Consider this scenario:
A user who is a patient will login to web portal. In the web portal he got appointments, lab reports etc.
I want to make the user, only view their appointments and lab reports.
How do I achieve that? How should I set permissions and roles?