Back to blog
Operations7 min read

NDIS provider portal access: A myID and RAM checklist for SDA teams

For SDA providers, government portal access is no longer a background admin detail. The NDIA moved provider portal access to myID and Relationship Authorisation Manager (RAM), with PRODA access discontinued after 10 November 2025. The NDIS Commission is also moving its portals to myID and RAM, with the transition period scheduled to end on 30 September 2026. That makes identity setup, delegated access and backup coverage a practical continuity issue for teams managing dwelling enrolments, claim enquiries, registration records, worker screening and reportable incidents.

What changed for provider access

The NDIA says providers and employees accessing NDIS systems need myID and RAM. The current provider portal guidance says each employee who uses the portals needs their own Digital ID with myID, and the organisation's principal authority needs to link the business in RAM before authorising others.

The NDIS Commission transition is separate. Its guidance says providers, quality auditors and government agencies can now use myID and RAM for NDIS Commission portals, with the transition period scheduled to end on 30 September 2026. The Commission also makes clear that this change does not replace NDIS worker screening checks.

The operational point is simple: do not treat portal access as one finance login. In SDA, access controls decide who can enrol or modify dwellings, submit claim and payment enquiries, download reports, view participant information, manage registration tasks and lodge urgent regulatory notifications.

Separate NDIA portals from Commission portals

SDA providers should keep a clear map of which portal does which job. NDIS guidance says the my NDIS provider portal is used for participants on the new computer system, while myplace is used for participants on the old computer system. It also says all SDA dwelling enrolments and claim or payment enquiries are handled through the my NDIS provider portal, while claims and payment requests are submitted through myplace.

Commission portals support a different risk profile. Registered providers use the Commission portal to manage registration. Commission guidance for reportable incidents says registered providers use the Registered Provider portal to submit required incident notifications. Worker screening guidance also points registered providers to the portal for worker screening database access, worker linking and employer ID tasks.

That split matters because the people who need access are not always the same. Finance may need claim status and payment request access. Operations may need dwelling enrolment and participant relationship visibility. Compliance may need registration, worker screening and incident-notification access. Executives may need principal authority or authorisation administrator coverage.

A practical myID and RAM checklist

Use this checklist before the next access problem becomes a claim delay, registration blocker or incident-reporting scramble.

Confirm the principal authority

Identify the director, owner or other principal authority who can link the business in RAM. Record who has completed the link, which ABN was linked, and who can act if that person is unavailable.

Set identity strength early

Check whether each portal user has the required myID identity strength. RAM guidance says principal authorities need Strong identity strength to link a business online, while authorised users generally need at least Standard identity strength to act on behalf of a business.

Authorise by operating role

Create RAM authorisations that match real duties: SDA enrolments, claim and payment enquiries, finance uploads, registration management, worker screening, incident notifications, executive oversight and audit support.

Keep backup coverage

Avoid single-person access for time-sensitive workflows. At minimum, nominate backup users for claim enquiries, dwelling enrolment actions, registration renewal tasks, worker screening checks and reportable incident lodgement.

Test the actual workflows

Do not stop at a successful login. Test whether each authorised user can reach the right organisation, switch providers where needed, see expected portal functions and complete a low-risk task or training walkthrough.

Review leavers and contractors

Build RAM and portal access into onboarding, role changes and offboarding. Remove access when staff leave, when contractors finish, when a finance user changes role or when an external consultant no longer needs delegated authority.

Protect participant data while widening access

Portal access is also a privacy control. NDIS provider portal guidance lists functions such as viewing participant details, seeing plan and budget information where consent exists, downloading reports and extracting key participant information in Excel. That is sensitive SDA operating data, not a general admin convenience.

Each authorisation should have a purpose. A user who only manages worker screening should not automatically receive participant claim exports. A user who handles owner reporting should not need unrestricted access to plan, incident or health information. A consultant helping with an audit should have an end date and a defined evidence scope.

Keep a simple access register that records name, role, portal, organisation, permission purpose, approval date, review date, offboarding date and whether the user can export participant data. Review it at least quarterly and after any incident, data breach, key-personnel change or provider-ownership change.

Build access into time-critical controls

The most expensive access problem is the one discovered under time pressure. A claim enquiry may be waiting on a portal upload. A dwelling enrolment request may need action before a move-in. A worker screening expiry may block a roster. A registration change may need Commission visibility. A reportable incident may need notification within the required timeframe.

SDA teams should connect portal access to their operating calendar. Include access checks in monthly claim close, dwelling onboarding, staff onboarding, registration renewal, worker screening review, incident drills and disaster recovery testing. If the provider runs after-hours supported accommodation, decide who can lodge or support urgent Commission tasks outside ordinary office hours.

Keep alternative evidence paths clear. If a portal task cannot be completed immediately, the provider still needs dated notes, screenshots where appropriate, request numbers, email records, internal approvals and a named owner for follow-up. Access controls should create accountability, not hide operational blockers.

How StepFree fits the workflow

StepFree SDA should not replace the official NDIS or NDIS Commission portals. The useful role is to keep the surrounding operating record clean: which dwelling enrolment is waiting on portal action, which claim enquiry has an owner, which participant relationship is blocking a claim, which worker screening task is due, and which incident or registration action needs evidence.

The same structure supports owner-safe reporting. Owners need accurate status on vacancy, onboarding, claim readiness, submitted claims, payment exceptions and compliance delays. They do not need raw participant portal exports or unrestricted participant-identifying information.

Conclusion

SDA providers should treat myID and RAM as part of their claims, compliance and continuity controls. The practical test is whether the right people can access the right portal, for the right purpose, with backup coverage, evidence trails and privacy boundaries in place before a claim run, enrolment request, worker-screening task or incident notification becomes urgent.

StepFree SDA can help providers track portal-dependent claims, dwelling enrolments, worker screening actions, registration tasks, incidents, access-sensitive exceptions and owner-safe status reporting in one SDA operations workflow.