← Admin console
Platform security

Roles & access control

NHCIP is a multi-tenant SaaS platform. Access is governed by a four-tier role hierarchy and a permission matrix. Only Super Admins can change these definitions; every API request is checked against them server-side.

Role hierarchy
SA

Super Admin

Tier 1 · Platform owner

Full control of NHCIP: all tenants, system admins, billing, government systems, and the role/permission model itself.

3 users
SY

System Admin

Tier 2 · NHCIP operations

Runs day-to-day platform operations: approves and manages tenants, monitors connections, views analytics and government systems.

11 users
TA

Tenant Admin

Tier 3 · Organisation admin

Manages a single organisation (tenant): its users, API connections, uploads and subscription. Scoped to that tenant only.

238 users
TU

Tenant User

Tier 4 · Organisation staff

Clinicians and records staff. Verify patients, view and submit records within their tenant, subject to patient consent. No admin rights.

4,120 users
Permission matrix
Full create, edit, delete Manage edit within scope View read-only None no access
Capability
SASuper
SYSystem
TATenant Adm
TUTenant User

Tip: click any cell to cycle its access level (None → View → Manage → Full). Changes are illustrative in this prototype.

Permission model — last changed 12 May 2026 by Super Admin.
Saved