As an administrator, you can add and manage roles with associated permissions and then assign those roles to users within Rad AI Reporting.
In this article:
- Prerequisites
- Overview
- Adding a new role and configuring permissions
- Viewing an existing role and permissions
- Editing an existing role and permissions
- Assigning one or multiple roles to a user
Prerequisites
You’ve been assigned a role (e.g., “Admin”) that has Admin Access permission.
Overview
Rad AI Reporting uses role-based access control (RBAC), a security framework that ensures only authorized users can access specific information or perform certain tasks.
Administrators can create new roles or configure existing ones by enabling or disabling associated permissions. Then they can assign one or multiple roles to each user as well as assign different roles to a user at different sites.
Key terminology and definitions
| Term | Definition |
| permission | A permission governs whether certain tasks—such as creating a report or viewing a document—can be performed within Rad AI Reporting. Permissions can be enabled or disabled for each role. |
| role | A role is a collection of permissions. Roles are typically designed to correspond to job functions or responsibilities within an organization. The associated permissions allow people in that role to perform their job effectively. For example, a “Radiologist” role may include permissions such as View Report, Create Report, and Sign Report. Users can be assigned different roles at different sites. |
| user | A user is an individual with access to Rad AI Reporting. To let a user perform specific tasks, assign them a role with the appropriate permissions.Users can be assigned multiple roles. For more information, see Adding and managing users. |
Preconfigured roles and permissions
Rad AI Reporting comes with three preconfigured roles:
- Admin (Administrator): Can view reports and perform administrative actions, but can’t create, edit, or sign reports
- Radiologist: Can write, view, edit, and sign reports, but can’t perform administrative actions
- Resident: Can write, view, and edit reports, but can’t sign them or perform administrative actions.
You can view the permissions that are enabled or disabled for each default role below:
| Permission Group | Permission | Admin | Radiologist | Resident |
| Addendum | Create Addendum | ❌ | ✔ | ✔ |
| List Addendum | ✔ | ✔ | ✔ | |
| Sign Addendum | ❌ | ✔ | ❌ | |
| Update Addendum | ❌ | ✔ | ✔ | |
| View Addendum | ✔ | ✔ | ✔ | |
| Admin | Admin Access | ✔ | ❌ | ❌ |
| Auto-Launch Rules | Create Auto Launch Rules | ✔ | ✔ | ✔ |
| List Auto Launch Rules | ✔ | ✔ | ✔ | |
| Update Auto Launch Rules | ✔ | ✔ | ✔ | |
| Collection | Create Collection | ✔ | ✔ | ✔ |
| Delete Collection | ✔ | ✔ | ✔ | |
| List Collections | ✔ | ✔ | ✔ | |
| Update Collection | ✔ | ✔ | ✔ | |
| View Collection | ✔ | ✔ | ✔ | |
| Document | Create Document | ❌ | ✔ | ✔ |
| Delete Document | ❌ | ❌ | ❌ | |
| List Documents | ✔ | ✔ | ✔ | |
| Update Document | ❌ | ✔ | ✔ | |
| View Document | ✔ | ✔ | ✔ | |
| Group | Create Group | ✔ | ❌ | ❌ |
| View Group | ✔ | ❌ | ❌ | |
| List Groups | ✔ | ❌ | ❌ | |
| Update Group | ✔ | ❌ | ❌ | |
| Integration | List Integrations | ✔ | ❌ | ❌ |
| Update Integration | ✔ | ❌ | ❌ | |
| Observation | Manage Observation | ✔ | ❌ | ❌ |
| Read Observation | ✔ | ✔ | ✔ | |
| Report | Create Report | ❌ | ✔ | ✔ |
| Delete Report | ❌ | ❌ | ❌ | |
| Dictate Report | ❌ | ✔ | ✔ | |
| List Reports | ✔ | ✔ | ✔ | |
| List as Report Author | ✔ | ✔ | ✔ | |
| Mark as Review/Prelim With No Finalizing Author | ❌ | ✔ | ✔ | |
| Print Report | ✔ | ✔ | ✔ | |
| Sign Preliminary Report | ❌ | ✔ | ✔ | |
| Revert Preliminary Report to Draft | ✔ | ❌ | ❌ | |
| Revert Report to Draft (Before ORU Sent) | ✔ | ❌ | ❌ | |
| Revert Report to Draft (After ORU Sent) | ❌ | ❌ | ❌ | |
| Search Report | ✔ | ✔ | ✔ | |
| Sign Report | ❌ | ✔ | ❌ | |
| Update Report | ❌ | ✔ | ✔ | |
| View Report | ✔ | ✔ | ✔ | |
| View Canceled Studies | ✔ | ❌ | ❌ | |
| View Scheduled Studies | ✔ | ❌ | ❌ | |
| View Version History for Other Users' Reports | ✔ | ❌ | ❌ | |
| Report Outbound | Dissociate Study Report Outbound | ✔ | ❌ | ❌ |
| List Report Outbounds | ✔ | ❌ | ❌ | |
| Manage Studies Report Outbound | ✔ | ❌ | ❌ | |
| Resend Report Outbound | ✔ | ❌ | ❌ | |
| Role | Create Role | ✔ | ❌ | ❌ |
| List Roles | ✔ | ❌ | ❌ | |
| Update Role | ✔ | ❌ | ❌ | |
| View Role | ✔ | ❌ | ❌ | |
| Site | Create Site | ✔ | ❌ | ❌ |
| List Sites | ✔ | ❌ | ❌ | |
| Update Site | ✔ | ❌ | ❌ | |
| View Site | ✔ | ❌ | ❌ | |
| Template | Copy Template | ✔ | ✔ | ✔ |
| Create Template | ✔ | ✔ | ✔ | |
| Delete Template | ✔ | ✔ | ✔ | |
| List Templates | ✔ | ✔ | ✔ | |
| Update Template | ✔ | ✔ | ✔ | |
| View Template | ✔ | ✔ | ✔ | |
| User | Create User | ✔ | ❌ | ❌ |
| List Users | ✔ | ✔ | ✔ | |
| Update User | ✔ | ❌ | ❌ | |
| View User | ✔ | ✔ | ✔ | |
| Validation | HL7 Validation | ✔ | ❌ | ❌ |
Adding a new role and configuring permissions
You can create a new role (e.g., “Assistant”) within Rad AI Reporting and select the associated permissions.
-
Select Admin > Roles from the main navigation menu on the left-hand side.
-
Click the Add role button in the top-right corner of the page. The Add role dialog will appear.
- Type the name of the new role in the Name field.
-
Click on the down arrow next to each permission group to view all the available permissions. Select the ones you want to associate with this role.
- Select every available permission, click the checkbox next to Permission.
- To search for a specific permission, type its name in the search bar.
- To select all permissions in a group, click Select all on the right.
- To unselect all permissions in a group, click Deselect on the right.
- To show only the permissions you selected, turn on the Show only selected permissions toggle.
⚠️ Some tasks may require multiple permissions to be associated with a role. See some examples below:Task Required permissions Opening the worklist and viewing an existing report - Update Report
- View Report
- Update Document
- Sign Report
Dictating a report - Update Report
- Update Document
- Dictate Report
Signing a report - Update Report
- View Report
- Update Document
- Sign Report
-
Click the Save button. The new role will appear in the list of roles.
💡 To assign the new role to a user, see Assigning a role to a user.
Viewing an existing role and permissions
You can view a list of all the permissions associated with a specific role. You can narrow your search by applying the following filters:
-
Select Admin > Roles from the main navigation menu on the left-hand side.
-
Double-click on a role name in the list. The Role dialog will appear.
-
Click the Show only selected permissions toggle to view all the permissions associated with the role.
Filtering roles by permissions
You can filter the list of roles by the permissions that are associated with them.
- Click the filter icon on the right-hand side of the search bar at the top of the page.
- Click on the Permissions drop-down menu and select the permissions you want to filter the roles by. You can select more than one.
- Click the Search button. The filtered roles will appear in the list.
Filtering roles by active/deactivated status
You can filter the list of roles to determine which ones are active or have been deactivated.
-
Click the filter icon on the right-hand side of the search bar at the top of the page.
-
Click on the Active/Deactivated drop-down menu and select either Active or Deactivated.
- Click the Search button. The filtered roles will appear in the list.
Filtering roles by created since/created before dates
You can filter the list of roles by whether they were created before and/or after a specified date.
-
Click the filter icon on the right-hand side of the search bar at the top of the page.
-
Enter a date in the Created since field and/or the Created before field. You can also click on the calendar icon and select a date.
- Click the Search button. The filtered roles will appear in the list.
Editing an existing role and permissions
You can edit the name of a role and the permissions that are associated with it. You can also deactivate or reactivate a role.
- Follow the steps in the Viewing an existing role and permissions section to search for the role you want to edit.
- In the Role dialog, you can edit the Name field and the selected permissions by following steps 3–5 in the Adding a new role and configuring permissions section. You also have the options to:
Deactivating a role
If you no longer want a role to be available to assign to users, you can deactivate it.
-
Select Admin > Roles from the main navigation menu on the left-hand side.
- Click the three dots on the right-hand side of the role you'd like to deactivate and select Deactivate Role.
- In the Deactivate Role dialog that opens, click the Confirm button.
Reactivating a role
You can reactivate any roles that have been deactivated.
- Select Admin > Roles from the main navigation menu on the left-hand side.
-
Click the filter icon on the right-hand side of the search bar at the top of the page.
-
Click on the Active/Deactivated drop-down menu and select Deactivated.
-
Click the Search button. All deactivated roles will appear in the list.
- Click the three dots on the right-hand side of the role you'd like to re-activate and select Activate Role.
- In the Activate Role dialog that opens, click the Confirm button.
Assigning one or multiple roles to a user
You can assign one or multiple roles to an existing user. To add a new user, see Adding and managing users.
-
Select Admin > Users from the main navigation menu on the left-hand side.
-
To search for a user, do one of the following:
- In the search bar at the top of the page, enter the name or email address of the user and then double-click on their name within the list that appears.
- Click the filter icon to apply filters and narrow down the user list. Then click the Search button.
💡 You can sort each column in the user list by ascending or descending order by clicking on the column headers.
- Double-click on the user in the list to open the Edit user dialog.
- Click on the Sites and Roles tab.
-
Click on the Roles drop-down menu and select the role(s) you want to assign to the user.
💡 To remove a selected role, click on it in the Roles drop-down menu.6. Click the Sites drop-down menu and select one or multiple sites at which the user will have this role. By default, the All sites option is selected. You can also assign users different roles at different sites.
💡 Sites determine what data the user has access to. For example, if the user is assigned to site A and not site B, they can only see reports sent to site A in report lists (as long as their assigned role for site A has the "List Report" permission).⚠️ If you assign the “Admin” role to a user only at specific sites instead of all sites, there will be limitations to what they can do. You must select All Sites from the Sites drop-down menu to allow admins to edit organization-wide settings. Learn more.7. Click the Save button.
Assigning different roles to a user at different sites
By default, new users have the same role(s) and associated permissions across all sites in your organization. However, you may want to only provide users with access to certain sites, or assign users different roles and permissions at different sites.
For example, you may want a user to have a “Radiologist” role (with associated permissions) at site A, but have an “Admin” role (with associated permissions) at site B.
- Follow steps 1–6 in Assigning roles to a user.
-
To specify a different role (and optional practitioner ID) for the user at different sites, click on Specify a different Role or Practitioner ID.
💡 To remove a section with the assigned sites and roles, click the trash can icon. -
(Required) Click the Roles drop-down menu and select the role(s) you want to assign to this user.
💡 To remove a selected role, click on it in the Roles drop-down menu. -
(Required) Click the Sites drop-down menu and select one or multiple sites at which the user will have this role. By default, the All sites option is selected.
💡 To remove a selected option from the Sites drop-down menu, click on the X next to it. -
(Optional) Enter the user’s Practitioner ID.
💡 The Practitioner ID field is optional and will be included in the user’s signature in Outbound HL7 if set. If it’s not set, the user’s email address will be sent out by default. -
Click the Save button. The user now has different roles depending on the site.
⚠️ If you choose to use different roles or practitioner IDs at different sites but don’t specify roles for all sites in your organization, the user won’t have access to those excluded sites.
All-site admins vs specific site admins
When you assign the "Admin" role to a user, you also choose the sites where that role applies. This determines whether they are an all-site admin (organization-wide) or a specific site admin (limited to one or more sites).
-
All-site admins: Have the Admin role with All sites selected. They can edit organization-wide settings, including:
Roles
Users
Sites
All-site observations
All-site template collections and related auto-launch rules
System configuration: integrations, auto-launch rules priority order, and attestations
Specific site admins: Have the Admin role assigned only to specific sites. They can perform admin tasks for those sites, but can’t edit the organization-wide settings listed above.
Making a user an all-site admin
Select Admin > Users from the main navigation menu on the left-hand side.
Search for and open the user you want to update.
In the Sites and Roles tab, open the Roles drop-down menu and select Admin (and any other roles you want to assign).
In the Sites drop-down menu, make sure All sites is selected.
Click the Save button. The user is now an all-site admin and can manage organization-wide settings.
Making a user a specific site admin
Select Admin > Users from the main navigation menu on the left-hand side.
Search for and open the user you want to update.
In the Sites and Roles tab, open the Roles drop-down menu and select Admin.
In the Sites drop-down menu, select only the site or sites where you want this user to be an admin (do not select "All sites").
Click the Save button. The user is now an admin only at the selected sites and cannot edit organization-wide settings such as roles, users, sites, and system configuration.