HomeSettingsRoles and permissions
NPHIES polled 3 min agoSources healthy Search

Roles and permissions

Who can create, read, update, delete and execute in each module.

Wireframe state
Default roles. Eight roles ship with the portal: the six named in US-45 plus Viewer and Auditor, both read only. What a user can see and do follows their role. Buttons a role cannot use are shown disabled. Which facility they see is set separately, see Data scope. Adding your own roles needs approval first.

Roles

Role Today's portal role Users Scope
Administrator US-45Configures the portal: users, roles, organization, security, audit and API access. Reads every module for troubleshooting. Works at group scope or, as a facility administrator, for one facility only. admin 2 All facilities Edit
Receptionist US-45Front desk. Checks eligibility, finds patients and follows the worklist. provider, operations 4 Per facility Edit
Insurance approval officer US-45Requests and follows prior authorizations, answers Advanced Authorization and payer questions. preauth, clinical 3 Per facility Edit
Claims officer US-45Prepares and submits claims and batches, resubmits rejected ones and answers payer questions. billing 4 Per facility Edit
Accounts receivable (A/R) US-45Follows what payers owe: claim status, payment reconciliation and chasing rejections. Can work across several facilities. finance 2 Per facility Edit
Accounts payable (A/P) US-45Records payment notices and checks them against reconciliation. Often the same person as A/R (two roles on one user). finance 2 Per facility Edit
Viewer (read-only) AddedLooks, never acts. The safe default at go-live (US-46) for management, trainees and anyone nobody mapped. Never creates, changes or sends anything. viewer 6 Per facility Edit
Auditor (read-only) AddedCompliance and privacy review. Reads the audit log, users and roles across the group. Cannot change or delete anything, so the person who grants access is not the person who audits it. (new) 1 All facilities Edit

Administrator scopes

Group administrator Facility administrator
Works at The Al Raneem Group node and everything below it One facility node, for example Facility A
Can do Organization and structure, roles and permissions, users in any facility, security policy, API access, integrations, ICD-10 codes, audit log Users of that facility, unlock accounts, two-step reset for those users
Cannot do Cannot be combined with a transactional role on the same account Cannot change roles, security policy, API access or the organization. Cannot see other facilities
Reads for troubleshooting Every module, across all facilities Every module, in its own facility
Assigned by Raneem IT at go-live, then another group administrator A group administrator, from the user page

Reading the matrix

  • A/R has a status checker and replies on messages linked to a claim they chase. Prior authorization messages stay with the approval officer.
  • D on Eligibility, Prior Authorization and Claims means drafts only: you can delete your own drafts, never a sent request.
  • Override of a calculated financial value needs a second approver. The override and both names go in the audit log.
  • Viewer and Auditor only ever hold R. Nobody can add C, U, D or X to them.

Permission matrix

Module Admin Receptionist Approval officer Claims officer A/R A/P Viewer Auditor
Everyone
Home CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
Inbox CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
Journeys CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
Work
Worklist CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
Patients CRUDX CRUDX CRUDX CRUDX None None CRUDX CRUDX
Eligibility CRUDX CRUDX CRUDX CRUDX None None CRUDX CRUDX
Prior Authorization CRUDX CRUDX CRUDX CRUDX None None CRUDX CRUDX
Advanced Auth CRUDX None CRUDX CRUDX None None CRUDX CRUDX
Claims CRUDX None CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
Claim Batch CRUDX None None CRUDX CRUDX None CRUDX CRUDX
Finance
Payments CRUDX None None CRUDX CRUDX CRUDX CRUDX CRUDX
Communications
Communications CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
APA Communication CRUDX None CRUDX None None None None None
Tools
Poll NPHIES CRUDX None CRUDX CRUDX None None None None
Status and cancel CRUDX None CRUDX CRUDX CRUDX None None CRUDX
Administration
Data sources CRUDX None None None None None None None
Data source changes None None None None None None None CRUDX
Organization CRUDX None None None None None None CRUDX
Users CRUDX None None None None None None CRUDX
Roles and permissions CRUDX None None None None None None CRUDX
Security policy CRUDX None None None None None None CRUDX
Audit log CRUDX None None None None None None CRUDX
API access CRUDX None None None None None None None
Go-live readiness CRUDX None None None None None None CRUDX
Integrations CRUDX None None None None None None None
Quarantined responses CRUDX None None None None None None None
ICD-10 codes CRUDX None None None None None None None
Account
Profile CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX CRUDX
C CreateR ReadU UpdateD DeleteX Execute (poll, cancel)
Scope set to All facilities. In the live portal the counts and lists on this page follow it.
Scope set to Facility A. In the live portal the counts and lists on this page follow it.
Scope set to Facility B. In the live portal the counts and lists on this page follow it.
Scope set to Facility C. In the live portal the counts and lists on this page follow it.