Permission matrix
«Permission Matrix» shows, role by role, which permissions each one grants. It is read-only: nothing is changed here.
1. How to read it
Roles are grouped by category; each group is a table with roles as rows and permissions as columns. A green tick means the role grants that permission; a dot means it does not. The search filters by role, category or permission, and each group folds when you click its title.
The demo has a single group, «Health» (3 roles · 4 permissions), with the names as they come from the system: «Health Data (Statistical)» only has «medical.read-stats» (aggregated data), «Medical Professional» has «medical.certify», «medical.read-full» and «medical.write», and «Occupational Health Nurse» has «medical.read-full» and «medical.write».
2. Where these roles are assigned
These three roles are the options of “Health surveillance access” on each user's record in Team: occupational physician (full access), occupational nurse (read and write) and aggregated data only (no clinical records). Check here what each one allows before granting it; every grant and withdrawal is logged.
3. Who sees this screen
It is under Administration › Security and Audit, for the company's administrators. The Viewer, Editor and Admin roles you choose when inviting someone do not appear in this matrix.