Overview
Akhara uses a hierarchical permission model where access is controlled at two levels:- Organization Level: Global settings, billing, user management, and cross-project visibility
- Project Level: Datasets, evaluations, reviews, and project-specific configurations
Permission Hierarchy
Organization Permissions
Organization Settings
*Members can create projects if enabled in org settings
User Management
Project Permissions
Project Configuration
Data & Evaluation Access
*Requires explicit PHI access grant
Review Queue Access
*Within credentialed scope only
Managing Access
Invite Users to Organization
Add Users to Projects
Bulk Permission Updates
Project Visibility
Control which projects users can see:Visibility Modes
PHI Access Control
PHI access is controlled separately from general permissions:Grant PHI Access
PHI Access Policies
Team Management
Create Teams
Organize users into teams for easier permission management:Team Permissions
When a team is added to a project, all team members inherit the assigned role. Individual overrides can be applied:Access Requests
Enable self-service access requests for governed onboarding:Best Practices
Least Privilege
Start with Viewer role and escalate only as needed
Use Teams
Group users by function for easier management
Regular Reviews
Audit project membership quarterly
PHI Minimization
Only grant PHI access with documented justification
Related
Role-Based Access Control
Detailed role definitions and permission matrix
Audit Logs
Track all permission changes and access events