DoS Sponsor: access, roles and responsibilities
This page explains how to become a DoS Sponsor, which responsibilities the role includes, and how to access the tools required to support user onboarding.
Overview
A Directory of Services (DoS) Sponsor is responsible for managing user access across the systems used to onboard and administer DoS users.
As a DoS Sponsor, you approve user accounts in DoS Admin UI, support identity verification using Apply for Care ID (AfCID) and assign appropriate DoS Positions using Care Identity Management (CIM).
Before you can access CIM or AfCID, your Care Identity (CI) must be configured with the appropriate DoS Sponsor Position by your Registration Authority (RA) Manager, and an Authenticator Assurance Level 3 (AAL3) authenticator configured for your CI.
What this role does in DoS Admin UI
- Approve new DoS UI user accounts
- Add/remove legacy DoS permissions
What this role does in CIM and AfCID
In CIM
- Assigns DoS-only Positions to DoS users' CI
- Revokes DoS-only Positions when the user's access ends
- Confirms DoS Position assignments are correct
In AFCID
- Invites DoS users who do not have a CI to begin the process of proving their identity
Why this is changing
Why NHS England is making this change
As part of NHS England's commitment to safe, secure digital systems, all national services are expected to use Multi-Factor Authentication (MFA). With MFA now live for DoS, Role-Based Access Control (RBAC) is the next step. Where MFA confirms who a user is, RBAC governs what they can access, ensuring every user has the right level of access to DoS data, strengthening data governance and keeping DoS aligned with NHS security standards
What this means for current DoS User Administrators
DoS Sponsors are DoS User Administrators (holders of the Legacy DoS 'ApproveUser' permission) who manage user access within their own organisation. The role gives you local control, maintains full audit trails, and prepares your organisation for the future state where DoS user onboarding and lifecycle management moves entirely into AfCID and CIM, eventually retiring user management within the DoS application itself.
Prerequisites to becoming a DoS Sponsor
Before accessing CIM or AfCID, ensure that you have:
- completed the National Registration Authority and Smartcard Policy (RAP) training
- shared your RAP completion certificate with your local RA Manager
And your local RA manager will have assigned:
- the appropriate DoS Sponsor Position to your CI
- an Authenticator Assurance Level 3 (AAL3) authenticator* to your CI
* The current authenticators are: Windows Hello, smartcard, Security key and iPad app.
Access AfCID
AfCID is a secure online ID verification service for NHS users to submit and verify their documents online. Once a user's identity has been verified, a profile will be created for them in Care Identity Service (CIS).
Access AfCID [opens in new tab]
As a DoS Sponsor, you can:
- enter user details to invite them to apply
- update CI applications you have submitted
- check the progress of CI applications
Once the applicant has successfully completed the required identity checks, the application will progress through the Registration Authority approval process. After the applicant's identity has been approved:
- a CI profile will be created
- the user's CI will also become available within CIM where DoS access and permissions are managed
For support using AfCID, view the Apply for Care ID guidance.
Access CIM
CIM allows NHS and healthcare staff to be registered for a ‘Care Identity'. A digital identity that can then be associated with health and care organisations they work for.
The system is used to assign and manage permissions that enable appropriate access to clinical systems and patient information. It is also used to assign authentication tokens that allow healthcare professionals to perform multi-factor authentication to these clinical and patient record systems.
Access CIM [opens in new tab]
As a DoS Sponsor, you can:
- assign DoS-only Positions to DoS users' CI
- revoke DoS-only Positions when the user's access ends
- confirm DoS Position assignments are correct
If you are unable to access CIM, contact your local Registration Authority team.
For support using CIM, view the CIM guidance.
New DoS Positions in CIM
As a DoS RA sponsor, you may be able to assign the following DoS position directly to users who have a CI. The new CIM Positions replace the existing (legacy) DoS permissions
|
Position name |
What this position allows users to do in the DoS |
Mapped to legacy DoS permissions |
|---|---|---|
|
DoS Service Creator |
Create new services in DOS |
addService |
|
DoS Service Profile Editor |
Edit service demographics, clinical info, endpoints, attributes |
controlService, editDemographics, editServiceAdmin, viewServiceAdmin, editClinical, viewUnlinkedOrg, editAttribute, viewAdminAttribute, editEndpoints, viewClinical |
|
DoS Service Profile Approver & Publisher |
Approve and publish service profile changes |
approveDemographics, approveClinical, approveAttribute, approveEndpoints, approveControlService, viewClinical |
|
DoS Service Profile Assurance |
Compare services, run test scenarios, view reports |
compareService, environmentCompare, testScenarios, viewReport |
|
DoS Temporary Availability Updater |
Update capacity / availability for services |
editCapacity |
Further information
Information about Care Identity Management and its features
Information about Apply for Care ID and how it supports Care Identity applications
Help and support for Care Identity Management.
Guidance for creating and managing Care Identity applications.
Registration Authority and Smartcard Policy (RAP) training.
Last edited: 7 August 2026 4:27 pm