Role-Based
Navigation
A safe starting guide for mapping staff responsibilities to modules, permissions, record scope, and the first workflows they should practice.
Front Desk
Start with patient search/creation, appointments, OPD queue placement, and billing handoff.
Clinical Teams
Use OPD, admissions, emergency, prescriptions, diagnostics history, and patient timelines.
Emergency Desk
Practice triage intake, capacity review, escalation, bed claim, handoff, and disposition updates.
Diagnostics
Walk through lab orders, sample status, verification, radiology handoff, and patient-linked reports.
Revenue & Supply
Review service rates, invoices, claims, pharmacy stock, inventory movements, and valuation reports.
People Operations
Review staff profiles, attendance, leave, payroll exceptions, org scope, and approval responsibilities.
Governance Admins
Audit access, role changes, settings, report builder usage, and production readiness checks.
Give the least access that completes the job.
HMIS permissions are module/action based, while record and org scopes decide how far a user can see inside patient and people records.
- 1
Confirm the staff account, role, department/org unit, and record-scope permission before the first login.
- 2
Open only the modules required for the user journey, then verify navigation from the dashboard and handbook search.
- 3
Run a supervised practice case using demo data: patient lookup, workflow action, audit check, and handover note.
- 4
Review privacy rules: do not export, share, screenshot, or paste patient data outside approved hospital workflows.
- 5
For admins, verify permission-catalog parity before adding new permissions to roles or UI links.
Technical Architecture
| Field | Type | Institutional Role |
|---|---|---|
| role_id | UUID | Role binding used by dashboard navigation and API checks. |
| permission_key | String | Module/action capability such as patients:view or billing:create. |
| record_scope | Enum | Patient visibility boundary: self-created, self-assigned, or all. |
| org_scope | Enum | People-operation visibility boundary for assigned organizational units. |
Note: Sensitive fields use AES-256 field-level encryption where applicable.
Governance & Power
roles:viewusers:viewaudit:viewsettings:adminTreat patient, employee, payroll, billing, media, and AI output as hospital-confidential data. Use exports, screenshots, chat, and report sharing only when the user role and workflow explicitly allow it.
Training attestation before production access: docs/info/training/CURRICULUM.md · Record completions via POST /api/v1/governance/training/complete