GeNext MedEd FoundationLearn • Collaborate • Elevate

INSTITUTIONAL RECORD

Role Permission & Access Control Standard

GMEF-AUTH-003 · Controlled GeNext MedEd Foundation record

READ ONLINE

Document content

This page is the readable website view of the controlled institutional source.

GeNext MedEd Foundation — Role Permission & Access Control Standard

Document code: GMEF-AUTH-003
Version: 1.0
Status: Controlled working standard

Purpose
Translates institutional roles into system permissions for GeNext Connect, internal registers, document repositories and administrative tools.

Permission principles
Least privilege; need-to-know; separation of duties; time-bound elevated access; explicit approval for sensitive data; auditable changes; prompt removal when a role ends.

Permission layers
Public: approved public pages, verification outcomes and released resources.
Authenticated professional/member: role-appropriate programme, community or learning access.
Programme operational: applications, attendance, assessments and cohort records for assigned programmes.
Faculty/mentor: assigned learner/programme functions; no general administrative access by default.
Research: project-specific access according to role and governance/data rules.
Institution reviewer: host-centre evidence and site review within assigned cases.
Quality/audit: read/review access necessary for assurance, with restricted write/closure authority.
Ethics/grievance: case-specific restricted access.
Document/library administration: controlled publishing and metadata; substantive approval remains with designated authority.
System administrator: technical administration; does not automatically confer academic, ethics, certificate or research authority.

High-risk actions
The following should require explicit permission and audit logging: changing verification status; approving a programme/site; changing assessment outcome; issuing/revoking a certificate; releasing restricted clinical material; activating a research project; viewing sensitive grievance records; changing role/permission assignments; deleting or superseding controlled records.

Access lifecycle
Request → authority approval → provision → periodic review → modification where role changes → suspension/revocation → retained audit history.

Shared credentials
Shared user accounts/passwords should not be used for accountable institutional decisions. Actions should resolve to an authorised person or service identity.

Emergency access
Break-glass/emergency access, if implemented, must be exceptional, logged, reason-coded and reviewed after use.
Role Permission & Access Control Standard | GeNext MedEd Foundation