Skip to main content

iiQ IT Pro - Permissions Functionality

iiQ IT Pro features attribute-based permission controls that streamline staff access to tickets, assets, and user accounts. By setting criteria such as user type, grade level, department, and asset mode, this approach reduces the need for manual workarounds and ensures precise control over user capabilities.

In addition to standard permission options found in other modules, iiQ IT Pro provides the added advantage of conditional filters that can be applied to specific permission categories. This knowledge base guide will explore the general concepts and the available attribute-based filters.

iiQ IT Pro customers can access these attribute-based conditional filters in all of their modules.

Learn more about Permissions here:
Permissions KB Guide

Use Case Examples:

  • Allow agents to only view and manage specific models (e.g., Chromebooks) at their school, rather than accessing every asset in the building.

  • Allow faculty and staff to add followers during the ticket submission process, while excluding Students and Parents/Guardians from the list of visible options.

  • Allow librarians to view and work on tickets with the 'device/hardware' ticket type without granting access to other tickets.


General Concepts & Logic

"Only" Logic

When setting up condition filters, "ONLY" frames the permissions being granted.

  • Example: If issue type "Screen cracked/broken" is set as a condition group for Tickets (View/Work/Resolve), users can only interact with those specific ticket types. They cannot access other ticket types unless other policies are stacked.

Exclude Selected

The Exclude Selected toggle is available for various condition filters, allowing you to easily filter out specific items.

Additive Permissions

If a user receives the same permission from multiple permission policies, and one policy grants unrestricted access (no filters), the exclusion has no effect.

  • Example:

    • Policy A: Grants "View Tickets" with Issue Type "Exclude: Screen Cracked."

    • Policy B: Grants "View Tickets" with no filters.

    • Result: The user can view all tickets, including "Screen Cracked" tickets, because Policy B grants unrestricted access.

  • Tip: For an exclusion to work as intended, every permission policy that grants the same permission must either exclude the same items or not grant the permission at all.

Filter Management

  • Remove Filters: To remove any filter, hover over the filter element and click the X.

  • Search: If a long list of attributes is available, the system displays the first 100 items; use the search box to locate additional attributes.


Attribute- Based Condition Filters

To provide more granular policy configuration based on specific attributes, additional condition filters are available.

  • Access: Navigate to Permissions > Specific Policy, scroll to the relevant section (Tickets, Assets, or Users), and click the Filter button.

The additional condition filters can be applied to the following permission sections and groups:

  • Assets

  • Tickets

  • Users

Product Scope: Filter options are product-specific. For example, Facilities-related models will not appear when configuring IT Ticketing policies.

Data Sourcing:

  • Attributes and filter lists available for selection depend on your district's site configuration.

  • Filters such as OU Path and Grade levels pull directly from your active directory sync and User Explorer data.

Custom Fields Conditional Filters

For both Asset and User permissions, custom fields are automatically included as filter options once they are created and applied to the corresponding data entity. The following custom field types are supported:

  • IP Address

  • Phone

  • Select

  • MultiSelect

  • iiQ Location

  • Model

  • Asset

  • Asset Status

  • iiQ Room

  • On Off

  • Number (and Number Range)

  • Date (and Date Time, Date Range)

Did this answer your question?