Skip to content

Procedure

Change what someone can do

Adjust a member of staff's access in Cirith Manager, choose the roles and relationships that apply, and confirm the change.

Access in Pensieve comes from a role and a care relationship working together. You adjust a member of staff's access here in Cirith Manager, choose the roles and relationships that apply, and confirm the change.

Two levers, one decision

A role sets what a person may do. A care relationship sets which patients those actions reach. You reach both from the same panel, and a decision draws on the two together.

Before you start

Done.You hold an access-governance role in Cirith Manager.
Done.You know the person whose access you are changing.
Outstanding.You know the change you want to make.

What you can change

Cirith Manager is the access panel inside Nexus Manager. You change a person's access along two axes.

The role

The role is the named set of capabilities the person carries at a site. A site membership holds one role, and that role inherits its parent's capabilities, so one role carries the full set the person needs. Change the role and the capabilities change with it.

The relationship

A care relationship is the tie between the person and a patient. It rests on the patient's admission, their consent, and the person's place on a care team, unit or service. Add or end a relationship and the patients the role reaches change with it.

Change the access

  1. 1

    Open Cirith Manager

    Open the access panel in Cirith Manager, inside Nexus Manager. The panel opens on the current site.

  2. 2

    Find the person

    Search for the member of staff by name or sign-in name. Their current access appears, with the role they hold and the relationships in force. To read the full picture, open what this person can see.

  3. 3

    Choose the change

    Describe the change. Grant or replace the role, add or end a care relationship, or adjust the services a role covers. The panel accepts one change or a set of them together.

  4. 4

    Simulate the change

    Run the change against the live relationships. The simulator returns two lists: the people who gain access and the people who lose it. Read both before you go on. The section on simulating a change sets out the two lists in full.

  5. 5

    Read the resolution path

    Open an entry to read the resolution path behind a gain or a loss. The path shows the chain of role and relationship the change adds or removes, so the effect reads plainly.

  6. 6

    Apply and confirm

    Choose Apply to make the change real, or Discard to leave the relationships as they were. Applying is its own step, and the access log records who applied it and when.

Simulation leaves the relationships unchanged

A simulation reads a pinned snapshot of the live relationships and holds the change against it. The change takes effect only when you apply it, and applying it lands as its own event in the access log. Read the access log.

A change to access
Person and current role
Change: role and relationships
Gains access
Loses access
Resolution path
Apply or discard
A described change held against the live relationships, returning the staff who gain access and the staff who lose it before you apply.

Why the two lists matter

A change to a role or a relationship can widen or narrow access for many people at once. Role inheritance carries a grant to every role beneath it, and a change to a shift moves the reach of everyone on it. Reading the two lists first shows the full effect while the relationships still stand as they were.

Common questions

Why did access change when the shift changed?

A role's reach follows the live duty scope, which the current shift derives. As the shift changes, the units and services the role covers change with it.

Can a person hold two roles at one site?

A site membership holds one role. That role inherits from a parent, so it carries the full capability set through inheritance rather than stacking.

Does a role open a record on its own?

Access combines the role with a current care relationship, so a role gives capabilities and the relationship decides which patients they reach.

Review who currently holds access to a patient in who can see this patient.