Investment Plans workspace
Open raw ↗

# HAD Digital - Role-Permission Matrix

Version: 1.0.0 Date: 5 September 2026 Clinical Owner: Dr Kais Aldabbagh, Polyclinique St Come - Medical Oncology


Overview

This document defines the access control matrix for HAD Digital. Each role has specific permissions for viewing and interacting with patient data, based on their relationship to the patient episode.


Roles

RoleDescriptionTypical Users
oncologistHospital oncologist / referring physicianDr Martin, Dr Dupont
had_nurseHAD coordinating nurseNurse Moret, Nurse Bernard
community_nurseCommunity / HAD nurseNurse Leroy, Nurse Petit
gpGeneral practitionerDr Thomas, Dr Robert
pharmacistHospital / HAD pharmacistPharmacist Garcia
patientPatientMarie Durand, Pierre Martin
caregiverCaregiver / family memberFamily members
adminSystem administratorIT staff

Permission Matrix

Patient Data

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
View patient list✓✓✓✓✓✗✗✓
View patient details✓✓✓✓✓✓*✓*✓
View patient demographics✓✓✓✓✓✓*✓*✓
View patient medical history✓✓✓✓✓✓*✓*✓
Edit patient information✓✓✗✗✗✗✗✓

*patient and caregiver can only view their own data


Toxicity Reports

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
Submit patient report✗✗✗✗✗✓✓✗
Submit clinician observation✓✓✓✗✗✗✗✗
View all reports✓✓✓✓✓✗✗✓
View own reports✓✓✓✓✓✓✓✓
View assigned patient reports✓✓✓✓✓✓*✓*✓
Confirm grades✓✗✗✗✗✗✗✗

*patient and caregiver can only view reports for their own episode


CTCAE Grades

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
View all grades✓✓✓✓✓✗✗✓
View assigned patient grades✓✓✓✓✓✓*✓*✓
Confirm provisional grades✓✗✗✗✗✗✗✗
Override automated grades✓✗✗✗✗✗✗✗

*patient and caregiver can only view grades for their own episode


Alerts

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
View all alerts✓✓✓✗✗✗✗✓
View assigned alerts✓✓✓✓✓✗✗✓
Acknowledge alerts✓✓✓✓✓✗✗✓
Escalate alerts✓✓✗✗✗✗✗✓
Resolve alerts✓✓✗✗✗✗✗✓

Timeline

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
View all timeline events✓✓✓✗✗✗✗✓
View assigned patient timeline✓✓✓✓✓✓*✓*✓
Add timeline notes✓✓✓✓✗✗✗✓

*patient and caregiver can only view timeline for their own episode


Treatment Plans

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
View all treatment plans✓✓✓✗✗✗✗✓
View assigned patient plans✓✓✓✓✓✓*✓*✓
Create treatment plans✓✗✗✗✗✗✗✗
Modify treatment plans✓✗✗✗✗✗✗✗

*patient and caregiver can only view plans for their own episode


Messages

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
Send direct messages✓✓✓✓✓✓✓✓
View all messages✓✗✗✗✗✗✗✓
View own messages✓✓✓✓✓✓✓✓
View assigned patient messages✓✓✓✓✓✓*✓*✓

*patient and caregiver can only view messages for their own episode


Export & Reports

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
Export toxicity summary✓✓✓✓✓✗✗✓
View audit log✗✗✗✗✗✗✗✓
Generate clinical reports✓✓✗✗✗✗✗✓

System Administration

Permissiononcologisthad_nursecommunity_nursegppharmacistpatientcaregiveradmin
Manage users✗✗✗✗✗✗✗✓
Manage roles✗✗✗✗✗✗✗✓
View system logs✗✗✗✗✗✗✗✓
Configure system✗✗✗✗✗✗✗✓

Data Visibility Rules

Episode-Based Access

  1. Oncologist: Can see all patients assigned to them
  1. HAD Nurse: Can see all patients in their HAD structure
  1. Community Nurse: Can see patients assigned to them for home visits
  1. GP: Can see patients who have designated them as their GP
  1. Pharmacist: Can see patients with active treatment plans
  1. Patient: Can see only their own data
  1. Caregiver: Can see only the patient they are linked to
  1. Admin: Can see all patients (for system administration)

Data Minimization

  1. Minimum Necessary: Each role sees only the data necessary for their function
  1. Purpose Limitation: Data is used only for the purpose it was collected
  1. Access Logging: All data access is logged in the audit trail
  1. Consent: Patient consent is required for data sharing (implicit in HAD admission)

Implementation Notes

MVP Implementation

The MVP implements basic role-based access control:

  1. Authentication: All users must log in with username/password
  1. Session Management: Session cookies with 24-hour expiry
  1. Role Checking: API endpoints check user role before processing
  1. Data Filtering: Queries filter data based on user role and patient assignment

Future Enhancements

  1. Fine-Grained Permissions: Individual permission flags instead of role-based
  1. Episode-Based Access: Dynamic access based on active episodes
  1. Consent Management: Explicit patient consent for data sharing
  1. Audit Trail Enhancement: Log all data access with timestamps
  1. Multi-Factor Authentication: MFA for clinicians (required by spec)
  1. Session Timeout: Configurable session timeout based on role

Clinical Responsibility

Important: Access control does not replace clinical responsibility. Even with access to data, clinicians must:

  1. Verify patient identity before discussing care
  1. Document clinical decisions in the appropriate record
  1. Respect patient privacy and confidentiality
  1. Follow institutional policies for data sharing
  1. Report security incidents immediately

References