Role-Based Access Control

Who sees and does what. Especially with AI.

Legacy PACS was built when access control meant 'can this person log in.' Sirona sets granular permissions by organization, clinic, and facility, with radiologists scoped to their sites, from one admin interface.

See Sirona in Action

How Sirona is Different

AI changes everything about access control

When AI models read studies, generate findings, and pre-populate reports, the question of 'who has access' expands dramatically. Who can enable a new AI algorithm? Who can see AI-generated findings before a radiologist reviews them? Who can modify AI configuration parameters? Who can access AI performance analytics? Legacy PACS has no concept of these permissions because it was built before AI existed in the workflow. Sirona is extending its role model with AI-specific permission layers: model deployment, output visibility, configuration access, and an audit trail for every AI action. In the age of AI, RBAC isn't just about data access. It's about algorithmic governance.

Access control at every layer

Granular permissions and durable audit logs, enforced across every module and every site.

Single Sign-On

Single sign-on is available through our identity-provider integration, configured per organization during onboarding. Users authenticate once through your existing identity provider.

Granular Role Definitions

Roles bundle granular permissions for study access, report editing, worklist management, and administrative functions, so each person gets the access their job needs and nothing more.

Facility-Level Scoping

Scope a role to the whole organization, a clinic, or a single facility. A radiologist at Site A sees only Site A studies. An admin manages only their assigned locations.

AI-Specific Permissions (Coming Soon)

Designed to control who can deploy AI models, view AI-generated findings, modify algorithm configurations, and access AI performance analytics. A new permission layer for a new era.

Audit Logs

Changes to clinical information — patient and order updates and study lifecycle events — are logged to durable, access-controlled storage that supports HIPAA audit requirements.

Governance that keeps pace with the platform

AI Governance (Coming Soon)

Permissions for the AI era

As AI becomes a bigger part of the workflow, governing who can enable and configure it is where Sirona is extending its role model. The same organization, clinic, and facility scopes will decide who can turn an algorithm on, who sees its output before a radiologist does, and who can change how it runs.

AI model deployment permissions: control who can enable or disable algorithms

AI output visibility: restrict pre-review findings to authorized roles

AI configuration access: limit who can modify model parameters

AI audit trail: every model interaction logged with user, timestamp, and action

Identity

One identity, enforced everywhere

Single sign-on is available through our identity-provider integration, configured per organization during onboarding. Users authenticate once through your existing identity provider, and one Sirona identity carries the same role into the viewer, the reporter, the worklist, and administration. Roles are defined and managed directly in Sirona.

Single sign-on, configured per organization during onboarding

One Sirona identity across viewer, reporter, worklist, and admin

Roles defined and managed in Sirona

Multi-Site

Permissions that match your organizational complexity

A multi-site practice needs radiologists scoped to specific facilities, technologists with worklist access but no report editing, and administrators with configuration rights but no clinical access. Sirona's role model supports all of these at once, with facility-level scoping and functional permission sets in a single system. No per-site instances, no separate permission databases, no inconsistent access policies across locations.

Facility-scoped roles — restrict access by clinic or facility

Functional permissions — separate study viewing, report editing, and configuration

Consistent enforcement across all sites from a single admin interface

Compliance

Audit evidence from normal operation

Changes to clinical information in Sirona — patient and order updates and study lifecycle events — generate a durable audit record in access-controlled storage that supports HIPAA audit requirements. Access itself is governed by one role model rather than a separate permission database per site, so when your compliance team needs to show who can do what, there is one place to look. Beyond the audit trail, Sirona captures detailed application event data, including session replays of how the application was used. We are making more of that data available through the Dashboard, and over time through the SDK and APIs.

Audit logs of changes to clinical information

Durable, access-controlled log storage

One role model to evidence, not one per site

An active SOC 2 Type II program — attestation available under NDA

Access control that scales

3

scopes for every role: organization, clinic, and facility

All sites

covered by facility-scoped roles

Active

SOC 2 Type II program — attestation available under NDA

1

administrative interface for every site and every role

Security and governance built in

Everlight RadiologyRead the partnership announcement

“Through Sirona's platform, Everlight will be able to build and deploy AI-powered automations across clinical, administrative, and operational workflows. This partnership will fundamentally transform how our radiologists practice, and position Everlight at the forefront of AI-enabled diagnostic medicine globally.”

Jeff Oakman

Global Chief Operating Officer, Everlight Radiology

Built Different: the architecture behind RadOS

Sirona's technical advisor Jeff Queisser (Co-Founder of Box, NYSE: BOX) on how RadOS was architected for reliability and performance at scale.

FAQs