Roles & Permissions is a product for Premium EHR customers only. If you are interested in upgrading to the Premium EHR subscription to use this feature, click the I need help button to notify Elation and a member of the Elation Team will reach out to assist you. If you have Premium EHR and Roles & Permissions does not appear under Settings, click I need help > Contact Elation Support.
Setup
Before you start:- Only Admin Level Users in Elation can configure Roles & Permissions and User Groups (another essential feature for Roles & Permissions).
- You need at least one user group with members. Create groups under Settings > User Groups first — a role has no effect until it applies to a group that has people in it.
Permissions take effect only after you turn on Enforce permissions in Turning on enforcement.
Creating a role
1
Open Roles & Permissions
Click Settings in the navigation bar, then click Roles & Permissions.
2
Create a new role
Click New Role in the Roles card header.
3
Name the role
Enter a Role Name that describes the group of people it is for, such as “Front Desk” or “Medical Assistants.” Names can be up to 100 characters.
4
Choose the user groups it applies to
In Assigned Groups, select one or more groups. Everyone in the selected group(s) gets this role’s permissions. The Assigned Groups dropdown lists all of the available user groups, and you can also search for groups. You can leave the Assigned Groups field empty for now and assign groups later.
5
Set each permission
Set the level this role grants. Most permissions offer None or Full only; some permissions also offer View. Permissions default to None, so set only what this role should be able to do.
6
Save
Click Save. Elation confirms with “Role created.” and returns you to the role list.
Copying an existing role
Copying is the fastest way to create a variation of an existing role.- In the role list, click the copy icon on the role you want to start from. You can also open the role and click Clone.
- Elation opens a new role named Copy of the original, with the same permissions.
- Change the name, then select the groups it applies to.
- Click Save.
A copy does not carry over the original’s groups. Assign them deliberately so a copy never grants access to a group by accident.
Editing a role
- In the role list, click the edit icon on the role, or click its name.
- Change the name, the assigned groups, or any permission level.
- Click Save.
Deleting a role
- In the role list, click the delete icon on the role. You can also open the role and click Delete.
- Confirm by clicking Delete Role.
Checking what a user ends up with
Show Users reports each person’s permissions after every role that reaches them is combined. Use it to confirm a role does what you intended before you turn on enforcement, and to check anyone who reports a problem afterwards.1
Open the list
Open Settings > Roles & Permissions and click Show Users on the Permission Enforcement card. Elation opens Permissions by User, listing every active user in the practice.
2
Find the person
Type a first or last name in Search users, or page through the list.
3
Open their row
Click their name. The row expands to show each permission they have, the level, and the role and group that granted it — for example, “Front Desk Role — Front Desk Staff”. A permission granted by two roles at the same level lists both.
Turning on enforcement
Enforce permissions is the switch that makes your roles take effect. Turn it on only after every active user is covered by a role.1
Check your coverage
Open Settings > Roles & Permissions. The line under Enforce permissions tells you how many users get permissions from a role and how many users do not have a role with permissions. Click Show Users to see who they are, one row per user.
2
Turn on the switch
Click Enforce permissions. Elation opens a confirmation dialog listing how many users will start getting permissions from their roles, and naming any user who has no role and will lose access to anything a permission controls.
3
Review the named users
If the dialog names users you did not expect, click Not Yet and assign them a role first. If the list is what you intend, continue.
4
Confirm
Click Enforce Permissions. Elation confirms with “Permissions are now enforced.”
Turning off enforcement
- Open Settings > Roles & Permissions.
- Click Enforce permissions to switch it off.
- Click Turn Off to confirm.
Tips
Roll out in this order to avoid surprises:- Create your groups first. Roles apply to groups, so group structure decides how precisely you can grant access. Settings > User Groups.
- Start from an Elation Default. Assign one to a group as-is, or copy it and adjust, rather than setting every permission from scratch.
- Cover everyone before you turn on Enforce permissions. Every active user should be in a group with a role. A user with no role is blocked from every action a permission controls — open Show Users and look for anyone reading 0 permissions.
- Grant the minimum, then add. Permissions combine across roles and always keep the highest level, so it is easier to add access later than to work out which role is granting too much.
- Tell your team before you switch it on. Users see controls disappear, not an explanation. The block message directs them to a practice administrator.
- Check the first day. Ask staff to report anything they can no longer do, and adjust the roles rather than turning Enforce permissions off, unless the problem is widespread.