Identity and Access Management
Healthcare People Do Not Work
for One Organization
The Challenge
Single sign-on is a sales requirement before it is a security feature
The deeper issue is that healthcare access is contextual. Whether somebody should see a record depends on their relationship to it, not only on their job title, and a role-based model alone cannot express that without creating a role for every combination.
Roles Multiply Until They Mean Nothing
Deprovisioning Is Where It Fails
Shared Logins Appear Where the Model Cannot Cope
Machine Identities Outnumber Human Ones
Access Is Contextual
Care relationship, client assignment and case scope cannot be expressed cleanly through categorical roles alone.
Nobody Reviews What Accumulated
List everybody with access who no longer needs it.
Our Approach
Model the relationship, not just the role
Step 1
Step 2
Step 3
Step 4
Design roles as capability bundles with a governance process, so the list stays comprehensible and auditable.
Step 5
Treat machine identities as first-class, with an owner, a scope, an expiry and a review.
Step 6
Step 7
Step 8
Step 9
Step 10
Every shared login is a product design failure, not a customer discipline problem.
Capabilities
Identity, authorization, provisioning, governance
Identity
Multi-Organization Identity Model
Authentication and Single Sign-On
Patient and External Identity
proofing, recovery and support paths for people who will not call an IT desk.
Machine and Service Identity
Authorization
Role and Capability Design
Contextual and Attribute-Based Access
Tenant Scope Enforcement
Break-Glass Access
Provision and Govern
Enterprise Provisioning
Lifecycle Automation
joiner, mover and leaver handled as events rather than requests somebody remembers.
Access Review Tooling
customer-run review of who holds what and what each role permits.
Access Audit and Evidence
who can reach what, who did reach what and when, per customer and record.
What CaliberFocus does, and does not do.
Where It Applies
Seven identity types, and most products designed for one
Product identity models are usually built for the customer employee logging in during business hours. The third column is what each of the other types actually requires.
| Identity Type | Who They Are | What They Require |
|---|---|---|
| Customer Workforce | Staff at the organization that bought your product | Directory provisioning, and this is the only one most products handle well. |
| Multi-Organization Clinicians | Practising at several facilities with different privileges | One identity, several memberships. The model failure that produces most workarounds. |
| Agency and Temporary Staff | Present for weeks, covering shifts, then gone | Time-bound access with automatic expiry rather than a removal somebody must remember. |
| Outsourced and Offshore Teams | A vendor serving several of your customers | Access scoped per client assignment, with clear separation between them. |
| Consultants and Implementers | Configuring and migrating across several customers | Temporary, scoped, auditable access that does not require a permanent account. |
| Machine and API Identities | Integrations, automations and services | Owner, scope, expiry and review. They outnumber humans and are governed least. |
| AI Agents | Software acting with delegated authority | Separate grants for data, tools and actions, since capability must never imply permission. |
Administration Is a Capability, Not a Universal Permission
The ability to add users, configure workflows, manage integrations and assign roles does not require unrestricted access to patient information. Programmatic identities operate faster than humans and reach larger datasets, so their privileges should be narrower rather than broader.
The Method
Roles answer some questions. Attributes answer the rest.
| Mechanism | What It Decides Well | Where It Breaks Down |
|---|---|---|
| Authentication | Who this person or system is | It is routinely treated as permission, which is where escalation begins. |
| Role | What category of work somebody does | Relationship, assignment and time. Adding roles for these is how lists reach fifty. |
| Tenant Scope | Whose data they may reach | Nothing. It is the foundation and it must be structural rather than a filter. |
| Attribute and Context | Care relationship, assignment, location, time, case | Complexity. Rules become hard to reason about if nobody owns the policy. |
| Record-Level Scope | Which specific records within a customer | Performance and design effort, which is why it is frequently skipped. |
| Break-Glass | Legitimate urgent access outside normal rules | Becoming ordinary if it is not time-bound, visible and reviewed. |
Engineering Discipline
Privilege and Lifecycle
Most of your identities are not people
Service & System Accounts
Integration & Partner Credentials
Support & Engineering Access
AI Agent Identities
Administrative Access
Secrets & Credentials
The lifecycle has seven stages and one is usually missing.
Trust
Your customer has to attest to access they cannot see
Access Governance
Lifecycle
Auditability
Compliance Engineering
Give customers the access report rather than making them ask for it.
Outcomes
Faster onboarding, smaller access surface, fewer shared logins
| Category | What We Measure | Why It Matters |
|---|---|---|
| Cross-Customer Reach | How many identities can access more than one customer, human and machine, and why each still can | The clearest single measure of access risk in a multi-tenant healthcare product. |
| Enterprise Onboarding | Time to provision a customer with directory integration and single sign-on | A sales-cycle measure and common reason implementations run long. |
| Deprovisioning Latency | Time from a person leaving to access being removed, and accounts still active in error | The most common access finding and easiest to correct once measured. |
| Shared Credential Usage | Accounts showing concurrent or implausible use patterns | Each is an audit trail identifying nobody and a product-design signal. |
| Machine Identity Governance | Non-human identities with an owner, scope and expiry | They outnumber people and are reviewed least. |
| Role Comprehensibility | Number of roles and whether an owner can explain what each permits | A catalogue past auditability cannot support minimum necessary. |
Honest expectation setting
Reduce access risk, simplify enterprise onboarding and strengthen customer trust.
Start with the clinical workflow, not the ambient AI platform.
Bring us a specialty or clinical setting where clinicians are spending too much time creating notes. We will assess where ambient documentation fits, what must remain clinician controlled, how it should integrate with your EHR, and how to measure whether it is actually reducing burden.
- AI Agents and Workflow Automation
- Voice and Conversational AI
- Document AI and Intelligent Processing
- Generative AI and Enterprise Copilots
- AI Strategy and Governance
- HCC and Risk Adjustment Analytics
Security & Compliance
