Roles & access control
NHCIP is a multi-tenant SaaS platform. Access is governed by a four-tier role hierarchy and a permission matrix. Only Super Admins can change these definitions; every API request is checked against them server-side.
Super Admin
Full control of NHCIP: all tenants, system admins, billing, government systems, and the role/permission model itself.
System Admin
Runs day-to-day platform operations: approves and manages tenants, monitors connections, views analytics and government systems.
Tenant Admin
Manages a single organisation (tenant): its users, API connections, uploads and subscription. Scoped to that tenant only.
Tenant User
Clinicians and records staff. Verify patients, view and submit records within their tenant, subject to patient consent. No admin rights.
| Capability | SASuper |
SYSystem |
TATenant Adm |
TUTenant User |
|---|
Tip: click any cell to cycle its access level (None → View → Manage → Full). Changes are illustrative in this prototype.