shared user accounts in koha

Shared user accounts in Koha

We're  often asked in one way or another why libraries shouldn't use shared accounts for staff members, for example using a Circulation account rather than individual accounts in Koha for each member who performs circulation tasks. While it may be faster in the beginning to create a handful of accounts instead of one account per staff member, there are very good reasons to spend the time up front making individual users: 

  1. Koha's permissions are very granular (and getting more granular each version); ensuring that each staff member has appropriate permissions assigned to them per their role is the best way to ensure that staff can perform their assigned duties while also not having more access than is required. Not only does this protect patron data and privacy, but also helps to avoid confusion and unintentional access/changes made by staff with more access than their role requires. 
  2. With any staff turnover (either staff leaving or transferring to new positions), shared accounts are easily missed and old passwords that were known by former staff may persist, posing risk to patron data and privacy. Individual accounts are easy to decommission and are less likely to be overlooked during the offboarding process.
    1. This is especially important to consider in the case where staff may pose an insider threat- that is, a staff member or other employee who either accidentally or purposefully poses a risk to the library. 
  3. Internal audits of actions taken by staff are unclear and hard to parse with shared accounts, making correction of incorrect processes, providing additional training, or addressing potential misuse of the system very hard or impossible to undertake by management. 
  4. If there is ever a need for an external audit, individual accounts provide accountability for your staff and their actions within the system.