For AI agents: the documentation index is at /docs/aidbox/llms.txt. A Markdown version of this page is available at /docs/aidbox/modules/eprescription/epcs/access-management/configure-access-policies.md or by requesting it with the Accept: text/markdown header.
Aidbox Docs

Configure Access Policies

Acting User

Every call needs an acting user: the Aidbox User authenticated for the request. A request made with only a Client credential has no acting user, and the module returns 403.

Access Policies

bootstrap-admin does not require the caller to be an access manager. At a location with no administrator, any acting user allowed by your AccessPolicies can grant that role to themselves or to another user. Restrict this operation to deployment operators. See the AccessPolicy documentation for policy configuration. Do not expose it to EHR users or to an administration UI.

Write a policy for each operation and grant it to the smallest group that needs it:

  • POST /e-prescription/access/epcs/bootstrap-admin: the operators who set up locations during deployment.
  • GET /e-prescription/access/epcs/permissions: administrators.
  • GET /e-prescription/access/epcs/permissions/mine: the users who work in the prescribing UI.
  • GET /e-prescription/access/epcs/requests: administrators and nominees.
  • POST /e-prescription/access/epcs/requests: administrators.
  • POST /e-prescription/access/epcs/requests/<id>/approve: nominees.
  • POST /e-prescription/access/epcs/requests/<id>/cancel: administrators and nominees.

The module checks each caller's role as described in Approver Nominations.

This example policy matches a field of your User resource. Replace data.role and its value with whatever your EHR stores on its users.

resourceType: AccessPolicy
id: erx-epcs-bootstrap-admin
engine: matcho
matcho:
  uri: /e-prescription/access/epcs/bootstrap-admin
  request-method: post
  user:
    data:
      role: deployment-operator

Last updated: