> ## Documentation Index
> Fetch the complete documentation index at: https://help.elationhealth.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & Permissions Guide — Creating roles and enforcing permissions (Premium)

> Step-by-step instructions to create roles, assign them to user groups, and turn on permission enforcement for your practice.

This guide walks a practice administrator through building roles and switching enforcement on. For the concepts behind each step, see the [Roles & Permissions Introduction](/articles/roles-and-permissions-introduction).

<Note>
  Roles & Permissions is a product for Premium EHR customers only. If you are interested in upgrading to the Premium EHR subscription to use this feature, click the **I need help** button to notify Elation and a member of the Elation Team will reach out to assist you. If you have Premium EHR and **Roles & Permissions** does not appear under **Settings**, click **I need help > Contact Elation Support**.
</Note>

## Setup

Before you start:

* Only [Admin Level Users](/articles/administrative-privileges) in Elation can configure Roles & Permissions and User Groups (another essential feature for Roles & Permissions).
* You need at least one user group with members. Create groups under **Settings > User Groups** first — a role has no effect until it applies to a group that has people in it.

<Note>
  Permissions take effect only after you turn on **Enforce permissions** in [Turning on enforcement](#turning-on-enforcement).
</Note>

## Creating a role

<Steps>
  <Step title="Open Roles & Permissions">
    Click **Settings** in the navigation bar, then click **Roles & Permissions**.
  </Step>

  <Step title="Create a new role">
    Click **New Role** in the **Roles** card header.
  </Step>

  <Step title="Name the role">
    Enter a **Role Name** that describes the group of people it is for, such as "Front Desk" or "Medical Assistants." Names can be up to 100 characters.
  </Step>

  <Step title="Choose the user groups it applies to">
    In **Assigned Groups**, select one or more groups. Everyone in the selected group(s) gets this role's permissions. The Assigned Groups dropdown lists all of the available user groups, and you can also search for groups. You can leave the Assigned Groups field empty for now and assign groups later.
  </Step>

  <Step title="Set each permission">
    Set the level this role grants. Most permissions offer **None** or **Full** only; some permissions also offer **View**. Permissions default to **None**, so set only what this role should be able to do.
  </Step>

  <Step title="Save">
    Click **Save**. Elation confirms with "Role created." and returns you to the role list.
  </Step>
</Steps>

To leave without saving, click **Back to Roles**. If you have unsaved changes, Elation asks you to confirm before discarding them.

## Copying an existing role

Copying is the fastest way to create a variation of an existing role.

1. In the role list, click the copy icon on the role you want to start from. You can also open the role and click **Clone**.
2. Elation opens a new role named **Copy of** the original, with the same permissions.
3. Change the name, then select the groups it applies to.
4. Click **Save**.

<Note>
  A copy does not carry over the original's groups. Assign them deliberately so a copy never grants access to a group by accident.
</Note>

## Editing a role

1. In the role list, click the edit icon on the role, or click its name.
2. Change the name, the assigned groups, or any permission level.
3. Click **Save**.

Changes apply to everyone in the role's assigned group(s). They take a few moments to reach every user — anyone who is signed in may need to reload the page to see the change.

Roles tagged **Elation Default** work slightly differently. Elation manages their names and permissions, so on those roles you can only change **Assigned Groups**. Copy one if you need a version with different permissions.

## Deleting a role

1. In the role list, click the delete icon on the role. You can also open the role and click **Delete**.
2. Confirm by clicking **Delete Role**.

<Warning>
  Deleting a role cannot be undone. Users in that role's groups immediately lose the permissions it granted. If they do not already have equivalent permission from another role, they lose access to those actions entirely.
</Warning>

Roles tagged **Elation Default** cannot be deleted. Remove their assigned groups instead.

## Checking what a user ends up with

**Show Users** reports each person's permissions after every role that reaches them is combined. Use it to confirm a role does what you intended before you turn on enforcement, and to check anyone who reports a problem afterwards.

<Steps>
  <Step title="Open the list">
    Open **Settings > Roles & Permissions** and click **Show Users** on the **Permission Enforcement** card. Elation opens **Permissions by User**, listing every active user in the practice.
  </Step>

  <Step title="Find the person">
    Type a first or last name in **Search users**, or page through the list.
  </Step>

  <Step title="Open their row">
    Click their name. The row expands to show each permission they have, the level, and the role and group that granted it — for example, "Front Desk Role — Front Desk Staff". A permission granted by two roles at the same level lists both.
  </Step>
</Steps>

A row reading **0 permissions** means no role reaches that user. Add them to a group that has a role before you turn on enforcement.

## Turning on enforcement

**Enforce permissions** is the switch that makes your roles take effect. Turn it on only after every active user is covered by a role.

<Steps>
  <Step title="Check your coverage">
    Open **Settings > Roles & Permissions**. The line under **Enforce permissions** tells you how many users get permissions from a role and how many users do not have a role with permissions. Click **Show Users** to see who they are, one row per user.
  </Step>

  <Step title="Turn on the switch">
    Click **Enforce permissions**. Elation opens a confirmation dialog listing how many users will start getting permissions from their roles, and naming any user who has no role and will lose access to anything a permission controls.
  </Step>

  <Step title="Review the named users">
    If the dialog names users you did not expect, click **Not Yet** and assign them a role first. If the list is what you intend, continue.
  </Step>

  <Step title="Confirm">
    Click **Enforce Permissions**. Elation confirms with "Permissions are now enforced."
  </Step>
</Steps>

If the switch is grayed out, no role reaches a group that has members yet. Assign a role to a populated group first — see [Troubleshooting Roles & Permissions](/articles/troubleshooting-roles-and-permissions-in-elation-ehr).

## Turning off enforcement

1. Open **Settings > Roles & Permissions**.
2. Click **Enforce permissions** to switch it off.
3. Click **Turn Off** to confirm.

Everyone keeps their roles, and nothing is restricted by them until you turn **Enforce permissions** back on. Turning **Enforce permissions** off is the fastest way to restore access for the whole practice if you need to address any issues with the configuration of your roles and permissions.

## Tips

Roll out in this order to avoid surprises:

1. **Create your groups first.** Roles apply to groups, so group structure decides how precisely you can grant access. **Settings > User Groups**.
2. **Start from an Elation Default.** Assign one to a group as-is, or copy it and adjust, rather than setting every permission from scratch.
3. **Cover everyone before you turn on Enforce permissions.** Every active user should be in a group with a role. A user with no role is blocked from every action a permission controls — open **Show Users** and look for anyone reading **0 permissions**.
4. **Grant the minimum, then add.** Permissions combine across roles and always keep the highest level, so it is easier to add access later than to work out which role is granting too much.
5. **Tell your team before you switch it on.** Users see controls disappear, not an explanation. The block message directs them to a practice administrator.
6. **Check the first day.** Ask staff to report anything they can no longer do, and adjust the roles rather than turning **Enforce permissions** off, unless the problem is widespread.

## Frequently Asked Questions

### Do I have to turn enforcement on to test a role?

Yes. Roles have no effect until **Enforce permissions** is on. Practices commonly cover everyone first, turn on **Enforce permissions**, and then refine the roles with it left on.

### How do I see what one person can do?

Click **Show Users** on the **Permission Enforcement** card and search for them. See [Checking what a user ends up with](#checking-what-a-user-ends-up-with).

### Can I give one person an exception?

Add them to a group that has a role granting the permission. Because a user will have the highest level permission from any roles with conflicting permission settings, that grant wins over any other roles assigned to the user with more restrictive permissions.

### Why can't I modify the name and permissions for some roles?

Elation maintains **Elation Default** roles. Elation manages their names and permissions, and organizations can assign them to user groups. You may copy an Elation Default role if you wish to use it as a starting point.

### How long do permission changes take to apply?

Permission changes typically apply within seconds. A user who is already signed in may need to reload the page they are on to see the changes take effect.

## Related Articles

* [Roles & Permissions Introduction](/articles/roles-and-permissions-introduction)
* [Troubleshooting Roles & Permissions in Elation EHR](/articles/troubleshooting-roles-and-permissions-in-elation-ehr)
* [Managing user accounts](/articles/managing-user-accounts)
* [Administrative privileges](/articles/administrative-privileges)
