Who sees what
This step signs in as Marcus, the practice manager, and opens a payment. He reads every result, reason, deadline and follow-up, and whose each claim is, but cannot import files, record follow-ups or assign work, and the payer’s raw remittance file (835) is withheld: in real use it carries patient names and member IDs. Import is not even in his menu.
That is enforced by the database, not the screen. Each role’s allowed and blocked operations are proven against a real Postgres database, and anyone without a role sees nothing at all.
Before real remittances are loaded, a business associate agreement and hosting under it are required. The design notes in docs/phi-boundary.md say exactly what changes.
A bar stays at the top of every screen so you can come straight back to this step.