User Roles and Permissions

User Roles and Permissions

Everything a staff member can see and do in CareVision is controlled by their assigned security roles and permissions. Your organisation should assign roles carefully to ensure that sensitive and confidential information remain secure.


Keywords: user roles, carevision permissions, security roles, organisation scope, circle scope, staff access, client data access, role permissions, access control, carevision security

Two user security layers
CareVision has two security layers that apply to your organisation’s staff members. Both layers work together to determine access.
Security layerWhat it governsExample
Organisation scopeThe features, modules and sections of CareVision that a staff member can access. This scope is closely linked to their role in the organisation.Determines whether a staff member can access rostering, view the claims dashboard or open system settings.
Circle scopeHow a staff member can access information about a client and the people connected to that client.Determines whether a staff member can open a particular client’s record and what information they can view within it.

System Scope
CareVision also has a system scope, which applies to global administrative actions such as activating an organisation or creating a branch. This scope is generally limited to system administration and is not commonly used in day-to-day work.

Organisation scope
Organisation scope determines which CareVision functions a staff member can access. For example, it may control whether a staff member can:
  1. Access the management portal, mobile app or both
  2. Open the rostering module
  3. View claims and funding information
  4. Access reports and dashboards
  5. Manage staff profiles
  6. Change organisation settings and configurations

Organisation scope is also connected to CareVision’s user-based licensing. Changing a staff member’s organisation scope may have licensing and cost implications. For this reason, role and scope changes must be assessed through the appropriate account and project process. See How to Manage Your User Licenses.

Circle scope
Circle scope determines how a staff member can access client information.
A circle consists of the client and the people connected to that client. Circle security is important for field staff members using the CareVision Plus Mobile App.
Circle security roleAccess provided
Active Circle Security RoleProvides access to a client’s information around a booking with that client: seven days before the booking, the day of the booking and seven days after it. This creates a 15-day access window.
Inactive Circle Security RoleDetermines how a staff member can access or view a client’s information when they do not have a booking with that client.

A support worker typically sees clients with whom they have an active working relationship during the 15-day window. A manager may have access to all active clients, depending on their assigned role.
If a client no longer appears in the mobile application, check the date of the staff member’s most recent or upcoming booking with that client. The client may have moved outside the staff member’s active access window.

Security roles and permissions
Security role is a named group of permissions assigned to a staff member according to their job responsibilities. You can view a staff member’s security role in their detailed profile under the Security Role field.

Permission controls one action within CareVision. Permission names generally combine an action with the relevant module or information type. Examples include:
  • ViewClientsData

  • EditClientsData

  • DeleteClientsData

  • AddCaseNotes

  • EditCaseNotes

  • DeleteCaseNotes

Each permission is also linked to a scope. A staff member may appear to have the correct permission but still be unable to complete an action if the permission is assigned at the wrong scope.

For example, if a page requires an organisation-scope permission and the staff member’s role does not provide that scope, CareVision will refuse access.

Understanding a 403 Forbidden message
A 403 Forbidden, Access denied or permissions message means the staff member’s security role does not provide the permission required by the page or action, or that the permission is assigned at the wrong scope.

When this occurs, confirm:

  1. Which page or feature the staff member was trying to access.
  2. Which action they were trying to complete.
  3. Which security roles are assigned to them.
  4. Whether the required permission is included.
  5. Whether the permission has the correct organisation or circle scope.
  6. Whether branch, filtering or classification settings limit their access.
Applying permissions across branches
Organisation-scope permissions can determine which parts of your organisation’s structure a staff member can access.

This is important for organisations with a head office and multiple branches.

SettingAccess provided
ThisProvides access to the staff member’s own organisation. For a branch staff member, this is the branch to which they belong.
ParentProvides access to the parent organisation or head office. A branch staff member with parent access may also view permitted head-office information.
ChildProvides access to child organisations or branches. A head-office staff member with child access may access permitted information from branches below the head office.
This is why some standard roles are described as Head Office roles and others as Branch roles. A Head Office role may allow a staff member to switch between branches, while a Branch role is generally limited to its assigned branch.

Filtered and Classified roles
Some security role names include the modifiers Filtered or Classified, such as Coordinator Admin Filtered and Classified.
  1. Filtered roles
A Filtered role limits a staff member to a defined part of the organisation, usually by region or department.
Two staff members may hold the same base role but see different client lists because different filters have been applied to them.
  1. Classified roles
A Classified role protects confidential information about other staff members.
If a staff member does not need access to another staff member’s personal details, the Classified role prevents that information from being displayed. The staff member can still see the person’s name and other information relevant to their role.

Where organisation and circle scopes apply
The scope used depends on the information or CareVision feature being accessed.
AreaApplicable scope
Case notesCircle scope applies because case notes contain client-centred information. Security may also be configured according to the case note type.
FormsThe scope depends on the Form is for field. Circle scope applies to client forms, while organisation scope applies to forms about staff members or organisation users.
Application accessOrganisation scope determines whether a staff member can access the management portal, mobile application or both.

Standard security roles
CareVision includes standard security roles based on common organisational responsibilities. These roles cover most day-to-day access requirements.
Your organisation’s configuration remains the source of truth for what a particular role can access. Role names and permissions may vary depending on your organisation’s approved setup.

Common organisation-scope roles
  1. Coordinator Admin Security Role
The Coordinator Admin Security Role provides the highest level of organisation access. It includes access to settings and configuration and is commonly assigned to authorized management portal users.
This role provides broad administrative access and should only be assigned to staff members who require that level of control.
  1. Coordinator Admin Filtered and Classified Variants
The Coordinator Admin Filtered and Classified variants provide a high level of management portal access while limiting information according to region, department or classification requirements.
These variants are commonly used when a staff member needs extensive operational access but should not see all staff or organisational information.
  1. Field Care Professional
The Field Care Professional role is commonly assigned to staff members who use the CareVision Plus Mobile App.
It supports field-based work without providing the broader management portal access associated with administrative roles.

Common circle-scope roles
  1. Patient Admin
The Patient Admin role provides the highest level of access to client information and profiles. It is generally paired with the Coordinator Admin Security Role.
  1. Patient Admin Filtered and Classified Variants
The Patient Admin Filtered and Classified variants provide extensive access to client profiles while limiting access according to region, department or classification settings.
These roles are generally paired with the corresponding Coordinator Admin Filtered and Classified variants.

Active Carer and Inactive Carer
Active Carer and Inactive Carer are separate roles used for field care teams:
  • Active Carer is assigned in the Active Circle Security Role field.
  • Inactive Carer is assigned in the Inactive Circle Security Role field.

Together, these roles help ensure that field staff members can access client information when required for service delivery.
The Active Carer role should not be entered in both fields. Assigning it as both the active and inactive role may allow a staff member to see all clients at all times rather than only those within the required access window.

Additional standard security roles
CareVision supports additional roles for specific business functions.
RoleSummaryTypical structure
CorporateSupports executive and upper-management responsibilities, including organisation settings, rates, services, funding, claiming and reporting.Head Office
System AdminManages CareVision configuration and settings, including system and access changes.Head Office
HR/RecruitmentSupports staff management, onboarding, staff forms, policies and procedures. It does not provide access to clients or billing and claiming settings.Head Office
Support CoordinatorProvides limited access to assigned clients and allows staff members to create forms and notes. It does not provide access to system configuration or staff profiles.Branch
Allied HealthProvides limited access to assigned clients and allows staff members to create forms and notes. It does not provide access to system configuration or staff profiles.Branch
Direct ServicesProvides limited access to assigned clients for service delivery without access to funding or billing information.Branch
GrowthSupports marketing and sales activities, including creating leads. It does not provide access to personal or clinical client information, staff information, rostering, billing or claiming.Head Office
Quality & ComplianceProvides limited access to client profiles and supports the creation, approval and management of notes and forms for compliance purposes. It does not provide billing, funding or claiming access.Head Office
People & Culture Manager, Coordinator or OfficerSupports HR, recruitment and employee engagement, including staff profiles, skills, qualifications, work availability, policies and procedures.Head Office
Customer CareSupports client services, rostering changes and the maintenance of current client information.Branch and Head Office
Payroll/Finance CorporateProvides limited access to client funding, staff pay details and schedules for award interpretation and service review.Head Office
Accommodation CorporateManages accommodation settings across branches, including schedules, notes, new accommodations and programs.Head Office
House Lead / House ManagerProvides administrative access for an assigned house, including client information, house schedules and programs.Branch
State ManagerSupports branch operations, critical reporting, rostering and staff performance oversight, with limited client access.Branch
Direct Services ManagerSupports branch operations, reporting, rostering and staff performance oversight, with limited client access.Branch
RosteringAllows staff members to view and update bookings, create ad hoc bookings, send job offers and complete other service delivery tasks. Client and staff profile access is limited.Branch
EA Global CEO CorporateSupports executive staff members and managers with reporting and organisational insights.Head Office

Role names and your organisation’s configuration
Some role names may differ between CareVision resources or from those used in your organisation’s configuration.
For example, a role may be referred to as Field Care Professional in one location and Field Staff in another. Classified variants may also appear differently depending on your organisation’s configuration.
Before relying on a role name alone, confirm the role and its permissions within your organisation’s CareVision configuration.

Custom security roles
Standard security roles cover most operational requirements. Custom roles may be considered when your organisation has access requirements that are not supported by a standard role.
Organisation type or stageCustomisation available
Enterprise implementationSecurity roles may be customised by enabling or disabling permissions when included in the agreed project scope.
SME implementationCustom security roles are not available.
After go-liveA project change request is required. The work is charged at CareVision’s applicable services rate.

Notes
The CareVision Support team cannot modify or enforce user role permissions. These permissions are managed internally by the organisation’s system administrator. The appropriate roles must be configured within the organisation to provide staff with the required access. 

For more information about user roles and permissions, contact the CareVision Support Team.

    • Related Articles

    • Account Access and Security

      CareVision provides authorized users with access to the platform based on their assigned roles and permissions. Secure login practices protect personal and vital information from unauthorized access. This topic describes how to access CareVision, use ...
    • Submit a Ticket to CareVision

      CareVision aims to provide assistance so you can make the most of our platform and maintain smooth operations. We provide several ways for you to receive help quickly and easily. Submitting a ticket is one of the fastest ways to reach our support ...
    • CareVision’s Knowledge Base

      CareVision provides a Knowledge Base where you can find articles, step-by-step guides, troubleshooting resources, and tutorial videos to help you get the most out of CareVision products. The Knowledge Base is updated regularly, with new documentation ...
    • CareVision Academy

      CareVision Academy is the central learning hub for CareVision users, designed to support onboarding and continuous skill development. It provides a repository of training resources, including introductory system guides, major learning series such as ...
    • How to Change Your Password in CareVision

      I. Change Your Password To keep your account secure, we recommend changing your password after your first login. Follow these steps to change your password: Log in to the CareVision portal using your username and password. In the left menu, click My ...

    Request an Article or Guide

    We are keen to know what you want to know more about? Let us know on chat or raise a ticket for an article or topic you would like covered in more detail. We have a team of technical writers and learning content creators keen for your suggestions.