Auron
Web consoleOrganization settings

Access

Granting people and teams access to individual entity records, and checking who can see what.

A role says what kind of thing you can do. Access says which records you can do it to. This screen is the second half.

Two ways to work

The screen has a users view and a groups view, and they are the same job approached from either end.

By user. Pick a person, see the records they have been given, and assign or unassign from the records available.

By group. Pick a team, see the records assigned to it, and do the same.

Both views show the assigned records next to the available ones, so granting access is a matter of moving things across rather than searching blind.

Each person in the user list has an arrow beside their name that opens their profile, for when you are about to grant access and want to check who you are granting it to.

Checking the other direction

For any entity or record you can ask the opposite question: which users and which teams currently have access to this. Use that view before sharing something sensitive, rather than assuming from the role list.

What access controls

Someone without access to a record does not see it anywhere: not in the record lists, not in search, not in their history, and not on their phone. Sessions attached to a record they cannot see are not visible to them either.

Two levels

Access can be granted to a whole entity, which covers its records, or to individual records. Entity-level access is the right default for a team that works the whole book; record-level is for the cases where one account or one patient needs to be narrower than that.

Records and their entities are managed in Entities and records.

On this page