Back to blog
Compliance7 min read

SDA consent and plan sharing: A provider register checklist

Consent has become more than an onboarding form for SDA providers. NDIS guidance updated in August 2026 explains that participants can give consent for information sharing or for someone to do things on their behalf, and that consent can change over time. In the my NDIS provider portal, provider relationships, plan-sharing permissions and my provider status now sit close to claim readiness. For SDA teams, the practical response is a consent and plan-sharing register that records who authorised what, which portal relationship exists, what evidence the provider can rely on, and what must stay out of owner reporting.

Turn consent into an operating control

NDIS consent guidance distinguishes between sharing information and allowing someone to act on a participant's behalf. It also says participants can choose who they give consent to, what they give consent for, and how long the consent lasts. That makes consent a status that can expire, narrow, expand or be withdrawn, not a one-time intake note.

SDA providers should record consent in the same operational rhythm as plan evidence, service agreements, vacancy intake and claim readiness. Useful fields include participant or nominee, authority source, provider role, support category, plan system, information shared, action authority, start date, review date, expiry date, portal evidence, staff access group and next action.

The register should be practical enough for intake, tenancy, finance and compliance staff to read. Avoid vague states such as consent received. Use specific states such as plan-sharing consent requested, provider relationship active, active goals visible, nominee confirmed, consent expiry pending, participant withdrew consent or owner update restricted.

Separate my provider from plan-sharing permission

A my provider relationship is not the same thing as a broad consent to see every plan detail. NDIS guidance says participants with NDIA-managed or plan-managed funding need to record providers they regularly work with as my providers. It also says my providers must be recorded for specialist disability accommodation, home and living supports, behaviour supports, plan managers, support coordinators and recovery coaches.

For SDA, that relationship matters because claims for those supports can be rejected if the provider is not recorded as a my provider. But a provider relationship still needs to be read alongside consent. NDIS plan-sharing guidance says participants choose which providers can access which parts of their plan, and my providers can see active goals only where consent is given.

Do not use a full plan copy, a support coordinator email or an owner request as a shortcut around the relationship state. The cleaner workflow is to track my provider status, plan-sharing consent, service agreement evidence and claim dates separately. Finance can then see whether a claim is blocked by relationship status, missing plan evidence, a consent gap, a funding-management issue or an internal review hold.

Build the consent register checklist

Use this checklist for new residents, participant transfers, reassessments, plan-manager changes, support coordinator handovers, nominee changes and any vacancy where the provider does not yet have reliable plan visibility.

Confirm the authorised person

Record whether consent came from the participant, nominee, child representative or another authorised contact. If a referrer or family member is helpful but not authorised, record them as a contact, not the consent source.

Map the provider role

Separate SDA provider, plan manager, support coordinator, recovery coach, SIL provider and other support roles. Link the role to the correct support category and portal relationship state.

Capture the exact permission

Record whether the provider can see basic information, active goals, plan and budget details through another role, or only information supplied directly by the participant. Avoid broad labels that do not explain what staff may rely on.

Store source evidence

Attach portal screenshots, consent-form records, participant portal confirmation, call notes, service-hub references, plan-meeting notes or written participant instructions where appropriate.

Set expiry and review triggers

Add review dates for plan reassessment, provider change, nominee change, participant withdrawal, transfer, service exit, support coordinator handover and staff role change.

Restrict owner reporting

Mark what can be shared with owners: vacancy status, claim readiness, income timing or unresolved evidence state. Do not expose plan content, goals, nominee details, support needs or private family context unless an existing permission clearly allows it.

Control nominees, guardians and staff access

NDIS consent guidance says a nominee may give consent on a participant's behalf, and a child representative may make decisions for a participant under 18. Plan-sharing guidance also notes that when a provider is a business with multiple staff, the NDIA needs the contact person at that business that the participant gives consent to.

That creates two separate SDA risks. First, teams can assume the loudest contact is authorised when they are not. Second, a provider can let too many internal users treat plan access as open-ended because the organisation has a portal relationship. The register should show both the external authority chain and the internal role-based access decision.

Review access when staff move roles, contractors leave, an owner asks for more detail, a support provider changes, or a participant changes who can speak for them. A clear consent register helps a provider answer the practical question: who can see this information today, why, and for what SDA workflow?

Connect consent states to vacancies and claims

Consent gaps often look like finance problems. A new resident is ready to move in, but plan evidence is incomplete. A my provider request is waiting in the participant portal. A participant has changed plan manager. A support coordinator can see the plan, but the SDA provider cannot. A nominee is listed, but the owner update would reveal more than the provider should disclose.

Make those blockers explicit before they become old claims or confused owner reports. Claim states can include relationship requested, participant action pending, nominee confirmation pending, plan evidence supplied by participant, consent not required for current action, consent withdrawn, claim hold pending authority check, or claim ready from verified SDA evidence.

This also protects the participant relationship. NDIS guidance on protecting plans tells participants to keep good records, check claims and avoid sharing portal or myGov login details with providers. SDA providers should make the same boundary visible in their process: ask for appropriate consent and evidence, never ask for personal portal credentials, and reconcile claims back to actual supports delivered.

Keep privacy and records audit-ready

The NDIS Commission's Code of Conduct includes respecting the privacy of people with disability. The Practice Standards also require participant information to be identifiable, accurately recorded, current and confidential, with consent obtained for collection, use, retention and disclosure where required.

For SDA providers, this is where the consent register becomes more than a portal checklist. It should connect to service agreements, incident and complaint records, behaviour support boundaries, support-provider handoffs, claim evidence, RRC records, owner reporting and document retention. Each record should show the purpose, source, access, decision and disclosure limit.

The strongest evidence pack is not the largest one. It is the one that shows the provider only collected what it needed, used it for a clear SDA workflow, kept it current, limited staff access, and avoided sending participant-identifying information into commercial owner channels without permission.

How StepFree fits the workflow

StepFree SDA can help providers keep consent, plan visibility, my provider status and claim readiness connected to the operating record. Instead of relying on inbox searches or separate privacy spreadsheets, teams can link consent states to participants, dwellings, vacancies, service agreements, claims, RRC records, owner reporting and internal tasks.

That connected view matters when a claim is blocked, a support coordinator changes, a nominee query arrives, a participant withdraws consent, or an owner asks for an income explanation. Staff can see the permitted action, the evidence source and the privacy boundary before they respond.

Conclusion

SDA providers do not need to turn consent into bureaucracy for its own sake. They do need a live record that separates participant authority, my provider status, plan-sharing permission, nominee details, staff access, claim readiness and owner-safe disclosure. As PACE and the my NDIS provider portal continue to shape daily workflows, a consent and plan-sharing register gives providers a defensible way to move vacancies and claims forward without over-collecting or over-sharing participant information.

StepFree SDA can help providers manage consent registers, my provider checks, plan evidence, claims, RRC records, vacancies and privacy-safe owner reporting in one SDA operations workflow.