PointClickCare User Roles: Design by Job Function, Not Request

Most PointClickCare access problems start the same way. A nurse manager asks for "the same access as Sarah," an administrator approves it, and six months later nobody can say why twenty people have slightly different permissions. Multiply that by turnover, agency staff and promotions, and you have an access model nobody understands.

The fix is to design roles around what people do, not around who asked. This post walks through a practical way to do that, in general terms that apply whatever your current configuration looks like.

Why individual requests fail

When access is granted one request at a time, three things happen:

Permission creep. People change jobs and keep old access because nobody removes it.

Inconsistent staffing coverage. The weekend charge nurse can do less than the weekday charge nurse, and no one knows why.

Audit pain. HIPAA's Security Rule expects access to be limited to the minimum necessary for a person's job. If you cannot explain why someone has a permission, you cannot show you meant to grant it.

Start with a job function inventory

Before touching any settings, list the distinct jobs in your building or company. A typical skilled nursing or senior-living operator might have:

Direct care staff such as CNAs and medication aides

Licensed nurses (LPN and RN) on the floor

Unit managers and the Director of Nursing

MDS and care plan coordinators

Admissions and business office staff

Medical records

Activities and social services

Administrator and corporate reviewers

Therapy and outside clinicians

For each job, write one sentence describing what they need the system to do. "Document care and view the residents on their assigned hall" is a good sentence. "Whatever they need" is not.

Build a role matrix

Take your job list and, on a single page, mark what each job needs to view, enter, edit or approve. Keep it in plain language first, such as "can see all residents in the building" or "can enter progress notes but not edit billing." Then have your PointClickCare administrator map those statements to the actual roles and permission options in your configuration. Do not guess at option names; confirm them against what your system offers.

Aim for a small number of roles. If you end up with forty, you have rebuilt the individual-request problem with nicer labels. A good test: could a new hire in a given job be set up by picking one role, with no exceptions?

Handle exceptions deliberately

Some people really do need something extra, such as a nurse who also covers medical records. Handle that by assigning a second role or by documenting a named exception with an owner and a review date. Do not quietly edit the base role to fit one person.

Separate admin access

People who can manage users and settings should have that ability in a distinct, tightly limited role. Keep the number small and review it often.

Put an approval process around changes

A role model only works if it is the only door in. Set up a simple access request form that asks for the person's name, job title, start date and the role they need. The supervisor approves the job title, and the system administrator assigns the matching role. Requests that do not fit a role go to a short review by the administrator or compliance lead.

Tie the process to HR events:

New hire: role assigned from the job title on the start date, not before.

Transfer or promotion: old role removed when the new one is added.

Termination: access disabled the same day, ideally automated from the HR notice.

Review on a schedule

At least twice a year, have each department head review a list of the people in their area and the role each holds. They only need to answer one question: is this still right? Remove anything they do not recognize. Keep the signed-off lists as evidence for your security risk analysis.

For multi-facility operators, use the same role names and definitions everywhere. It makes floating staff, corporate support and audits far easier, and it lets you compare buildings for outliers.

A starting point for your team

If you are cleaning up an existing system, do not try to redesign everything at once. Pick one department, such as nursing, define its roles, move people onto them, and then repeat for the next. Document what you decided and why, because the reasoning will matter the next time someone asks for an exception.

UnityCare IT works with long-term care operators on exactly this kind of access cleanup, from drafting the role matrix with your DON and administrator to setting up the onboarding and offboarding steps that keep it accurate.

Related service

Keeping PointClickCare and other EHR systems fast, connected and available.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172