This functionality is available for Item Bank Managers.
This article will guide you through the new advanced permissions feature for Item Banks. You will learn how to use a Three-Part Access Model involving the Item Bank, Access Groups and Author user roles (including Custom User Roles (CURs)) to achieve more granular control over content, along with best practices for implementation
How to Control Access
The Item Bank permissions functionality introduces a powerful way to control access to your content by combining Access Groups and user roles/Author Custom User Roles (CURs). Crucially, a user's entry to an Item Bank and its Public content is granted by the combination of their membership in an Access Group and the user role linked to that group. Access to Private content within that bank requires explicit item-level sharing in addition to bank membership (refer to article, Understanding Private and Public Content).
If a user does not have this specific combination, they will only gain access if they possess the overarching Extended Access role.
Think of the relationship as a Three-Part Access Model:
- The Content: The specific Item Bank (what is being accessed).
- The Actors: The Access Group(s) assigned to that Item Bank (who has access).
- The Actions: The Author user role(s) associated with those Access Groups (what they can do).
To create an Item Bank, it must have at least one Access Group assigned to it.
Planners with access to the Item Bank can add Public Question Sets to tests without additional sharing. Private Question Sets must be shared with the Planner individually or through an Access Group.
Visualising the Access Models
The diagrams below illustrate how the Three-Part Access Model is applied to both granular and simplified access scenarios across multiple Item Banks. You can configure the model in whichever way best serves the needs of your institution.
Granular access controls
This may suit an institution who has a decentralised approach to Authoring - i.e. each module or subject area has its own Authors, so variations in access are required across Item Banks.
This granular access example only displays two Access Groups, although you will be able to add up to five Access Groups per Item Bank (see the Best Practice Recommendations section below for more details).
Access varies based on whether the Content Privacy is Private or Public.
Private Content:
Public Content
Simplified access controls
This may suit an institution that has a more centralised approach to Authoring - i.e. Authoring activities are managed by a central team for all Item Banks.
Private Content
Public Content
Setting up Access Groups and Author user roles
When managing an Item Bank (via the Properties tab), you will associate one or more Access Groups with one or more Author user roles. As illustrated in the screenshot below, this association defines the permissions for the users within that group.
You can assign up to five distinct Access Groups to a single Item Bank, and each of those groups can be linked to one or multiple CURs. If you anticipate needing more than five Access Groups for a single bank, please reach out to our Service Desk for assistance.
We strongly recommend that you carefully consider the level of access control required. While increasing the number of Access Groups offers highly precise permissions, it also increases the administrative effort needed to keep the member lists updated.
Nested Access Groups
Users can inherit Item Bank access through nested Access Groups. If you are a member of a parent Access Group, and a child Access Group within it has been assigned to an Item Bank, you will automatically gain access to that Item Bank. The level of access you receive is determined by the role on your user profile that matches the role affiliated with the child Access Group for that Item Bank.
Users who have access through inheritance are indicated by an icon next to their name in the Access tab of the Item Bank. Hovering over the icon displays a tooltip showing the inheritance path that granted them access.
Note on Blank Custom User Roles
It is possible to keep the Custom user role(s) field blank for an Access Group. In the case where only one Access Group is defined for an Item Bank and the CURs field is left blank, only users who are members who possess the Author system role will gain access to that Item Bank. This is an intentional mechanism to restrict access to certain Item Banks to only your existing Author users.
Best Practice Recommendations for Granular Access
If you require a complex or granular approach to permissions—meaning different users need different levels of access across various Item Banks—we recommend a formulaic approach:
- CUR Setup (Reusable and Static): We advise creating and publishing your required Author CURs (e.g., View Only, Edit Only, Full Access) upfront. Since these roles define the actions users can take, they can be reused across multiple Item Banks and should therefore remain static. You can use the Starter CURs we provide (Author View Only CUR, Author View and Edit Only CUR, Author Full Access CUR), or edit the Starter CURs to meet your needs, or entirely create your own CURs (see Author Custom User Roles (CURs): create, edit, delete, and assign to users for more details).
-
Formulaic Naming: Create Access Groups specific to the Item Bank and level of access. For example, for an Item Bank named 'Civil Engineering' you might create:
- Access Group: 'Engineering Authors', linked to the Author Full Access CUR.
- Access Group: 'Engineering Viewers', linked to the Author View-only CUR.
Linking a specific Author CUR is the key to completing the Three-Part Access Model and defining the exact level of access (e.g., View, Edit, or Full) for the users in that Access Group. Otherwise you could leave the Custom user role(s) field blank and assign those users the Author system role (see section above)
Recommendation: We suggest starting with only a few Access Groups per Item Bank initially and trialling this configuration to assess its effectiveness. Keeping to a formulaic approach for all Item Banks will also help with tracking which access controls are required each time an Item Bank is created, reducing administrative burden.
Simple Access Model
If a simpler access model is sufficient, you can follow these steps:
- Create one Access Group and assign all your Authors to it.
- Link this Access Group to the Author Full Access CUR or simply grant the Author system role and leave the CUR field blank.
The Author System Role and Default Access
It is important to understand the difference between CURs and system roles:
- Author System Role: Adding a user to an Access Group, associating that group with an Item Bank and granting the user the Author system role gives them access to the Item Bank’s Public content. It does not grant access to Private content unless that content has been explicitly shared with them. The Author system role also allows them to create their own content within the Item Bank.
- Custom User Roles (CURs): Use Author CURs to grant specific permission capabilities across the Item Bank (e.g., View-Only or Edit-Only). To restrict access to specific individual items within a bank, set those items to Private and manage access via item-level sharing."
- Author System Role + Extended Access: Granting a user the Author system role plus Extended Access gives them access to ALL content across ALL Item Banks. This acts as a super user role. Use this role only for users who require a broad, system-wide content overview.
- Planners: Planners with access to the Item Bank can add Public Question Sets to tests without additional sharing. Private Question Sets must be shared with the Planner individually or through an Access Group.
- All users with default, system-wide access (Authors, Planners, Extended Access users) are listed in the 'All' view within the Access tab for Item Banks.
Next steps
Now that you understand the Three-Part Access Model for setting up Item Bank permissions, take a look at the Access tab for Item Banks. This article will guide you through managing and monitoring exactly who has access to the content within the Item Bank.