> For the complete documentation index, see [llms.txt](https://opora.gitbook.io/opora-health-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://opora.gitbook.io/opora-health-documentation/core-features/access-control-and-audit.md).

# Access Control & Audit

This Security feature enforces role-based access control (RBAC) and maintains immutable audit logs for all data interactions within OPORA Core, ensuring traceable, compliant, and justified data use.

The OPORA Access Control & Audit feature provides centralized management of user access rights and data-use accountability across all OPORA Core deployments. It enforces role-based access control (RBAC), ensuring that each user can access only the datasets, modules, and operations permitted by their assigned role (e.g., Data Steward, Researcher, Clinician).

The module continuously records access events through immutable audit logging, capturing the user identity, timestamp, data asset, and access purpose. These logs are automatically validated for integrity and stored within the OPORA Security Layer.

This feature is critical for compliance with the Caldicott Principles, Common Law Duty of Confidentiality, and NHS DSP Toolkit, demonstrating adherence to principles of minimal access, justified use, and traceability.

*Outputs:* structured audit logs (CSV/JSON), automated reports for Data Protection Officers.

*Dependencies:* OPORA-Core Security API, Consent Management Service.

*Status:* Active (v2.3).

#### Components of AI-ready Health Data Audit Trail

<figure><img src="https://1006254083-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlOhtEUn0IGCvXdlPOQkq%2Fuploads%2Faj3h21Rbuu0DmdnkSxIp%2Faudit.jpg?alt=media&amp;token=f5bff887-d5c3-44c7-ab08-b6394585c528" alt=""><figcaption></figcaption></figure>
