ROLE & PERMISSION MATRIX
Least privilege instead of shared logins.
Every role should receive only the actions and data needed for its job. V11 defines a concrete permission model ready to move into a database-backed identity system.
| Role | Capabilities | Sensitive actions | Typical scope |
|---|---|---|---|
| Organisation Admin | Users, sites, modules, policy | Invite/remove users; configure roles | Own organisation |
| Clinical User | Cases, evidence inspection, routing | No billing/admin permissions | Assigned clinical workspace |
| Evidence Reviewer | Sources, revisions, conflicts, review state | Approve/reject evidence assertions | Assigned evidence domain |
| Referral Coordinator | Referral intake, assignment, escalation | No role/billing control | Referral programmes |
| Analyst | Aggregate dashboards and reports | No patient-level editing by default | Approved datasets |
| Billing Admin | Subscription, invoices, seats, usage | No clinical/evidence editing | Commercial account |
| DI Platform Admin | Platform operations | Privileged access requiring audit/MFA | Explicit support scope only |