Advanced Capability

Privacy & Permissions

Role-based access that matches real operations - with privacy-aware visibility.

Control what organizations, specialists, affiliates, and internal admins can see and do, without turning the platform into an 'all-or-nothing' admin experience.

Advanced capability screenshot

How it works

A streamlined process designed for efficiency and control

1

Define roles with specific action permissions and surface access per portal

2

Configure scope controls by organization, network/tenant, or relationship

3

Set visibility rules for identified vs anonymized patient reporting

4

Apply separation of duties for sensitive operations like payout approvals

5

Use audit-friendly visibility language with clear 'you don't have access' states

Core capabilities

Enterprise-grade features for complex operational needs

Organization Oversight

Limited views for program admins with aggregate insights, or expanded views for authorized roles where permitted.

Specialist Operations

Access limited to allocated patients and relationships, with profile and operational controls for their own account.

Affiliate Access

Performance reporting and payouts visibility without unnecessary patient identity exposure.

Platform Admin

Controlled 'break-glass' access with audit trails where applicable for platform-level operations.

Role-Based Access Control

RBAC for actions and surfaces, defining who can do what across the entire platform.

Scope Controls

Control access by org, by network/tenant, or by relationship for granular permission boundaries.

Visibility Rules

Configure identified vs anonymized patient reporting based on role requirements and privacy needs.

Privacy-Aware Reporting

Anonymize patient data where required while maintaining operational visibility and outcome tracking.

Separation of Duties

Require multiple roles or approvals for sensitive operations like payout approvals and data exports.

Audit-Friendly Language

Clear UI states for access boundaries with predictable permission messaging throughout the platform.

Scoped Data Views

Each role sees only the data slices they're authorized to access, preventing accidental exposure.

Built for scale and precision

Our advanced capabilities are designed for organizations that need granular control, sophisticated workflows, and enterprise-grade reliability.

RBAC with granular role definitions
Scope-based access boundaries
Anonymized reporting options
Separation of duties for sensitive actions
Dashboard view

Use cases

See how different organizations leverage this capability

Organizations

Organization Portal Access

Control what org admins can see about specialists and customers with support for both limited and full access models.

Specialists

Specialist Data Isolation

Ensure specialists only access the customers they're assigned to, with clear boundaries around their operational scope.

Affiliates

Affiliate Privacy Reporting

Attribution and payout visibility with privacy-aware reporting that doesn't expose unnecessary patient identity.

Platform Operators

Multi-Tenant Separation

Maintain strict data boundaries between tenants while enabling cross-tenant operational views where authorized.

Compliance Teams

Compliance & Governance

Meet regulatory requirements with clear access patterns, audit trails, and privacy-aware data handling.

Internal Teams

Internal Operations

Platform admins get controlled access with appropriate audit trails and break-glass procedures when needed.

Why choose this capability

RBAC with granular role definitions
Scope-based access boundaries
Anonymized reporting options
Separation of duties for sensitive actions
Clear permission denial messaging
Tenant and network-level isolation
Configurable visibility per role
Privacy-first data architecture
Audit-ready access patterns
Flexible access models per organization
Specialist-assigned patient restrictions
Affiliate attribution without identity leaks

Model complex roles without sacrificing privacy

Talk to us and we'll map your access model to clear roles, scopes, and reporting boundaries - across customers, specialists, organizations, and affiliates.