Users & Access
Least privilege by default. Break-glass access is time-limited, requires a reason and is heavily audited.
Permission matrix
Role versus permission
| Role | View masked patient identity | View full patient identity | Assign / replace tag | Confirm transfer | Publish screen content | Emergency override | Export reports | Manage users & roles | View audit log |
|---|---|---|---|---|---|---|---|---|---|
| Registration staff | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow |
| Nurse | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny |
| OR coordinator | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow |
| Transfer coordinator | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow |
| Supervisor | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny |
| Management | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow |
| IT | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow |
| Biomedical engineer | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny |
| Screen editor | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow |
| Auditor | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow |
| System administrator | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny | ✓ allow | ✓ allow | — deny |
Demo users
| User | Role | Scope | MFA | Status |
|---|---|---|---|---|
| n.mansour | OR coordinator | NJR-01 · Theatres | App MFA | Active |
| a.alyami | Nurse | NJR-01 · Day Surgery | App MFA | Active |
| s.alharbi | Supervisor | NJR-01, NJR-02 | Hardware key | Active |
| it.duty | IT | All hospitals | Hardware key | Active |
| biomed.eng | Biomedical engineer | All hospitals · devices | App MFA | Active |
| screen.editor | Screen editor | Cluster screens | App MFA | Password reset due |
| auditor.gov | Auditor | Read-only cluster | Hardware key | Active |
Enterprise identity
- Healthy
Microsoft Entra ID (OIDC)
Connected · 412 users synced
- Standby
LDAP directory
Configured · fallback only
- Off
SAML 2.0
Not configured
- Healthy
Privileged MFA policy
Required for IT, admin and break-glass
- Review
Break-glass sessions (30 days)
3 sessions · all reviewed