Roles & privacy

Default-deny access, admin elevation, Queue Manager redaction, confidential care, and audit logging.

Epimely handles pastoral-care records as sensitive information. The security model is default-deny: records are visible only through role permissions, assignment, group leadership, explicit grants, or elevated admin mode.

The system redacts on the server before data reaches the browser or mobile app. This matters most for Queue Managers, who can route and monitor care without seeing private requester or person details.

How to

  1. Use admin mode for org-wide access

    Admins normally work in care-worker scope. Enter admin mode, re-authenticate, and use the 30-minute elevated window for org-wide reads, exports, audit log review, and access approvals.

  2. Respect Queue Manager redaction

    Queue Managers can route requests and monitor queue health, but request PII and assigned-person PII are redacted to initials or operational status. They do not get person profile visibility from queue monitoring.

  3. Handle confidential requests

    Confidential requests are limited to Pastoral Care Leaders and above. They are filtered from lists for roles that cannot access them, not merely hidden in the UI.

  4. Request access when needed

    When a user needs records outside their default scope, they can request access and wait for admin approval in Settings -> Access requests.

  5. Read the audit log

    Sensitive reads, note access, status and flag changes, role changes, elevations, access grants, exports, and work reassignment are recorded in the audit log with elevation state where relevant.

Tips

  • If the app shows no results, it may be because your current role or assignment scope does not include those records.
  • Do not use exports as a shortcut for routine browsing. Exports require admin mode for a reason.
  • The privacy model applies to both website and iOS app access.

Everyone is governed by this model. Admin-only elevation and audit tools are intentionally narrow.