Skip to main content
Carelane uses a hierarchical role-based access control (RBAC) system to manage permissions across organizations, studies, sites, and service providers.

Role Hierarchy

Roles exist at four levels, each with its own scope of permissions:

Organization Roles

Control access to organization-wide settings and resources.

Study Roles

Manage study-level operations and oversight.

Site Roles

Handle site-specific data collection and participant management.

Service Provider Roles

Enable external service providers like laboratories.

Role Scopes Overview

ScopeRolesPurpose
OrganizationAdministrator, MemberManage organization settings and access
StudyStudy Administrator, CI, D-CI, Data Reviewer, Reviewer, CollaboratorOversee study operations and data review
SitePI, Site Admin, Deputy PI, Sub-Investigator, CRC, Data Entry Specialist, Site Collaborator, Authorized Signer, Local Lab Lead/MemberExecute site operations and data entry
Service ProviderLaboratory Lead, Laboratory AssistantProvide centralized services across sites

Permission Inheritance

Higher-level roles do not automatically grant lower-level permissions. An organization administrator still needs explicit study or site roles to access specific studies or sites.

Role Assignment

Roles are assigned through invitations:
1

Invite User

An administrator invites a user via email to join at a specific level (organization, study, or site).
2

Select Role

During invitation, the administrator selects the appropriate role for the user.
3

User Accepts

The invited user accepts the invitation and gains the assigned permissions.

Multiple Roles

Users can hold multiple roles simultaneously:
  • Different roles in different studies within the same organization
  • Different roles at different sites within the same study
  • Roles at multiple levels (e.g., Study Administrator and Site PI)
When a user has multiple roles, they receive the union of all permissions from those roles.

Audit Trail

All role assignments and changes are recorded in the audit trail, including:
  • Who made the assignment
  • When the change occurred
  • The previous and new role values