Data governance and security
Before adding any data, confirm local Caldicott / Information Governance approval.
- No identifiable patient data by default
- Anonymised case IDs only
- Organisation-level data separation
- One organisation / customer must never access another organisation's data
- Role-based access control
- Audit logs for creation, editing, export, and deletion
- CSV export restricted to authorised users
- Local Caldicott / IG approval prompts
- GDPR-aware design
Roles and permissions
| Role | Permissions |
|---|---|
| Admin | Full configuration, role assignment, deletion, export. |
| Project lead | Configure project, manage cases, manage standards, export. |
| Reviewer / data collector | Create and edit own case records. |
| Viewer / read-only | Read dashboards and summaries only. |
Note
Role-based access enforcement requires organisational deployment with authentication. The standalone version stores data only in your local browser.