Concept explainer
Who can see the money
Explains how access to financial data is scoped by role and site, which figures each finance user sees, and how that access is logged.
This page explains how access to financial data is scoped by role and site, which figures each finance user sees, and how that access is logged. It sets out the mechanism a reviewer can test rather than a claim to take on trust.
Two things decide access
Every read of a financial figure passes through one authorisation decision. That decision reads two things together: the person's role, which sets the figures they may see, and the site, which sets the accounts those figures come from. A billing role at one site reads the accounts of that site, and the same role gives a narrower view of the money than the finance head holds.
Cirith Manager makes the decision, and Vault shows a finance user only what the decision returns. The screen a person opens is a projection of what their role and site allow.
What each role sees
The role sets which categories of figure a finance user opens. The grid below reads across the money surfaces a hospital runs on.
| Finance head | Billing clerk | Cashier | Insurance desk | |
|---|---|---|---|---|
| Charges and invoices | Present | Present | Present | Present |
| Payments and deposits | Present | Present | Present | Partial |
| Claims and payer terms | Present | Partial | Absent | Present |
| Receivables and ageing | Present | Partial | Absent | Partial |
| Ledger and period totals | Present | Absent | Absent | Absent |
| Site-wide totals across accounts | Present | Absent | Absent | Absent |
A cashier settling a bill reads the invoice and posts the payment. An insurance desk reads the claim and the payer terms behind it. The finance head reads the whole book, including the ledger and the totals across accounts. Each user works within the figures their role returns.
Scoped to the site
One deployment serves an organisation and all of its sites, and financial data is scoped to a site. A finance user at a site reads that site's accounts, and access reaches another site's figures only under defined conditions. This keeps each site's money within its own boundary while the organisation still holds one view where the finance head is entitled to it. Read how the boundary holds in the site boundary.
The patient's own view
A patient sees their own account and their own statement. That patient-facing statement is held separate from the staff figures, so a patient reads what they owe and what a payer covered without reaching the wider finance surfaces. The staff figures and the patient statement draw on the same charges, so the two views agree on the amount.
Every read is logged
Every read and every write of a financial figure writes one access entry: who acted, which figures they touched, and when. The entry is written alongside the action it describes, so a committed action carries its record. This lets the finance head answer, for any account, who looked at the money and what they did. Read how that question is answered in answering who saw this record.
Attribution holds on a shared counter
On a shared billing counter, each member of staff signs in as themselves. The access log names the person who acted, so the money stays attributable even where several clerks use one screen through a shift.
Common questions
Does a role alone open the finance figures?
Access reads the role and the site together. The role sets the figures, and the site sets the accounts those figures come from, so a role at one site reads that site's book.
Can a finance user at one site read another site's figures?
Financial data is scoped to a site. Access reaches another site's figures only under defined conditions, and each such reach is decided and logged like any other.
What does a patient see of the money?
A patient sees their own account and statement: what they owe and what a payer covered. That statement is held separate from the staff finance surfaces.
Read the decision that sits behind every read in the authorisation model.