\/wp\/v2\/ht-kb-tag?post=2319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}