Skip to content

Concept explainer

The authorisation model

Explains how Cirith Manager decides access from relationships between staff, patients and the organisation, rather than from static role lists.

Cirith Manager decides every access in Pensieve from the relationships between staff, patients and the hospital model, rather than from a static list of roles. A role names the actions a person may take. A current relationship to the patient decides which patients those actions reach.

One decision point

An authorisation decision is the platform's answer to one question: may this person take this action on this thing, in this moment. Every read and every write asks that question once, in one place. Each tool routes its decision through the one decision point rather than holding a rule of its own.

Because the decision is made in one place, the interface a person sees is a projection of it. The dock a member of staff lands in shows the actions their role and relationships allow, so the screen and the decision stay in step.

Roles and relationships

Access is decided from two things together: the person's role, and their relationship to the patient in front of them.

A role names the actions a person may take at a site. A care relationship connects a member of staff to a patient, established by an admission at a site and the patient's consent for that site. A role on its own settles the actions a person may take; the care relationship settles which patients those actions reach.

This is relationship-based access. The governing rule is the clinical one: my family doctor, my ward, my patient, rather than every doctor. Access flows along the relationships between staff, patients and the hospital model.

Why a role list falls short

A static role list answers what a person is, and stops there. It carries the person's title, and stays silent on the patient in front of them. Deciding from the role together with a current care relationship keeps every access tied to a present reason to see a record.

Figure 1.Diagram showing the patient plane and the site plane joined by an active care relationship, resolving to one access decision.

The two planes

Access resolves against two planes that meet at the care relationship.

The patient-consent plane carries the patient's decisions about their own record. It is patient-owned, one record per patient, held once outside the tenancy structure and read across sites under the patient's consent. The site-permission plane carries roles, postings, care teams and field sensitivity, held within a single site.

The care relationship joins the two. It materialises the patient's consent into real access and it is the precondition for the site's permissions to reach the record.

The factors combine

Record access holds when several factors hold together, as an intersection, rather than one broad check.

FactorWhat it establishes
The person's roleThe actions the person may take at the site
A current care relationshipThat the person is caring for this patient now
Consent for the siteThat the patient allows this site to hold their record
Field sensitivity clearanceThat the reader is cleared for a sensitive field
The patient's source directivesThat the data's source site stays in view for this reader

Each factor is a separate term, and access materialises where they meet. Emergency access can override the last two factors under a logged path, and it stays clear of the patient's own record and of an admission already in progress.

The three answers

A decision returns one of three answers.

AnswerMeaning
PermitThe person may take the action now
RefuseThe action stands outside what the person may do
Held for contextThe action becomes permitted once a named condition is supplied

When a fault prevents the platform from reaching the information a decision needs, it returns an error that names the fault, and it holds the answer open rather than reading a fault as a refusal. A refusal is a genuine authorisation answer, kept distinct from an outage.

Seeing access

Cirith Manager makes the decision legible before and after it is applied. An administrator sees who can see this patient, looks up what one person can see, and simulates a change against the live model before applying it. Each of these reads the same relationships the live decision reads.

Does a senior role open every record?

A senior role widens the actions a person may take. It reaches a patient's record when a current care relationship connects the two, decided the same way for every role.

What establishes the care relationship?

An active admission at a site, together with the patient's consent for that site. When the admission closes, the relationship lapses after a short defined period, and the record narrows again.

Where does emergency access fit?

Emergency access is a defined path a treating clinician invokes with a stated reason. It overrides the patient's source directives and site sensitivity markings, stays logged in full, and is surfaced to the patient.

Read how the patient lens narrows a record to the reader with a current reason to see it.