Skip to content

eSHARS Roles and Permissions

Overview

eSHARS uses a Role-Based Access Control (RBAC) system to manage user permissions across the application. Roles determine what features, data, and actions a user can access based on their organizational responsibilities.

Key Concepts

ConceptDescription
RoleA named collection of permissions assigned to users
HierarchyNumeric level (1-9) indicating the role’s authority level; lower numbers = higher authority
State Level AccessWhether the role can access state-wide data across all districts
Role GroupsCategories that group related roles (Main, Finance, Internal, Nursing)
Security AreasFunctional modules within the application that can be individually permissioned

Hierarchy Levels

Level 1: Global Admin (System Owner)
Level 2: Super Admin (Full System Access)
Level 3: EDI Super Admin, EDI Admin, SMEs (Specialized System Functions)
Level 4: Admin, Admin Support, EDI Student Data, Paper Process Admin
Level 5: Paper Biller (Data Entry)
Level 6: District Admin, Exemption of Approval to Release
Level 7: Marketing Admin
Level 8: Finance Module Roles, Financial Provider
Level 9: API/Internal Roles, Client User (Most Restricted)

How Hierarchy Works

The hierarchy system enforces downward-only management - users can only manage roles and users at a lower authority level (higher number) than their own.

Rule 1: Editing Security Roles

A user can only edit a role definition if:

  • They are Level 1 (Global Admin), OR
  • Their hierarchy level is lower (more authority) than the role they’re editing
Example: A Super Admin (Level 2) can edit:
✓ EDI Admin (Level 3)
✓ District Admin (Level 6)
✓ Client User (Level 9)
✗ Global Admin (Level 1) - cannot edit equal or higher authority

Rule 2: Assigning Roles to Users

A user can assign roles to another user if:

  1. The role being assigned is at a lower authority (higher number) than the assigning user’s role
  2. The role being assigned is in the same role group as the assigning user has access to
Example: An Admin (Level 4, Main group) can assign:
✓ Paper Biller (Level 5, Main group)
✓ District Admin (Level 6, Main group)
✗ EDI Admin (Level 3) - higher authority than Admin
✗ Finance Module Admin (Level 8, Finance group) - different role group

Rule 3: Self-Management Prevention

Users cannot edit their own role assignments - this prevents privilege escalation.

Hierarchy Visualization

┌─────────────────────────────────────────────────────────────────────────┐
│ AUTHORITY FLOW (Top-Down) │
├─────────────────────────────────────────────────────────────────────────┤
│ │
│ Level 1 ──────► Can manage ALL levels below │
│ │ │
│ ▼ │
│ Level 2 ──────► Can manage levels 3-9 │
│ │ │
│ ▼ │
│ Level 3 ──────► Can manage levels 4-9 │
│ │ │
│ ▼ │
│ Level 4 ──────► Can manage levels 5-9 │
│ │ │
│ ▼ │
│ ...and so on... │
│ │
│ Level 9 ──────► Cannot manage any roles (lowest authority) │
│ │
└─────────────────────────────────────────────────────────────────────────┘

Role Groups

Roles are organized into groups that determine which functional areas of the application they can access:

GroupDescriptionPrimary Users
MainCore application functionality (visits, students, caseloads)Clinicians, District Staff, Admins
FinanceFinancial operations (invoicing, receivables, cost reports)Finance Staff, Billing Admins
InternalSystem integration and API operationsSystem Processes Only
NursingNursing-specific workflows and documentationSchool Nurses

Role Definitions

System Administration Roles

Global Admin

AttributeValue
Hierarchy1 (Highest)
State Level AccessYes
Role GroupsFinance, Internal, Main, Nursing
DescriptionThe highest level of security with complete control of the configuration. This is the system owner role.

Capabilities:

  • Full access to all system modules and data
  • System-wide configuration management
  • User and role management across all organizations
  • Access to all environments and diagnostic tools

Super Admin

AttributeValue
Hierarchy2
State Level AccessYes
Role GroupsMain, Finance, Internal
DescriptionFull access to eSHARS and manage the configuration of the system. One step below the highest security level.

Capabilities:

  • Full access to eSHARS functionality
  • System configuration management
  • Multi-district oversight and support
  • Cannot modify Global Admin settings

Support & Operations Roles

Admin

AttributeValue
Hierarchy4
State Level AccessYes
Role GroupsMain
DescriptionAccount management, account oversight, and direct support to end-users and district admins at the district site. The admins are HISD reps and MIAs (Managed Implementation Associates).

Capabilities:

  • Account management and oversight
  • Support for end-users and district admins
  • District-level configuration assistance
  • User troubleshooting and support

Admin & Paper Biller

AttributeValue
Hierarchy4
State Level AccessYes
Role GroupsMain
DescriptionSame as Admin role but includes data entry permission on behalf of a clinician.

Capabilities:

  • All Admin capabilities
  • Create visits on behalf of clinicians
  • Data entry for providers who cannot enter their own visits

Admin Support

AttributeValue
Hierarchy4
State Level AccessYes
Role GroupsMain, Finance
DescriptionSupport center role to operate and support end-users by assisting in troubleshooting technical concerns, uploads, transportation, visit creations, and account support.

Capabilities:

  • Technical troubleshooting assistance
  • Upload and import support
  • Transportation module support
  • Visit creation assistance
  • Account support operations

Admin Support & Paper Biller

AttributeValue
Hierarchy4
State Level AccessYes
Role GroupsFinance, Main
DescriptionCombined Admin Support and Paper Biller capabilities. For MFCS users only.

Capabilities:

  • All Admin Support capabilities
  • Data entry on behalf of clinicians

EDI & Billing Roles

EDI Super Admin

AttributeValue
Hierarchy3
State Level AccessYes
Role GroupsFinance, Main
DescriptionSpecial role created for HISD EDI team leader. For MFCS users ONLY.

Capabilities:

  • Full EDI module administration
  • Billing transaction oversight
  • Team leadership functions

EDI Admin

AttributeValue
Hierarchy3
State Level AccessYes
Role GroupsMain, Finance
DescriptionManage key billing operation functions within eSHARS including processing billing, scheduling of bill transactions, and appeals.

Capabilities:

  • Manage billing operations
  • Schedule billing transactions
  • Process EDI 270/271 eligibility files
  • Handle billing appeals
  • Monitor transaction status

EDI Student Data

AttributeValue
Hierarchy4
State Level AccessYes
Role GroupsMain
DescriptionManage Student Data upload functions within eSHARS. For MFCS users ONLY.

Capabilities:

  • Student data imports
  • Eligibility data management
  • Student record uploads

District-Level Roles

District Admin

AttributeValue
Hierarchy6
State Level AccessNo
Role GroupsMain, Finance
DescriptionManage and configure district-specific data such as users, clinicians, campuses, students, and reporting. Supports clinician ability to create and manage visits.

Capabilities:

  • District user management
  • Clinician management
  • Campus configuration
  • Student data management
  • District-level reporting
  • Support clinician workflows

District Admin II

AttributeValue
Hierarchy6
State Level AccessNo
Role GroupsFinance, Main
DescriptionDistrict Administrators, District Manager, District representative to oversee District along with Exemption of Approval to Release permission.

Capabilities:

  • All District Admin capabilities
  • Exemption of Approval to Release
  • District oversight functions

Exemption of Approval to Release

AttributeValue
Hierarchy6
State Level AccessNo
Role GroupsMain
DescriptionAllows impersonation of a clinician to bill on the provider’s behalf and bypass the need to have visits go through approval to release workflow.

Capabilities:

  • Impersonate clinicians
  • Bill on provider’s behalf
  • Bypass approval-to-release workflow
  • Expedited visit processing

Finance Roles

Finance Module Admin

AttributeValue
Hierarchy8
State Level AccessYes
Role GroupsFinance
DescriptionHighest level of security within the finance module. Full access to manage, configure, and is the module owner.

Capabilities:

  • Full finance module access
  • Invoice management
  • Receivables administration
  • Cost report configuration
  • Settlement management
  • Finance module configuration

Finance Module Support Admin

AttributeValue
Hierarchy8
State Level AccessNo
Role GroupsMain, Finance
DescriptionAllows MIA’s account managers to view district-specific account information such as general, invoicing, general finance reports, R&S, and Cost Report data.

Capabilities:

  • View district account information
  • Access invoicing data
  • View finance reports
  • Access R&S (Revenue & Settlement) data
  • View Cost Report data

Finance Module District User

AttributeValue
Hierarchy8
State Level AccessNo
Role GroupsFinance
DescriptionDistrict admins who oversee the financial accounts at their district including general, invoicing, general finance reports, R&S, and Cost Report data.

Capabilities:

  • District-level financial oversight
  • View invoices for their district
  • Access district finance reports
  • View R&S data for their district
  • View Cost Report data for their district

Financial Provider

AttributeValue
Hierarchy8
State Level AccessNo
Role GroupsFinance
DescriptionView limited data management functions like campus, student, visit, and district data.

Capabilities:

  • Read-only access to campus data
  • View student information
  • View visit data
  • View district information

Clinician & Provider Roles

Paper Biller

AttributeValue
Hierarchy5
State Level AccessYes
Role GroupsMain
DescriptionEssentially a data entry person on behalf of a clinician. This user impersonates a clinician and creates visits on the provider’s behalf.

Capabilities:

  • Impersonate clinicians
  • Create visits for providers
  • Data entry for paper-based documentation
  • Support providers who cannot enter visits directly

Paper Process Admin

AttributeValue
Hierarchy4
State Level AccessYes
Role GroupsMain
DescriptionSpecial role created for HISD transportation team leader. For MFCS users ONLY.

Capabilities:

  • Transportation module administration
  • Process paper-based transportation logs
  • Team leadership functions

Specialized Roles

SMEs (Subject Matter Experts)

AttributeValue
Hierarchy3
State Level AccessNo
Role GroupsMain
DescriptionSubject matter experts in eSHARS various modules. Allows granting role permissions, running ad-hoc queries, managing broadcast messages, reporting, and complete access to district data functions.

Capabilities:

  • Grant role permissions
  • Run ad-hoc database queries
  • Manage broadcast messages
  • Full reporting access
  • Complete district data access
  • Module expertise and configuration

Marketing Admin

AttributeValue
Hierarchy7
State Level AccessYes
Role GroupsMain
DescriptionAccess campus, student, visit, and status info to develop, implement, and execute strategic marketing plans for the organization to attract potential customers and retain existing ones.

Capabilities:

  • Access campus information
  • View student data
  • View visit statistics
  • Marketing analytics and reporting
  • Customer retention analysis

Client User

AttributeValue
Hierarchy9
State Level AccessYes
Role GroupsMain
DescriptionAbility to download and delete files which are in ready to process status. The role is more specific to Log Files Management module.

Capabilities:

  • Download processed files
  • Delete ready-to-process files
  • Log Files Management module access

Internal/System Roles

⚠️ WARNING: These roles are for internal system use only and should NEVER be assigned to client user accounts.

API Imports

AttributeValue
Hierarchy9
State Level AccessYes
Role GroupsInternal
DescriptionINTERNAL ROLE that should NEVER BE LINKED TO ANY CLIENT ACCOUNTS. This role allows for all imports to flow within eSHARS.

Purpose:

  • System integration for automated imports
  • API-based data ingestion
  • Batch processing operations

API TMHP/DS

AttributeValue
Hierarchy9
State Level AccessYes
Role GroupsInternal
DescriptionINTERNAL ROLE used to support the DS/RS flows and RS FILES. NO ONE SHOULD BE USING THIS ROLE or LINKING IT TO CLIENT ACCOUNTS.

Purpose:

  • TMHP (Texas Medicaid) integration
  • DS/RS file processing flows
  • Automated billing transactions

Security Areas (Modules)

Permissions within roles are further refined by Security Areas, which represent functional modules in the application:

Security AreaDescription
DashboardHome page widgets and summary views
StudentsStudent demographic and enrollment management
VisitsVisit documentation and management
CaseloadProvider-student assignment management
EDIEligibility and billing transaction management
AppealsDenied visit appeal processing
ReportsReporting and analytics
ImportsBatch data import functions
FinanceInvoicing, receivables, cost reporting
AdminSystem configuration and user management
TransportationSpecial transportation logging
NursingNursing-specific documentation

Permission Types

Within each Security Area, users can have varying levels of access:

PermissionDescription
NoneNo access to the module
ViewRead-only access
EditCan modify existing records
CreateCan create new records
DeleteCan remove records
AdminFull control including configuration

Role Assignment Guidelines

Typical Role Assignments by User Type

User TypeRecommended Role(s)
System OwnerGlobal Admin
MFCS Support StaffSuper Admin, Admin, Admin Support
District IT/AdminDistrict Admin
District SupervisorDistrict Admin II
Clinician/Provider(Clinician - not shown, implied)
Data Entry ClerkPaper Biller
Finance ManagerFinance Module Admin
District FinanceFinance Module District User
EDI SpecialistEDI Admin

Best Practices

  1. Principle of Least Privilege - Assign the minimum role necessary for the user’s job function
  2. Avoid Internal Roles - Never assign API Imports or API TMHP/DS to human users
  3. State Level Access - Only grant to users who genuinely need cross-district visibility
  4. Regular Audits - Periodically review role assignments for appropriateness
  5. Separation of Duties - Avoid giving single users conflicting permissions

Role Hierarchy Diagram

┌─────────────────────────────────────────────────────────────────────────────┐
│ ROLE HIERARCHY │
└─────────────────────────────────────────────────────────────────────────────┘
Level 1 ┌──────────────┐
│ Global Admin │ ◄── System Owner (Full Control)
└──────┬───────┘
Level 2 ┌──────┴───────┐
│ Super Admin │ ◄── Full Access, One Step Below Global
└──────┬───────┘
┌──────┴───────┬─────────────────┬─────────────────┐
Level 3 │ │ │ │
┌────┴────┐ ┌─────┴─────┐ ┌──────┴──────┐ ┌──────┴──────┐
│EDI Super│ │ EDI Admin │ │ SMEs │ │(Other L3) │
│ Admin │ │ │ │ │ │ │
└─────────┘ └───────────┘ └─────────────┘ └─────────────┘
┌──────┴───────┬─────────────────┬─────────────────┐
Level 4 │ │ │ │
┌────┴────┐ ┌─────┴─────┐ ┌──────┴──────┐ ┌──────┴──────┐
│ Admin │ │Admin │ │ EDI Student │ │Paper Process│
│ │ │Support │ │ Data │ │ Admin │
└─────────┘ └───────────┘ └─────────────┘ └─────────────┘
Level 5 ┌──────┴───────┐
│ Paper Biller │ ◄── Data Entry on Behalf of Clinicians
└──────┬───────┘
┌──────┴───────┬─────────────────┐
Level 6 │ │ │
┌────┴────────┐ ┌─┴───────────────┐ │
│District │ │ District │ │ ┌───────────────────┐
│Admin │ │ Admin II │ └─│Exemption of │
└─────────────┘ └─────────────────┘ │Approval to Release│
└───────────────────┘
Level 7 ┌──────┴───────┐
│Marketing │ ◄── Marketing Analytics
│Admin │
└──────┬───────┘
Level 8 ┌──────┴───────┬─────────────────┬─────────────────┐
┌────┴────────┐ ┌─┴───────────────┐ │ ┌───────────────┴───┐
│Finance │ │Finance Module │ │ │Financial │
│Module Admin │ │Support Admin │ └─│Provider │
└─────────────┘ └─────────────────┘ └───────────────────┘
Level 9 ┌──────┴───────┬─────────────────┐
┌────┴────────┐ ┌─┴───────────────┐ ┌───────────────────┐
│ API Imports │ │ API TMHP/DS │ │ Client User │
│ (INTERNAL) │ │ (INTERNAL) │ │ │
└─────────────┘ └─────────────────┘ └───────────────────┘

User Guides by Role


Documentation generated: January 2026