Procedure
What can this person see
Walks through listing the records and actions a given member of staff holds access to, and the relationships behind them.
This procedure lists the records and actions a given member of staff holds access to, and the relationships behind them. It is the forward view of a permission: it starts from one person and lays out everything they may reach now.
Before you start
List what a person can reach
- 1
Open the access panel
Open Cirith Manager, the access panel inside Nexus Manager, and search for the member of staff by name.
- 2
Read the roles they hold
The panel lists the role the person holds at each site, and the capabilities each role carries through its own grants and its inheritance.
- 3
Read their live duty scope
Read the live scope the current shift derives: the units, locations and services the person covers now. This scope decides which of their capabilities reach a patient.
- 4
List the records they reach
The panel lists the patient records the person currently reaches, each with the relationship behind it. A record appears because a role, a care team and an active admission line up for it.
- 5
Expand an entry to see the path
Open an entry to read the resolution path, the chain from the person through their role and relationship to that record. The path shows why the access holds.
The set moves with the shift
The reachable set is bound to the live duty scope, so it moves as the shift moves. The panel shows the set as it stands at the moment you read it.
A capability a role carries reaches a patient only where the person's current scope covers the service and the patient holds an active admission. As the shift hands over, the set of records the person reaches changes with the scope.
Common questions
Why does the list change during the day?
A person's reachable set follows their live duty scope, which the current shift derives. When the shift hands over, the units and services they cover change, and the set changes with them.
Does a site administrator see records at another site?
Site permissions stay within their own site. The panel lists a person's access at each site separately, so cross-site reach shows only where a current relationship grants it.
Where do the capabilities in a role come from?
Each tool declares the capabilities it guards, and a role holds a set of them together with the set it inherits from its parent role.
Test a change to a person's roles or relationships before applying it in simulating a change.