US-45 names six roles but gives no matrix, so this is a proposal. Nine roles: the six named in US-45, two read-only roles (Viewer and Auditor) and a system-level Super admin who owns Data sources. C create, R read, U update, D delete (a draft of your own, never a submitted record, which is cancelled instead), X run a task such as Poll NPHIES. A role with no letters never sees the menu item. One user can hold several roles, and the user gets the union of them (never with Administrator).
Module
Admin
Receptionist
Approval officer
Claims officer
A/R
A/P
Viewer
Auditor
Super admin
Home
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Inbox
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Journeys
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Worklist
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Patients
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Eligibility
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Prior Authorization
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Advanced Auth
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Claims
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Claim Batch
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Payments
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Communications
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
APA Communication
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Poll NPHIES
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Status and cancel
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Data sources
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Data source changes
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Organization
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Users
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Roles and permissions
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Security policy
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Audit log
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
API access
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Go-live readiness
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Integrations
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Quarantined responses
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
ICD-10 codes
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
CRUDX
Actions beyond the module letters
Action
Who
Story
Override a calculated net amount (reason required, audited as a financial override). A second person above a threshold is a second-release item
Approval officerClaims officer
US-01, OP-7
Resume or delete your own drafts. Delete never applies to a submitted record: cancel it instead
ReceptionistApproval officerClaims officerA/P
US-38, OP-7
Assign a case to a colleague, or take it over (same role and facility, logged). Escalating to another role is an Assign
Change a user's role, facility or work email. Never your own role (blocked and logged)
Admin
US-53, OP-10
Give one user several roles at the same or different organization nodes. Administrator is never combined with a transactional role
Admin
OP-8
Administer at group scope: roles, security policy, API, integrations, quarantine, ICD-10 codes
Admin
US-45b, OP-8
Administer at facility scope: users, unlock and two-step reset for one facility only
Admin
US-45b, OP-8
Deactivate or unlock a user (never the last active administrator). Open items of the leaver are handed over
Admin
US-54, US-55, OP-2
Read the audit log (cannot edit or delete an entry)
AdminAuditorSuper admin
US-13, US-13b, OP-5
Maintain the ICD-10 code list
Admin
US-42
Replay an unattributed NPHIES response (logged)
Admin
quarantine, OP-10
Sign in with the break-glass account (sealed, MFA, raises an alert)
Admin
OP-10
Add, change or remove a data source, change the mode of an entity (typed confirmation and reason once data exists), set the fallback and replay quarantined rows. All audited
Super admin
DS-1 to DS-7
See the status of the data sources, read only
AdminSuper admin
DS-1, DS-8
Read the data source change trail (cannot edit or delete an entry)
AuditorSuper admin
DS-7
Ask an administrator for access from the No access screen
Everyone
US-45
See and end your own sessions, read your own sign-in history, set your notifications
Everyone
US-41, US-51
Administrator, two scopes
Scope
What an Administrator can do
Story
Group
Roles and permissions, security policy, API access, integrations, quarantine, ICD-10 codes, organization and data scope.
US-44b, US-45b, OP-8
Facility
Users, unlock and two-step reset for that facility only. No roles, security policy or API.
US-45b, OP-8
Never
Administrator is never combined with a transactional role on the same user, and nobody changes their own role.
OP-8, OP-10
Super admin, system level
Question
Decision in these wireframes
What does a Super admin see?
Home, Inbox, Profile and Journeys, then Data sources, Integrations, Security policy, Audit log, API access and Go-live readiness. Nothing else.
What does a Super admin never see?
Patients, eligibility, prior authorization, claims, payments, the worklist and search. No patient data is readable from this role, so a system role cannot be used to browse records. Organization, Users and Roles stay with the Administrator.
Where does it work?
Outside any facility: scope shows RaneemHCP platform, All groups. There is no facility switcher.
Who may change Data sources?
Only the Super admin. The group Administrator sees status read only (overview, entity, history, health). The Auditor reads the change trail. Everyone else sees only a source badge on records.
Why Integrations, Security policy and API access?
They are platform rules shared by all facilities, and they sit next to Data sources (feeds, credentials, system access). The Administrator keeps them at group scope too, so a small site needs only one of the two roles.
Role migration (US-46)
Super admin is not offered when mapping existing users. It is created once at install and cannot be combined with any other role.
How today's roles map onto the nine
Role in the portal today
Becomes
Why
admin
Administrator
Same name, but it reads clinical and finance modules instead of changing them (open question 2).
provider, operations
Receptionist
Front desk work: eligibility, patients, worklist.
preauth, clinical
Insurance approval officer
Prior authorization and Advanced Authorization.
billing
Claims officer
Claims and batches.
finance
A/R or A/P
Split by task: reconciliation is A/R, payment notices are A/P (open question 1).
viewer
Viewer (default)
The safe default for anyone who is not mapped at go-live (US-46). Read only, so a read-only user never gains create rights. The administrator can change it afterwards.
(no legacy role)
Auditor
New. For compliance and privacy review of the audit log, users and roles.
(no legacy role)
Super admin
New and not mapped from any portal role. Created by Raneem IT at install, outside every facility, and never offered in Assign roles to existing users. It is not a user role the Administrator can give, so no one raises their own rights. A named person holds it, with two-step sign in, and every use is audited.
People who have no role of their own
The six US-45 roles cover the daily desk work. These people are covered by scope, several roles on one user and peer takeover, not by new roles.
Person
Covered by
Medical coder
Claims officer (claims) or Approval officer (prior authorization)
Clinician
No portal role. Diagnoses arrive through the inbound feed (US-47) and the approval officer attaches documents
Finance manager
A/R at group or facility scope, plus CSV export in the first release
Supervisor
Peer takeover inside a role (logged). An optional Team lead role is a second-release item