Concept explainer
The authorisation model
Explains how Cirith Manager decides access from relationships between staff, patients and the organisation, rather than from static role lists.
Cirith Manager decides every access in Pensieve from the relationships between staff, patients and the hospital model, rather than from a static list of roles. A role names the actions a person may take. A current relationship to the patient decides which patients those actions reach.
One decision point
An authorisation decision is the platform's answer to one question: may this person take this action on this thing, in this moment. Every read and every write asks that question once, in one place. Each tool routes its decision through the one decision point rather than holding a rule of its own.
Because the decision is made in one place, the interface a person sees is a projection of it. The dock a member of staff lands in shows the actions their role and relationships allow, so the screen and the decision stay in step.
Roles and relationships
Access is decided from two things together: the person's role, and their relationship to the patient in front of them.
A role names the actions a person may take at a site. A care relationship connects a member of staff to a patient, established by an admission at a site and the patient's consent for that site. A role on its own settles the actions a person may take; the care relationship settles which patients those actions reach.
This is relationship-based access. The governing rule is the clinical one: my family doctor, my ward, my patient, rather than every doctor. Access flows along the relationships between staff, patients and the hospital model.
Why a role list falls short
A static role list answers what a person is, and stops there. It carries the person's title, and stays silent on the patient in front of them. Deciding from the role together with a current care relationship keeps every access tied to a present reason to see a record.
The two planes
Access resolves against two planes that meet at the care relationship.
The patient-consent plane carries the patient's decisions about their own record. It is patient-owned, one record per patient, held once outside the tenancy structure and read across sites under the patient's consent. The site-permission plane carries roles, postings, care teams and field sensitivity, held within a single site.
The care relationship joins the two. It materialises the patient's consent into real access and it is the precondition for the site's permissions to reach the record.
The factors combine
Record access holds when several factors hold together, as an intersection, rather than one broad check.
| Factor | What it establishes |
|---|---|
| The person's role | The actions the person may take at the site |
| A current care relationship | That the person is caring for this patient now |
| Consent for the site | That the patient allows this site to hold their record |
| Field sensitivity clearance | That the reader is cleared for a sensitive field |
| The patient's source directives | That the data's source site stays in view for this reader |
Each factor is a separate term, and access materialises where they meet. Emergency access can override the last two factors under a logged path, and it stays clear of the patient's own record and of an admission already in progress.
The three answers
A decision returns one of three answers.
| Answer | Meaning |
|---|---|
| Permit | The person may take the action now |
| Refuse | The action stands outside what the person may do |
| Held for context | The action becomes permitted once a named condition is supplied |
When a fault prevents the platform from reaching the information a decision needs, it returns an error that names the fault, and it holds the answer open rather than reading a fault as a refusal. A refusal is a genuine authorisation answer, kept distinct from an outage.
Seeing access
Cirith Manager makes the decision legible before and after it is applied. An administrator sees who can see this patient, looks up what one person can see, and simulates a change against the live model before applying it. Each of these reads the same relationships the live decision reads.
Does a senior role open every record?
A senior role widens the actions a person may take. It reaches a patient's record when a current care relationship connects the two, decided the same way for every role.
What establishes the care relationship?
An active admission at a site, together with the patient's consent for that site. When the admission closes, the relationship lapses after a short defined period, and the record narrows again.
Where does emergency access fit?
Emergency access is a defined path a treating clinician invokes with a stated reason. It overrides the patient's source directives and site sensitivity markings, stays logged in full, and is surfaced to the patient.
Read how the patient lens narrows a record to the reader with a current reason to see it.