Many institutions manage electronic resource access under licence agreements that distinguish between on-campus and off-campus use.
At our institution, some user groups are permitted to access only a subset of resources remotely, while additional resources are available only when the user is physically on campus.
We would like to move all access, both on-campus and off-campus, through OpenAthens in order to:
• centralise access management;
• improve usage monitoring and reporting;
• reduce reliance on separate IP-based access workflows.
However, OpenAthens currently does not appear to support dynamically assigning Permission Sets based on the user's source IP address or access location.
As a result, it is difficult to support scenarios where the same user group:
• can access Resource A from any location;
• can access Resource B only when connected from the institutional network; and
• receives the appropriate permissions automatically based on where they are connecting from.
Requested enhancement:
Allow OpenAthens to evaluate a user's access location (for example, whether the user is connecting from a recognised campus IP range or from outside the institution) during authentication and dynamically apply different Permission Sets accordingly.
This would enable institutions to manage complex licensing requirements while using OpenAthens as a single access management platform for both on-campus and off-campus access.
It would also support organisations seeking to replace legacy IP-based access management with a fully OpenAthens-managed access model without compromising compliance with publisher licence agreements.
Feedback from the OpenAthens community suggests that this challenge is not unique to a single institution and affects organisations that need to enforce different access rights based on both user type and access location.