> ## Documentation Index
> Fetch the complete documentation index at: https://help.elationhealth.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshooting Roles & Permissions in Elation EHR (Premium)

> Resolve blocked actions, missing buttons, and enforcement problems caused by role and permission settings.

<Note>
  Roles & Permissions is a product for Premium EHR customers only. If you are interested in upgrading to the Premium EHR subscription to use this feature, click the **I need help** button to notify Elation and a member of the Elation Team will reach out to assist you. If you have Premium EHR and **Roles & Permissions** does not appear under **Settings**, click **I need help > Contact Elation Support**.
</Note>

## What this article covers

* A user cannot take an action they could take before, or a button has disappeared.
* The **Enforce permissions** switch is grayed out.
* A role change does not seem to have taken effect.
* A user still cannot delete something even though their role grants it.

Not covered here:

* Sign-in failures and account lockouts. See [Troubleshooting account login issues](/articles/User-Accounts-Guide-Troubleshooting-account-login-issues).
* Chart access limited by patient criteria. See [Restricting access to patient charts based on patient criteria](/articles/Patient-Chart-Guide-Restricting-access-to-patient-charts-based-on-patient-criteria).

## How to recognize a permissions problem

Roles & Permissions blocks an action in one of two ways:

* **The control is not there.** Elation hides most buttons and chart sections a user cannot use, so the user reports something "missing" rather than blocked.
* **A message appears:** "You do not have permission to perform this action. Contact your practice administrator."

Both mean the same thing: **Enforce permissions** is on for your practice and no role reaching that user grants the permission at the level the action needs. Only a practice administrator can change that, from **Settings > Roles & Permissions**.

## Quick fixes checklist

1. Confirm enforcement is on. If **Enforce permissions** is off, roles are not what is blocking the action.
2. Look the user up in **Show Users**, on the **Permission Enforcement** card. Their row lists every permission they have, the level, and the role and group it came from — which usually settles whether the role is the problem in one step.
3. Check whether the user is in any group that has a role. A user with no role is blocked from every action a permission controls.
4. Open the role and check the permission's level. For any action-named permission — deleting, signing, merging — **Full** is the only level that grants it.
5. Ask the user to reload the page. A permission change takes a few moments to reach a session that is already open.
6. Confirm the group still exists. Deleting a user group removes the role from its former members.

## The user has no role

The line under **Enforce permissions** reports how many users get permissions from a role and how many have none. Click **Show Users** and search for the person: a row reading **0 permissions** confirms that no role reaches them. The confirmation dialog you see when you turn on **Enforce permissions** also names the users with no role.

To fix it:

1. Open **Settings > User Groups** and add the user to a group.
2. Open **Settings > Roles & Permissions** and confirm a role is assigned to that group.

## The Enforce permissions switch is grayed out

Elation blocks the switch until at least one role applies to a group that has members. The message under the switch reads: "Assign a role to a group with members before turning this on."

This protects you from a practice-wide lockout — with no role reaching anybody, enforcing would deny everyone. To clear it:

1. Confirm you have a user group with at least one member under **Settings > User Groups**. Ideally, every active user is in a group with a role.
2. Open a role and select that group in **Assigned Groups**, then click **Save**.
3. Return to the role list. The switch is now available.

## An administrator is blocked

Practice administrators are not exempt from Roles & Permissions. An administrator without a role that grants a permission is blocked from that action.

Give administrators a role that grants what they need. Practice administrators can always open **Settings > Roles & Permissions** regardless of their permissions, so this cannot lock you out of correcting it.

## A role change has not taken effect

Permission changes reach users within moments, but not instantly. A page that is already open keeps the permissions it loaded with.

1. Ask the user to reload the page.
2. If the change still has not appeared, ask them to sign out and sign back in.
3. Re-open the role and confirm the change saved. Look for the confirmation — "Role saved." — or check that the role list summary shows the group and permission counts you expect.
4. Click **Show Users** and open the user's row. If the permission is listed there at the level you expect, the change has been applied and the user's session is stale; if it is missing, the role is not reaching them.

## A user still cannot delete something

Open the user's row in **Show Users** and check the matching delete permission. **Full** is the only level that allows a deletion, and a permission missing from their row means no role grants it at all. Check the row rather than a single role, so every role the user is assigned is accounted for.

Deletion of letters, referrals, orders that are not reports, and anything else absent from the [permission list](/articles/roles-and-permissions-introduction#permissions-you-can-control) is not governed by Roles & Permissions at all.

If a role grants the permission at **Full** and the deletion is still blocked, something other than Roles & Permissions is restricting it. Contact Elation Support.

## Safe alternative workflows

While you sort out a role:

* **Hand the task to someone who has the permission.** This is the intended path, and it is faster than editing roles under pressure.
* **Grant the permission to a group the user is already in.** Permissions combine and users are granted the highest level of a permission from across all their assigned roles, so adding a grant takes effect without unpicking other roles.
* **Turn Enforce permissions off.** If the problem affects many people at once, switch **Enforce permissions** off. Everyone keeps their roles and nothing is restricted until you switch it back on. Use this as a circuit breaker, not a long-term state.

## When to contact Elation Support

Contact Support if:

* **Roles & Permissions** does not appear under **Settings** and you want the feature enabled. It is an Elation Premium EHR feature.
* Roles or the enforcement setting fail to load, and reloading the page does not fix it.
* A user is blocked from an action that no permission in the [permission list](/articles/roles-and-permissions-introduction#permissions-you-can-control) covers.
* A change saves successfully but never reaches users after repeated sign-outs.

Include:

* Your practice name.
* The name of the affected user and the role and groups they should be getting.
* The exact action that was blocked, and the message shown.
* The date and time it happened.

## Related Articles

* [Roles & Permissions Introduction](/articles/roles-and-permissions-introduction)
* [Roles & Permissions Guide — Creating roles and enforcing permissions](/articles/roles-and-permissions-guide-creating-roles-and-enforcing-permissions)
* [Troubleshooting account login issues](/articles/User-Accounts-Guide-Troubleshooting-account-login-issues)
* [Administrative privileges](/articles/administrative-privileges)
