Role based permissions / role-based access control RBAC

Who can publish
Who can see what data
Who can create payouts

Permission levels to blind PII and allow team members to get Patient CRM statistics without seeing email address/phone number/name. Just see the total represented in the APP. For example, how many hispanic men in the US living with type 2 diabetes do we have? (figuring out this functionality will be a good test/control for an eventual client portal/permissions.