
Role-Based Access Control
Who sees and does what. Especially with AI.
Legacy PACS was built when access control meant 'can this person log in.' Sirona sets granular permissions by organization, clinic, and facility, with radiologists scoped to their sites, from one admin interface.
How Sirona is Different
AI changes everything about access control
When AI models read studies, generate findings, and pre-populate reports, the question of 'who has access' expands dramatically. Who can enable a new AI algorithm? Who can see AI-generated findings before a radiologist reviews them? Who can modify AI configuration parameters? Who can access AI performance analytics? Legacy PACS has no concept of these permissions because it was built before AI existed in the workflow. Sirona is extending its role model with AI-specific permission layers: model deployment, output visibility, configuration access, and an audit trail for every AI action. In the age of AI, RBAC isn't just about data access. It's about algorithmic governance.
Access control at every layer
Granular permissions and durable audit logs, enforced across every module and every site.
Single Sign-On
Single sign-on is available through our identity-provider integration, configured per organization during onboarding. Users authenticate once through your existing identity provider.
Granular Role Definitions
Roles bundle granular permissions for study access, report editing, worklist management, and administrative functions, so each person gets the access their job needs and nothing more.
Facility-Level Scoping
Scope a role to the whole organization, a clinic, or a single facility. A radiologist at Site A sees only Site A studies. An admin manages only their assigned locations.
AI-Specific Permissions (Coming Soon)
Designed to control who can deploy AI models, view AI-generated findings, modify algorithm configurations, and access AI performance analytics. A new permission layer for a new era.
Audit Logs
Changes to clinical information — patient and order updates and study lifecycle events — are logged to durable, access-controlled storage that supports HIPAA audit requirements.
Governance that keeps pace with the platform
AI Governance (Coming Soon)
Permissions for the AI era
As AI becomes a bigger part of the workflow, governing who can enable and configure it is where Sirona is extending its role model. The same organization, clinic, and facility scopes will decide who can turn an algorithm on, who sees its output before a radiologist does, and who can change how it runs.
AI model deployment permissions: control who can enable or disable algorithms
AI output visibility: restrict pre-review findings to authorized roles
AI configuration access: limit who can modify model parameters
AI audit trail: every model interaction logged with user, timestamp, and action
Identity
One identity, enforced everywhere
Single sign-on is available through our identity-provider integration, configured per organization during onboarding. Users authenticate once through your existing identity provider, and one Sirona identity carries the same role into the viewer, the reporter, the worklist, and administration. Roles are defined and managed directly in Sirona.
Single sign-on, configured per organization during onboarding
One Sirona identity across viewer, reporter, worklist, and admin
Roles defined and managed in Sirona
Multi-Site
Permissions that match your organizational complexity
A multi-site practice needs radiologists scoped to specific facilities, technologists with worklist access but no report editing, and administrators with configuration rights but no clinical access. Sirona's role model supports all of these at once, with facility-level scoping and functional permission sets in a single system. No per-site instances, no separate permission databases, no inconsistent access policies across locations.
Facility-scoped roles — restrict access by clinic or facility
Functional permissions — separate study viewing, report editing, and configuration
Consistent enforcement across all sites from a single admin interface
Compliance
Audit evidence from normal operation
Changes to clinical information in Sirona — patient and order updates and study lifecycle events — generate a durable audit record in access-controlled storage that supports HIPAA audit requirements. Access itself is governed by one role model rather than a separate permission database per site, so when your compliance team needs to show who can do what, there is one place to look. Beyond the audit trail, Sirona captures detailed application event data, including session replays of how the application was used. We are making more of that data available through the Dashboard, and over time through the SDK and APIs.
Audit logs of changes to clinical information
Durable, access-controlled log storage
One role model to evidence, not one per site
An active SOC 2 Type II program — attestation available under NDA
Access control that scales
3
scopes for every role: organization, clinic, and facility
All sites
covered by facility-scoped roles
Active
SOC 2 Type II program — attestation available under NDA
1
administrative interface for every site and every role
Security and governance built in
“Through Sirona's platform, Everlight will be able to build and deploy AI-powered automations across clinical, administrative, and operational workflows. This partnership will fundamentally transform how our radiologists practice, and position Everlight at the forefront of AI-enabled diagnostic medicine globally.”
Jeff Oakman
Global Chief Operating Officer, Everlight Radiology
Built Different: the architecture behind RadOS
Sirona's technical advisor Jeff Queisser (Co-Founder of Box, NYSE: BOX) on how RadOS was architected for reliability and performance at scale.
FAQs
Does Sirona support single sign-on?
Can roles sync from our directory?
What AI-specific permissions will Sirona support?
Can I restrict access by facility or site?
How does Sirona handle audit logs for compliance?
What is Sirona's compliance posture?
How does RBAC differ from legacy PACS access control?