Skip to main content

Access & Roles

Access Model​

All access to CLIC is governed through AuthPass — OptumRx's centralized identity and access management platform. Secure groups are managed via Active Directory (AD) and the AuthPass platform.

Users log in through two surfaces:

  • Benefit Central — external clients via OHID (One Health ID) SSO
  • Ops Portal — internal users via MSID SSO

Personas​

PersonaSurfaceAudienceCapabilities
ClinicalConsultantBenefit Central + Ops PortalInternalSearch, view, create, update drug intent requests; can act on behalf of clients
ClientBenefit CentralExternalView and create their own drug intent requests
ClinicalCoderOps PortalInternalSearch, view, create, update drug intent requests; coding and validation of Form F data
AdminOps PortalInternalFull administration: client setup, field creation, template creation, client-to-template mapping, environment selection

As of the 9/08 release, Admin also has a Super User variant with elevated administration rights (see Recent & In-Flight Changes below).

Application-Level Authorization​

Beyond AuthPass secure-group membership (which governs who can reach CLIC), the application enforces its own authorization rule on what they can change:

  • Owner-only modification — a Form F / drug intent record can only be edited by the persona that created it (or an assigned Clinical Consultant/Coder acting on a client's behalf)
  • Admin read-only via separate admin API — Admin's client/template/field configuration surface is exposed through a distinct API path from the drug-intent CRUD API, so admin scope cannot be used to bypass owner-only edit rules
  • Auth tokens are short-lived JWT bearer tokens (RFC 6750) with a 15-minute TTL and refresh flow — independent of the 90-day client-credential rotation used for service-to-service AuthPass access

Role-Based Access Matrix​

RoleDEVStageUATPRODAdmin Portal
DeveloperRead/WriteReadNoneNoneNone
QA / TesterRead/WriteRead/WriteRead/WriteNoneNone
Business AnalystReadReadRead/WriteNoneNone
Business User (UAT)NoneNoneRead/WriteNoneNone
ArchitectRead/WriteRead/WriteReadReadRead
DevOpsRead/WriteRead/WriteRead/WriteRead/WriteRead/Write
Read-Only / AuditReadReadNoneReadNone

Secure Groups​

Non-Production UI Access​

Secure GroupPurpose
AZU_RX_PBR_DRUGINTENT_AUTHPASS_ADMINAdmin persona (restricted)
AZU_RX_PBR_DRUGINTENT_AUTHPASS_CLINICALCONSULTANTClinical Consultant (MSID/Internal)
AZU_RX_PBR_DRUGINTENT_AUTHPASS_CLINICALCODERClinical Coder (MSID/Internal)
AZU_RX_PBR_DRUGINTENT_AUTHPASS_DEFAULT_USERSDefault MSID users

Production UI Access​

Secure GroupPurpose
AZU_RX_PBR_CLIC_PROD_AUTHPASS_ADMINAdmin persona (restricted)
AZU_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CONSULTANTClinical Consultant (MSID/Internal)
AZU_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CODERClinical Coder (MSID/Internal)
AZU_RX_PBR_CLIC_PROD_AUTHPASS_DEFAULT_USERSDefault users

Ops Portal Production​

Secure GroupPurpose
AZU_BCOPS_PROD_RX_PBR_CLIC_PROD_AUTHPASS_ADMINAdmin persona
AZU_BCOPS_PROD_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CONSULTANTClinical Consultant
AZU_BCOPS_PROD_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CODERClinical Coder

Repository Access​

Secure GroupPurpose
AZU_ORX_PBM_GITHUB_PBR_RWGitHub repo read access
AZU_ORX_PBM_GITHUB_PBR_MAINTAINERGitHub repo read/write access
AZU_GHEC_USERSGlobal GitHub users for UHG

MongoDB Access​

Secure GroupEnvironmentPurpose
AZU_MONGO_6994c1e5a11568b74408ab62_READNon-ProductionMongoDB read
AZU_MONGO_6994c1e5a11568b74408ab62_CONTRIBUTORNon-ProductionMongoDB read/write (not admin)
AZU_MONGO_6a267fa17305f09d61e66a27_READProductionMongoDB read

Azure Subscription IDs​

EnvironmentSubscription
Non-Production4115081c-1558-4417-be92-29da9b1ea858 (RxPBMDrugIntent Non-Prod)
Production8dbf7bc4-4348-44b7-bc13-e8690d2c4ad5 (rxpbmdrugintent-prod)

How to Request Access​

All access must go through AuthPass onboarding:

  1. Raise access request — navigate to Secure portal; submit request with application name, environment, and access level; select the appropriate secure group from the list above
  2. AuthPass tenant setup — once approved, AuthPass team onboards you to the tenant; you receive: Tenant Name, Environment, Tenant URL, and Secure Group
  3. Generate client credentials — log into the AuthPass Admin Portal at https://authpass.optumrx.com/[tenant_name]; go to Settings → Reset Credentials; copy and store the Client ID and Client Secret (not shown again)

Important notes:

  • Client credentials expire after 90 days; 15-day advance notification is sent
  • Never share credentials — they are tied to your access grant
  • Support: [email protected] or AuthPass Teams channel

Key Contacts​

TeamContact
CLIC Team (all)[email protected]
AuthPass[email protected]
Ops Portal SurfaceDeshmukh, Kavita — [email protected]
FSOTKumar, Praveen; Ranjan, Vibhas; Serey, Tiffanie
RxClient360[email protected]
Benefit CentralCoulombe, Joseph J; Kundu, Sujay
SSMO[email protected]

Recent & In-Flight Access Changes​

Status as of the 15 Sep 2026 CLIC/CAT bi-weekly leads update — this section is the fast-moving part of the access model and should be checked against the latest update before relying on it.

Shipped (9/08 release):

  • Admin role split out a Super User variant with elevated administration rights

In progress, targeting 9/30 release:

  • F1891690 Role Level Security — a broader RBAC rework beyond the current persona-based model
  • Enhanced application access — new secure groups and role-level definitions
  • Deployment of enhanced role-based security to production

Planned (in requirements review/grooming for 10/30 release):

  • F1891715 Client Data Isolation
  • F1891698 Field Level Security

Known gap: Role-Based Testing (validating access behavior across all personas) was reported at 0% — not started as of 15 Sep 2026, out of 312 total test cases (57% overall automation rate). Treat the role/permission behavior documented above as the target design, not yet a fully verified state.