Skip to content

Concept explainer

Roles and relationships

Explains how roles and care relationships combine to grant access, so the right staff reach the right records at the right time.

Access in Pensieve comes from two things working together. A role sets what a member of staff may do, and a care relationship decides which patients those actions reach, so the right staff reach the right records at the right time.

What a role carries

A role is a named set of capabilities at a site. Each tool declares the capabilities it guards, and a role holds a set of them.

A role inherits from one parent role. Its capabilities are its own together with those it inherits, merged and deduplicated, so one role carries the full set a person needs. A site membership holds one role, which keeps the source of a person's authority to a single place.

  • clinician
    • ward doctor
      • consultantholds its own capabilities plus every inherited one

A role narrows to the services it covers. A role can list eligible services, and when the person's live duty scope covers one of them the role applies; otherwise the platform sets that role aside for the request, so a service-scoped role reaches only its own services.

What a relationship carries

A care relationship is the tie between a member of staff and a patient. It rests on the patient's admission at the site, the patient's consent, and the person's place on the care team, unit or service.

A care relationship is current. It holds while the person sits on the patient's care team at a site with an active visit and consent, and it lapses when any of those ends. The relationship decides which patients a role's capabilities reach.

Combining the two

The two inputs meet at the point of a decision. A role answers what a person may do. A relationship answers which patient they may do it for. Effective access is where the two coincide.

Figure 1.Diagram showing a role and a care relationship combining into the actions a person may take on one patient's record now.
Role onlyRole and relationship
Ties access to a current reasonAbsentPresent
Reflects the person's live shiftAbsentPresent
Reaches only this patient's recordsPartialPresent

The live duty scope

The duty roster derives a live scope for each member of staff: the units, locations, services and assets their current shift covers. Nexus Manager holds the roster and resolves this scope.

The live scope is the authority for who may act now. A shift-based check reads it, so a role's reach follows the person onto and off their shift. The section on duty rosters sets out how a shift derives this scope.

Delegation and grants

Access also passes by a grant. A patient grants a site access on the consent plane. A site administrator grants an employee or a unit access on the site plane. A grant carries an expiry, so the access ends on its own.

A guardian holds a proxy for a young patient, and a defined age ladder moves control of sensitive categories from the guardian to the young person as they grow older. A time-limited share code grants a named person temporary access.

Guards on the grant path

A grant that would raise the granter's own authority is refused at the point of writing, which holds a person to the authority they already carry. A grant to a sensitive category requires a witness: a second credentialed clinician, identity-verified, other than the granter.

Common questions

Can a person stack two roles at one site?

A site membership holds one role. That role inherits from a parent, so it carries the full capability set a person needs through inheritance rather than stacking.

Why did access change when the shift changed?

A role's reach follows the live duty scope, which the current shift derives. As the shift changes, the units and services the role covers change with it.

What ends a care relationship?

A completed visit past its grace period, the end of a care-team place, or a withdrawn consent each end the relationship, and access closes with it.

See who currently holds access to a patient in who can see this patient.