Access & Roles
Access Model
All access to CLIC is governed through AuthPass — OptumRx's centralized identity and access management platform. Secure groups are managed via Active Directory (AD) and the AuthPass platform.
Users log in through two surfaces:
- Benefit Central — external clients via OHID (One Health ID) SSO
- Ops Portal — internal users via MSID SSO
Personas
| Persona | Surface | Audience | Capabilities |
|---|---|---|---|
| ClinicalConsultant | Benefit Central + Ops Portal | Internal | Search, view, create, update drug intent requests; can act on behalf of clients |
| Client | Benefit Central | External | View and create their own drug intent requests |
| ClinicalCoder | Ops Portal | Internal | Search, view, create, update drug intent requests; coding and validation of Form F data |
| Admin | Ops Portal | Internal | Full administration: client setup, field creation, template creation, client-to-template mapping, environment selection |
As of the 9/08 release, Admin also has a Super User variant with elevated administration rights (see Recent & In-Flight Changes below).
Application-Level Authorization
Beyond AuthPass secure-group membership (which governs who can reach CLIC), the application enforces its own authorization rule on what they can change:
- Owner-only modification — a Form F / drug intent record can only be edited by the persona that created it (or an assigned Clinical Consultant/Coder acting on a client's behalf)
- Admin read-only via separate admin API — Admin's client/template/field configuration surface is exposed through a distinct API path from the drug-intent CRUD API, so admin scope cannot be used to bypass owner-only edit rules
- Auth tokens are short-lived JWT bearer tokens (RFC 6750) with a 15-minute TTL and refresh flow — independent of the 90-day client-credential rotation used for service-to-service AuthPass access
Role-Based Access Matrix
| Role | DEV | Stage | UAT | PROD | Admin Portal |
|---|---|---|---|---|---|
| Developer | Read/Write | Read | None | None | None |
| QA / Tester | Read/Write | Read/Write | Read/Write | None | None |
| Business Analyst | Read | Read | Read/Write | None | None |
| Business User (UAT) | None | None | Read/Write | None | None |
| Architect | Read/Write | Read/Write | Read | Read | Read |
| DevOps | Read/Write | Read/Write | Read/Write | Read/Write | Read/Write |
| Read-Only / Audit | Read | Read | None | Read | None |
Secure Groups
Non-Production UI Access
| Secure Group | Purpose |
|---|---|
AZU_RX_PBR_DRUGINTENT_AUTHPASS_ADMIN | Admin persona (restricted) |
AZU_RX_PBR_DRUGINTENT_AUTHPASS_CLINICALCONSULTANT | Clinical Consultant (MSID/Internal) |
AZU_RX_PBR_DRUGINTENT_AUTHPASS_CLINICALCODER | Clinical Coder (MSID/Internal) |
AZU_RX_PBR_DRUGINTENT_AUTHPASS_DEFAULT_USERS | Default MSID users |
Production UI Access
| Secure Group | Purpose |
|---|---|
AZU_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN | Admin persona (restricted) |
AZU_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CONSULTANT | Clinical Consultant (MSID/Internal) |
AZU_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CODER | Clinical Coder (MSID/Internal) |
AZU_RX_PBR_CLIC_PROD_AUTHPASS_DEFAULT_USERS | Default users |
Ops Portal Production
| Secure Group | Purpose |
|---|---|
AZU_BCOPS_PROD_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN | Admin persona |
AZU_BCOPS_PROD_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CONSULTANT | Clinical Consultant |
AZU_BCOPS_PROD_RX_PBR_CLIC_PROD_AUTHPASS_ADMIN_CODER | Clinical Coder |
Repository Access
| Secure Group | Purpose |
|---|---|
AZU_ORX_PBM_GITHUB_PBR_RW | GitHub repo read access |
AZU_ORX_PBM_GITHUB_PBR_MAINTAINER | GitHub repo read/write access |
AZU_GHEC_USERS | Global GitHub users for UHG |
MongoDB Access
| Secure Group | Environment | Purpose |
|---|---|---|
AZU_MONGO_6994c1e5a11568b74408ab62_READ | Non-Production | MongoDB read |
AZU_MONGO_6994c1e5a11568b74408ab62_CONTRIBUTOR | Non-Production | MongoDB read/write (not admin) |
AZU_MONGO_6a267fa17305f09d61e66a27_READ | Production | MongoDB read |
Azure Subscription IDs
| Environment | Subscription |
|---|---|
| Non-Production | 4115081c-1558-4417-be92-29da9b1ea858 (RxPBMDrugIntent Non-Prod) |
| Production | 8dbf7bc4-4348-44b7-bc13-e8690d2c4ad5 (rxpbmdrugintent-prod) |
How to Request Access
All access must go through AuthPass onboarding:
- Raise access request — navigate to Secure portal; submit request with application name, environment, and access level; select the appropriate secure group from the list above
- AuthPass tenant setup — once approved, AuthPass team onboards you to the tenant; you receive: Tenant Name, Environment, Tenant URL, and Secure Group
- Generate client credentials — log into the AuthPass Admin Portal at
https://authpass.optumrx.com/[tenant_name]; go to Settings → Reset Credentials; copy and store the Client ID and Client Secret (not shown again)
Important notes:
- Client credentials expire after 90 days; 15-day advance notification is sent
- Never share credentials — they are tied to your access grant
- Support: [email protected] or AuthPass Teams channel
Key Contacts
| Team | Contact |
|---|---|
| CLIC Team (all) | [email protected] |
| AuthPass | [email protected] |
| Ops Portal Surface | Deshmukh, Kavita — [email protected] |
| FSOT | Kumar, Praveen; Ranjan, Vibhas; Serey, Tiffanie |
| RxClient360 | [email protected] |
| Benefit Central | Coulombe, Joseph J; Kundu, Sujay |
| SSMO | [email protected] |
Recent & In-Flight Access Changes
Status as of the 15 Sep 2026 CLIC/CAT bi-weekly leads update — this section is the fast-moving part of the access model and should be checked against the latest update before relying on it.
Shipped (9/08 release):
- Admin role split out a Super User variant with elevated administration rights
In progress, targeting 9/30 release:
F1891690Role Level Security — a broader RBAC rework beyond the current persona-based model- Enhanced application access — new secure groups and role-level definitions
- Deployment of enhanced role-based security to production
Planned (in requirements review/grooming for 10/30 release):
F1891715Client Data IsolationF1891698Field Level Security
Known gap: Role-Based Testing (validating access behavior across all personas) was reported at 0% — not started as of 15 Sep 2026, out of 312 total test cases (57% overall automation rate). Treat the role/permission behavior documented above as the target design, not yet a fully verified state.