Skip to main content

DoS Sponsor: access, roles and responsibilities

This page explains how to become a DoS Sponsor, which responsibilities the role includes, and how to access the tools required to support user onboarding.

Overview

A Directory of Services (DoS) Sponsor is responsible for managing user access across the systems used to onboard and administer DoS users.

As a DoS Sponsor, you approve user accounts in DoS Admin UI, support identity verification using Apply for Care ID (AfCID) and assign appropriate DoS Positions using Care Identity Management (CIM).

Before you can access CIM or AfCID, your Care Identity (CI) must be configured with the appropriate DoS Sponsor Position by your Registration Authority (RA) Manager, and an Authenticator Assurance Level 3 (AAL3) authenticator configured for your CI.

What this role does in DoS Admin UI

  • Approve new DoS UI user accounts 
  • Add/remove legacy DoS permissions

What this role does in CIM and AfCID

In CIM 

  • Assigns DoS-only Positions to DoS users' CI 
  • Revokes DoS-only Positions when the user's access ends 
  • Confirms DoS Position assignments are correct

In AFCID 

  • Invites DoS users who do not have a CI to begin the process of proving their identity 
What is CIM?

CIM allows NHS and healthcare staff to be registered for a ‘Care Identity’ – a digital identity that can then be associated with health and care organisations they work for.

The system is used to assign and manage permissions that enable appropriate access to clinical systems and patient information. It is also used to assign authentication tokens that allow healthcare professionals to perform multi-factor authentication to these clinical and patient record systems.

Find out more about CIM

What is AfCID?

AfCID is a secure online ID verification service, for NHS staff to submit and verify their documents online. 

Find out more about AfCID


Why this is changing

Why NHS England is making this change

As part of NHS England's commitment to safe, secure digital systems, all national services are expected to use Multi-Factor Authentication (MFA). With MFA now live for DoS, Role-Based Access Control (RBAC) is the next step. Where MFA confirms who a user is, RBAC governs what they can access,  ensuring every user has the right level of access to DoS data, strengthening data governance and keeping DoS aligned with NHS security standards

What this means for current DoS User Administrators

DoS Sponsors are DoS User Administrators (holders of the Legacy DoS 'ApproveUser' permission) who manage user access within their own organisation. The role gives you local control, maintains full audit trails, and prepares your organisation for the future state where DoS user onboarding and lifecycle management moves entirely into AfCID and CIM, eventually retiring user management within the DoS application itself.


Prerequisites to becoming a DoS Sponsor

Before accessing CIM or AfCID, ensure that you have: 

And your local RA manager will have assigned:

  • the appropriate DoS Sponsor Position to your CI
  • an Authenticator Assurance Level 3 (AAL3) authenticator* to your CI
    * The current authenticators are: Windows Hello, smartcard, Security key and iPad app.

Access AfCID

AfCID is a secure online ID verification service for NHS users to submit and verify their documents online. Once a user's identity has been verified, a profile will be created for them in Care Identity Service (CIS).

Access AfCID [opens in new tab]

As a DoS Sponsor, you can: 

  • enter user details to invite them to apply
  • update CI applications you have submitted
  • check the progress of CI applications

Once the applicant has successfully completed the required identity checks, the application will progress through the Registration Authority approval process. After the applicant's identity has been approved: 

  • a CI profile will be created
  • the user's CI will also become available within CIM where DoS access and permissions are managed

For support using AfCID, view the Apply for Care ID guidance.


Access CIM

CIM allows NHS and healthcare staff to be registered for a ‘Care Identity'. A digital identity that can then be associated with health and care organisations they work for.

The system is used to assign and manage permissions that enable appropriate access to clinical systems and patient information. It is also used to assign authentication tokens that allow healthcare professionals to perform multi-factor authentication to these clinical and patient record systems.

Access CIM [opens in new tab]

As a DoS Sponsor, you can:

  • assign DoS-only Positions to DoS users' CI 
  • revoke DoS-only Positions when the user's access ends 
  • confirm DoS Position assignments are correct

If you are unable to access CIM, contact your local Registration Authority team.  

For support using CIM, view the CIM guidance.


New DoS Positions in CIM

As a DoS RA sponsor, you may be able to assign the following DoS position directly to users who have a CI. The new CIM Positions replace the existing (legacy) DoS permissions 

Position name​

What this position allows users to do in the DoS​

Mapped to legacy DoS permissions​

DoS Service Creator​

Create new services in DOS​

addService​

DoS Service Profile Editor​

Edit service demographics, clinical info, endpoints, attributes​

controlService, editDemographics, editServiceAdmin, viewServiceAdmin, editClinical, viewUnlinkedOrg, editAttribute, viewAdminAttribute, editEndpoints, viewClinical​

DoS Service Profile Approver & Publisher​

Approve and publish service profile changes​

approveDemographics, approveClinical, approveAttribute, approveEndpoints, approveControlService, viewClinical​

DoS Service Profile Assurance​

Compare services, run test scenarios, view reports​

compareService, environmentCompare, testScenarios, viewReport​

DoS Temporary Availability Updater​

Update capacity / availability for services​

editCapacity​


Further information

external
external
external
external
external

Last edited: 7 August 2026 4:27 pm