Security controls
Roles and permissions
The role roster, tiers and deny-by-default access.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0127How many roles does AuroraMed define?
A roster of 1,650 roles grouped into permission tiers T0 through T9 plus a service tier. The pilot derives capabilities from that roster.
C0128Is access deny-by-default?
Yes. Anything not granted by tier or role is denied, and denials return a generic reason while the policy trace is logged.
C0129Can a role's title differ from its permissions?
The design keeps a canonical role code with flexible display titles, so a clinic can call a role what it wants without changing what the person can do.
C0130Can a manifest grant a low tier a sensitive permission?
No. Sensitive permissions have tier ceilings that validation refuses to exceed, and the same floors are re-applied at enforcement, so a forged manifest cannot raise privileges.
C0131Can security staff read charts?
No. Security roles read no clinical data. In the design they see safety flags only during a live response and never diagnoses or notes.
C0132Who can read the audit log?
Privacy, compliance and governance tiers, in scoped, audited views. Clinical roles cannot.
C0133Can a role hold two jobs at once?
Yes through overlay assignments, each expiring and recertified on its own, such as a charge nurse who also supervises.
C0134Do students and scribes have limited rights?
Yes by design: their entries need cosignature and their access is narrower. The pilot provides the roster roles.
C0135How are contractors and external parties handled?
Through interface-only external roles or time-boxed guest access, never through a workforce login.
C0136Can a role be tested before it is granted?
The Packaging editor lets an author test a role against the permission grid. A broader what-if simulation for access policy is designed.
C0137Are patients' own roles included?
The roster includes patient, proxy and guardian entries, but the patient portal is not built, so they grant nothing in the pilot.
C0138How are compartments inherited by role?
They are not. Highly restricted compartments need an explicit purpose and extra approval regardless of tier.
C0139What about nurse-to-patient assignment?
Clinical read and write is scoped by care relationship such as assigned patient or home unit. The pilot implements assignment and unit scope.