Skip to content

Procedure

Simulating a change

Walks through testing a change to roles or relationships in simulation, so its effect on access is clear before it is applied.

This procedure tests a change to roles or relationships in simulation, so its effect on access is clear before it is applied. The simulation reads the live relationships and leaves them unchanged, and applying the change is a separate, recorded step.

Before you start

Done.You hold an access-governance role in Cirith Manager.
Done.You know the change you want to test.

Simulate the change

  1. 1

    Open the simulator

    Open the simulator in Cirith Manager, the access panel inside Nexus Manager.

  2. 2

    Describe the change

    Describe the change you want to test: grant or remove a role, add or end a care relationship, or change a patient's consent. The simulator accepts one change or a set of them together.

  3. 3

    Run against the live relationships

    Run the simulation. It reads a pinned snapshot of the current relationships and holds the change against it, so the result reflects the hospital as it stands now.

  4. 4

    Read who gains and who loses

    The simulator returns two lists: the people who gain access under the change, and the people who lose it. Each entry names the person, the record, and the access that shifts.

  5. 5

    Expand a sample to see the path

    Open an entry to read the resolution path behind a gain or a loss. The path shows the chain of role and relationship that the change adds or removes.

  6. 6

    Apply or discard

    Apply the change to make it real, or discard it to leave the relationships as they were. Applying is a separate step, and the platform records who applied it and when.

Simulation leaves the relationships unchanged

A simulation reads a pinned snapshot of the live relationships and leaves them unchanged. The change takes effect only when you apply it, and applying it is recorded as its own event in the access log.

Simulate a change
Change: grant ward doctor to K. Rao
Gains access
K. Rao: medicine ward records
Loses access
Existing staff keep their access
Show resolution path
Apply or discard
A described change held against the live relationships, returning the staff who gain access and the staff who lose it.

Why simulate first

A change to a role or a relationship can widen or narrow access for many people at once. Role inheritance means a single grant flows to every role beneath it, and a change to a shift moves the reach of everyone on it.

Running the simulation first shows the full effect against the live relationships, so a reviewer reads the consequence before the change lands. The two lists, read adversarially, surface a widening a reviewer wants to hold back.

Common questions

Does running a simulation change anything?

A simulation reads the current relationships and leaves them unchanged. The change takes effect only when you apply it as a separate step.

Does the simulation use live data?

Yes. It runs against a pinned snapshot of the current relationships, so the two lists reflect the hospital as it stands, rather than a stale copy.

What does the who-loses list cover?

It names the people whose access the change removes, each with the record and the relationship that the change ends. It is the counterpart to the who-gains list.

Read the emergency access route for urgent care in emergency access.