rcpch / national-paediatric-diabetes-audit

A django application to audit the care of children and young people with diabetes in England and Wales.
0 stars 1 forks source link

Permissions Discussion #126

Open dc2007git opened 2 weeks ago

dc2007git commented 2 weeks ago

[ discussion with @eatyourpeas ]

For clarification, we should ask the NPDA team if they are happy with the current set of permissions that have been assigned to roles (for reference, these are in the documentation site in the dev section in the Users page).

Some questions to pass on:

  1. For the can opt out patient permission, is it okay for this to be assigned to lead clinician, npda audit team + superusers?
  2. Should we use the CAN_LOCK_CHILD_PATIENT_DATA_FROM_EDITING permission? We shouldn't have to edit patients in previous cohorts, we'll only be able to edit patients in the current cohort and as such there's no need to lock patients like in E12.
  3. Should the site administrator have access / be able to edit clinical data?
dc2007git commented 2 weeks ago

@mbarton @eatyourpeas on the topic of these permissions, have we decided which users should be able to add other users? Is it lead clinician, administrator and rcpch audit team?

mbarton commented 1 week ago

We've not decided but I think it's fine to go with lead clinician and administrator to start with then broaden it out

dc2007git commented 1 week ago

No worries - we can ask Amani tomorrow at the meeting what she and the team would like!

dc2007git commented 1 week ago

Just to note have also added these permissions for the audit team members