eSHARS Roles and Permissions
Overview
eSHARS uses a Role-Based Access Control (RBAC) system to manage user permissions across the application. Roles determine what features, data, and actions a user can access based on their organizational responsibilities.
Key Concepts
| Concept | Description |
|---|---|
| Role | A named collection of permissions assigned to users |
| Hierarchy | Numeric level (1-9) indicating the role’s authority level; lower numbers = higher authority |
| State Level Access | Whether the role can access state-wide data across all districts |
| Role Groups | Categories that group related roles (Main, Finance, Internal, Nursing) |
| Security Areas | Functional modules within the application that can be individually permissioned |
Hierarchy Levels
Level 1: Global Admin (System Owner)Level 2: Super Admin (Full System Access)Level 3: EDI Super Admin, EDI Admin, SMEs (Specialized System Functions)Level 4: Admin, Admin Support, EDI Student Data, Paper Process AdminLevel 5: Paper Biller (Data Entry)Level 6: District Admin, Exemption of Approval to ReleaseLevel 7: Marketing AdminLevel 8: Finance Module Roles, Financial ProviderLevel 9: API/Internal Roles, Client User (Most Restricted)How Hierarchy Works
The hierarchy system enforces downward-only management - users can only manage roles and users at a lower authority level (higher number) than their own.
Rule 1: Editing Security Roles
A user can only edit a role definition if:
- They are Level 1 (Global Admin), OR
- Their hierarchy level is lower (more authority) than the role they’re editing
Example: A Super Admin (Level 2) can edit: ✓ EDI Admin (Level 3) ✓ District Admin (Level 6) ✓ Client User (Level 9) ✗ Global Admin (Level 1) - cannot edit equal or higher authorityRule 2: Assigning Roles to Users
A user can assign roles to another user if:
- The role being assigned is at a lower authority (higher number) than the assigning user’s role
- The role being assigned is in the same role group as the assigning user has access to
Example: An Admin (Level 4, Main group) can assign: ✓ Paper Biller (Level 5, Main group) ✓ District Admin (Level 6, Main group) ✗ EDI Admin (Level 3) - higher authority than Admin ✗ Finance Module Admin (Level 8, Finance group) - different role groupRule 3: Self-Management Prevention
Users cannot edit their own role assignments - this prevents privilege escalation.
Hierarchy Visualization
┌─────────────────────────────────────────────────────────────────────────┐│ AUTHORITY FLOW (Top-Down) │├─────────────────────────────────────────────────────────────────────────┤│ ││ Level 1 ──────► Can manage ALL levels below ││ │ ││ ▼ ││ Level 2 ──────► Can manage levels 3-9 ││ │ ││ ▼ ││ Level 3 ──────► Can manage levels 4-9 ││ │ ││ ▼ ││ Level 4 ──────► Can manage levels 5-9 ││ │ ││ ▼ ││ ...and so on... ││ ││ Level 9 ──────► Cannot manage any roles (lowest authority) ││ │└─────────────────────────────────────────────────────────────────────────┘Role Groups
Roles are organized into groups that determine which functional areas of the application they can access:
| Group | Description | Primary Users |
|---|---|---|
| Main | Core application functionality (visits, students, caseloads) | Clinicians, District Staff, Admins |
| Finance | Financial operations (invoicing, receivables, cost reports) | Finance Staff, Billing Admins |
| Internal | System integration and API operations | System Processes Only |
| Nursing | Nursing-specific workflows and documentation | School Nurses |
Role Definitions
System Administration Roles
Global Admin
| Attribute | Value |
|---|---|
| Hierarchy | 1 (Highest) |
| State Level Access | Yes |
| Role Groups | Finance, Internal, Main, Nursing |
| Description | The highest level of security with complete control of the configuration. This is the system owner role. |
Capabilities:
- Full access to all system modules and data
- System-wide configuration management
- User and role management across all organizations
- Access to all environments and diagnostic tools
Super Admin
| Attribute | Value |
|---|---|
| Hierarchy | 2 |
| State Level Access | Yes |
| Role Groups | Main, Finance, Internal |
| Description | Full access to eSHARS and manage the configuration of the system. One step below the highest security level. |
Capabilities:
- Full access to eSHARS functionality
- System configuration management
- Multi-district oversight and support
- Cannot modify Global Admin settings
Support & Operations Roles
Admin
| Attribute | Value |
|---|---|
| Hierarchy | 4 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Account management, account oversight, and direct support to end-users and district admins at the district site. The admins are HISD reps and MIAs (Managed Implementation Associates). |
Capabilities:
- Account management and oversight
- Support for end-users and district admins
- District-level configuration assistance
- User troubleshooting and support
Admin & Paper Biller
| Attribute | Value |
|---|---|
| Hierarchy | 4 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Same as Admin role but includes data entry permission on behalf of a clinician. |
Capabilities:
- All Admin capabilities
- Create visits on behalf of clinicians
- Data entry for providers who cannot enter their own visits
Admin Support
| Attribute | Value |
|---|---|
| Hierarchy | 4 |
| State Level Access | Yes |
| Role Groups | Main, Finance |
| Description | Support center role to operate and support end-users by assisting in troubleshooting technical concerns, uploads, transportation, visit creations, and account support. |
Capabilities:
- Technical troubleshooting assistance
- Upload and import support
- Transportation module support
- Visit creation assistance
- Account support operations
Admin Support & Paper Biller
| Attribute | Value |
|---|---|
| Hierarchy | 4 |
| State Level Access | Yes |
| Role Groups | Finance, Main |
| Description | Combined Admin Support and Paper Biller capabilities. For MFCS users only. |
Capabilities:
- All Admin Support capabilities
- Data entry on behalf of clinicians
EDI & Billing Roles
EDI Super Admin
| Attribute | Value |
|---|---|
| Hierarchy | 3 |
| State Level Access | Yes |
| Role Groups | Finance, Main |
| Description | Special role created for HISD EDI team leader. For MFCS users ONLY. |
Capabilities:
- Full EDI module administration
- Billing transaction oversight
- Team leadership functions
EDI Admin
| Attribute | Value |
|---|---|
| Hierarchy | 3 |
| State Level Access | Yes |
| Role Groups | Main, Finance |
| Description | Manage key billing operation functions within eSHARS including processing billing, scheduling of bill transactions, and appeals. |
Capabilities:
- Manage billing operations
- Schedule billing transactions
- Process EDI 270/271 eligibility files
- Handle billing appeals
- Monitor transaction status
EDI Student Data
| Attribute | Value |
|---|---|
| Hierarchy | 4 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Manage Student Data upload functions within eSHARS. For MFCS users ONLY. |
Capabilities:
- Student data imports
- Eligibility data management
- Student record uploads
District-Level Roles
District Admin
| Attribute | Value |
|---|---|
| Hierarchy | 6 |
| State Level Access | No |
| Role Groups | Main, Finance |
| Description | Manage and configure district-specific data such as users, clinicians, campuses, students, and reporting. Supports clinician ability to create and manage visits. |
Capabilities:
- District user management
- Clinician management
- Campus configuration
- Student data management
- District-level reporting
- Support clinician workflows
District Admin II
| Attribute | Value |
|---|---|
| Hierarchy | 6 |
| State Level Access | No |
| Role Groups | Finance, Main |
| Description | District Administrators, District Manager, District representative to oversee District along with Exemption of Approval to Release permission. |
Capabilities:
- All District Admin capabilities
- Exemption of Approval to Release
- District oversight functions
Exemption of Approval to Release
| Attribute | Value |
|---|---|
| Hierarchy | 6 |
| State Level Access | No |
| Role Groups | Main |
| Description | Allows impersonation of a clinician to bill on the provider’s behalf and bypass the need to have visits go through approval to release workflow. |
Capabilities:
- Impersonate clinicians
- Bill on provider’s behalf
- Bypass approval-to-release workflow
- Expedited visit processing
Finance Roles
Finance Module Admin
| Attribute | Value |
|---|---|
| Hierarchy | 8 |
| State Level Access | Yes |
| Role Groups | Finance |
| Description | Highest level of security within the finance module. Full access to manage, configure, and is the module owner. |
Capabilities:
- Full finance module access
- Invoice management
- Receivables administration
- Cost report configuration
- Settlement management
- Finance module configuration
Finance Module Support Admin
| Attribute | Value |
|---|---|
| Hierarchy | 8 |
| State Level Access | No |
| Role Groups | Main, Finance |
| Description | Allows MIA’s account managers to view district-specific account information such as general, invoicing, general finance reports, R&S, and Cost Report data. |
Capabilities:
- View district account information
- Access invoicing data
- View finance reports
- Access R&S (Revenue & Settlement) data
- View Cost Report data
Finance Module District User
| Attribute | Value |
|---|---|
| Hierarchy | 8 |
| State Level Access | No |
| Role Groups | Finance |
| Description | District admins who oversee the financial accounts at their district including general, invoicing, general finance reports, R&S, and Cost Report data. |
Capabilities:
- District-level financial oversight
- View invoices for their district
- Access district finance reports
- View R&S data for their district
- View Cost Report data for their district
Financial Provider
| Attribute | Value |
|---|---|
| Hierarchy | 8 |
| State Level Access | No |
| Role Groups | Finance |
| Description | View limited data management functions like campus, student, visit, and district data. |
Capabilities:
- Read-only access to campus data
- View student information
- View visit data
- View district information
Clinician & Provider Roles
Paper Biller
| Attribute | Value |
|---|---|
| Hierarchy | 5 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Essentially a data entry person on behalf of a clinician. This user impersonates a clinician and creates visits on the provider’s behalf. |
Capabilities:
- Impersonate clinicians
- Create visits for providers
- Data entry for paper-based documentation
- Support providers who cannot enter visits directly
Paper Process Admin
| Attribute | Value |
|---|---|
| Hierarchy | 4 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Special role created for HISD transportation team leader. For MFCS users ONLY. |
Capabilities:
- Transportation module administration
- Process paper-based transportation logs
- Team leadership functions
Specialized Roles
SMEs (Subject Matter Experts)
| Attribute | Value |
|---|---|
| Hierarchy | 3 |
| State Level Access | No |
| Role Groups | Main |
| Description | Subject matter experts in eSHARS various modules. Allows granting role permissions, running ad-hoc queries, managing broadcast messages, reporting, and complete access to district data functions. |
Capabilities:
- Grant role permissions
- Run ad-hoc database queries
- Manage broadcast messages
- Full reporting access
- Complete district data access
- Module expertise and configuration
Marketing Admin
| Attribute | Value |
|---|---|
| Hierarchy | 7 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Access campus, student, visit, and status info to develop, implement, and execute strategic marketing plans for the organization to attract potential customers and retain existing ones. |
Capabilities:
- Access campus information
- View student data
- View visit statistics
- Marketing analytics and reporting
- Customer retention analysis
Client User
| Attribute | Value |
|---|---|
| Hierarchy | 9 |
| State Level Access | Yes |
| Role Groups | Main |
| Description | Ability to download and delete files which are in ready to process status. The role is more specific to Log Files Management module. |
Capabilities:
- Download processed files
- Delete ready-to-process files
- Log Files Management module access
Internal/System Roles
⚠️ WARNING: These roles are for internal system use only and should NEVER be assigned to client user accounts.
API Imports
| Attribute | Value |
|---|---|
| Hierarchy | 9 |
| State Level Access | Yes |
| Role Groups | Internal |
| Description | INTERNAL ROLE that should NEVER BE LINKED TO ANY CLIENT ACCOUNTS. This role allows for all imports to flow within eSHARS. |
Purpose:
- System integration for automated imports
- API-based data ingestion
- Batch processing operations
API TMHP/DS
| Attribute | Value |
|---|---|
| Hierarchy | 9 |
| State Level Access | Yes |
| Role Groups | Internal |
| Description | INTERNAL ROLE used to support the DS/RS flows and RS FILES. NO ONE SHOULD BE USING THIS ROLE or LINKING IT TO CLIENT ACCOUNTS. |
Purpose:
- TMHP (Texas Medicaid) integration
- DS/RS file processing flows
- Automated billing transactions
Security Areas (Modules)
Permissions within roles are further refined by Security Areas, which represent functional modules in the application:
| Security Area | Description |
|---|---|
| Dashboard | Home page widgets and summary views |
| Students | Student demographic and enrollment management |
| Visits | Visit documentation and management |
| Caseload | Provider-student assignment management |
| EDI | Eligibility and billing transaction management |
| Appeals | Denied visit appeal processing |
| Reports | Reporting and analytics |
| Imports | Batch data import functions |
| Finance | Invoicing, receivables, cost reporting |
| Admin | System configuration and user management |
| Transportation | Special transportation logging |
| Nursing | Nursing-specific documentation |
Permission Types
Within each Security Area, users can have varying levels of access:
| Permission | Description |
|---|---|
| None | No access to the module |
| View | Read-only access |
| Edit | Can modify existing records |
| Create | Can create new records |
| Delete | Can remove records |
| Admin | Full control including configuration |
Role Assignment Guidelines
Typical Role Assignments by User Type
| User Type | Recommended Role(s) |
|---|---|
| System Owner | Global Admin |
| MFCS Support Staff | Super Admin, Admin, Admin Support |
| District IT/Admin | District Admin |
| District Supervisor | District Admin II |
| Clinician/Provider | (Clinician - not shown, implied) |
| Data Entry Clerk | Paper Biller |
| Finance Manager | Finance Module Admin |
| District Finance | Finance Module District User |
| EDI Specialist | EDI Admin |
Best Practices
- Principle of Least Privilege - Assign the minimum role necessary for the user’s job function
- Avoid Internal Roles - Never assign API Imports or API TMHP/DS to human users
- State Level Access - Only grant to users who genuinely need cross-district visibility
- Regular Audits - Periodically review role assignments for appropriateness
- Separation of Duties - Avoid giving single users conflicting permissions
Role Hierarchy Diagram
┌─────────────────────────────────────────────────────────────────────────────┐│ ROLE HIERARCHY │└─────────────────────────────────────────────────────────────────────────────┘
Level 1 ┌──────────────┐ │ Global Admin │ ◄── System Owner (Full Control) └──────┬───────┘ │Level 2 ┌──────┴───────┐ │ Super Admin │ ◄── Full Access, One Step Below Global └──────┬───────┘ │ ┌──────┴───────┬─────────────────┬─────────────────┐Level 3 │ │ │ │ ┌────┴────┐ ┌─────┴─────┐ ┌──────┴──────┐ ┌──────┴──────┐ │EDI Super│ │ EDI Admin │ │ SMEs │ │(Other L3) │ │ Admin │ │ │ │ │ │ │ └─────────┘ └───────────┘ └─────────────┘ └─────────────┘ │ ┌──────┴───────┬─────────────────┬─────────────────┐Level 4 │ │ │ │ ┌────┴────┐ ┌─────┴─────┐ ┌──────┴──────┐ ┌──────┴──────┐ │ Admin │ │Admin │ │ EDI Student │ │Paper Process│ │ │ │Support │ │ Data │ │ Admin │ └─────────┘ └───────────┘ └─────────────┘ └─────────────┘ │Level 5 ┌──────┴───────┐ │ Paper Biller │ ◄── Data Entry on Behalf of Clinicians └──────┬───────┘ │ ┌──────┴───────┬─────────────────┐Level 6 │ │ │ ┌────┴────────┐ ┌─┴───────────────┐ │ │District │ │ District │ │ ┌───────────────────┐ │Admin │ │ Admin II │ └─│Exemption of │ └─────────────┘ └─────────────────┘ │Approval to Release│ └───────────────────┘ │Level 7 ┌──────┴───────┐ │Marketing │ ◄── Marketing Analytics │Admin │ └──────┬───────┘ │Level 8 ┌──────┴───────┬─────────────────┬─────────────────┐ ┌────┴────────┐ ┌─┴───────────────┐ │ ┌───────────────┴───┐ │Finance │ │Finance Module │ │ │Financial │ │Module Admin │ │Support Admin │ └─│Provider │ └─────────────┘ └─────────────────┘ └───────────────────┘ │Level 9 ┌──────┴───────┬─────────────────┐ ┌────┴────────┐ ┌─┴───────────────┐ ┌───────────────────┐ │ API Imports │ │ API TMHP/DS │ │ Client User │ │ (INTERNAL) │ │ (INTERNAL) │ │ │ └─────────────┘ └─────────────────┘ └───────────────────┘Related Documentation
User Guides by Role
- State Admin Guide - For Global Admin, Super Admin (Global Services, system configuration)
- District Admin Guide - For District Admin roles (user management, students, imports)
- Supervisor Guide - For supervisors (approvals, provider oversight)
- Clinician Guide - For providers (visit documentation, caseload)
- Finance Guide - For Finance Module roles (invoicing, receivables)
- EDI Admin Guide - For EDI Admin roles (eligibility, billing transactions)
Documentation generated: January 2026