मुख्य कंटेंट तक स्किप करें

Roles & permissions

Create employee records, send login setup links, choose a role bundle and limit day-to-day work by branch.

Who can do this: Owner (Super Admin) with users.manage; restricted-record changes also need patient.update and patient.readRestricted. Where: Admin → Employee Management (/app/employees).

Before you start​

  • Create at least one branch.
  • Keep full name, phone, email and branch ready.
  • For doctors/practitioners, keep qualification, specialization and registration number ready.

Add an employee​

  1. Open Employee Management.
  2. Click Add New Employee.
  3. Fill Full Name and Phone Number.
  4. If the person should login, keep Allow app login for this employee ticked and enter Email Address. Result: On creation, a 72-hour Set Your Password link is emailed.
  5. Select Employee Role and Branch.
  6. For Practitioner, Doctor or Therapist, fill Professional Details: Display Name, Contact Number, Qualification, Specialization, Designation, License / Registration No. and Bio.
  7. Click Create Employee. Result: You see Employee created! A set-password email has been sent. or Employee created without login credentials.

The create screen offers Receptionist, Support Staff (Non-medical), Practitioner, Doctor, Therapist, Accountant, Branch Manager and Super Admin. The backend role catalog treats Therapist as an alias of Practitioner, and Practitioner, Doctor and Therapist behave the same everywhere a clinician is meant (staff pickers such as Treating Doctor, own-bill access, notifications about their own bills and patients, payouts, reports). There is no separate assignable Nurse role in roles.js; choose Practitioner (designation Nurse), Receptionist or a non-login support-staff record based on duties.

Public website listing​

Only clinicians opted in to public visibility appear on the public website, the online booking page and the doctor list shown to patient logins. Doctor and Therapist are listed by role. A Practitioner is listed only when every designation on record — Designation under Professional Details, or the one set in the onboarding wizard — is patient-facing (Doctor, Dentist, Physiotherapist, Occupational Therapist, Speech Therapist, Audiologist, Psychologist, Nutritionist); Nurse, Lab Technician or a free-text designation on either record, or no designation, keeps them private. Signature, seal and registration number are never public.

  • Practitioners invited in the onboarding wizard with a patient-facing designation are listed by default.
  • Create Employee and Edit Employee save the employee as not publicly listed; this screen has no visibility switch today.
  • Designation is owner-only: staff cannot change it from My Profile; set it here (Professional Details) or in the onboarding wizard.
  • Clinicians keep their own medical council registration number and council up to date under My Profile → Professional Details; these print on prescriptions.

See Practitioner.

Edit or deactivate access​

  1. Open Employee Management.
  2. Search by name, email or phone, or filter by role.
  3. Click Edit.
  4. Change phone, role, branch, status or professional details.
  5. To reset a password in edit mode, tick Change User Password and enter New Password and Confirm New Password.
  6. Click Update Employee.
  7. To stop access, click Deactivate on the employee row. Result: Status changes to Inactive and the user cannot use the system.

Choose the right role​

RoleUse it forScope
Owner (Super Admin)Clinic owner / accountable adminTenant-wide across all branches
Admin (legacy)Limited legacy branding/subscription accessTenant-wide across all branches
Branch ManagerBranch operations and cash closingAssigned branch(es)
ReceptionistRegistration, appointments, queue, bills and WhatsApp inboxAssigned branch(es)
Practitioner / DoctorEncounters, Rx, clinical documents and care plansAssigned branch(es)
AccountantFinance dashboards and reconciliationAssigned branch(es)
Staff / Support StaffMinimal or non-login staff recordsAssigned branch(es)

Tenant-wide roles are Super Admin, Admin and Platform Admin. Normal clinic staff roles are branch-scoped.

Working in several workspaces​

A doctor or manager who works for more than one clinic / hospital on this platform uses one login:

  • Signing in with the same e-mail and password in both workspaces links them automatically.
  • Otherwise an administrator of the other workspace creates the employee with the same e-mail and clicks Invite to link login. Open My workspaces from the profile menu and enter the invitation ID and 8-digit code from email.
  • A workspace switcher appears in the header. Your role in each workspace is the one that workspace gave you.
  • An administrator can suspend a person's access to their workspace; it takes effect immediately.

Restricted records permission​

patient.readRestricted lets a user open restricted patient records (VIP, psychiatry, HIV, employee health). Only the Owner (Super Admin) has it by default; practitioners see a restricted patient only when they are assigned to that patient. Every allowed or denied access is audited. A denied read is returned as not found so the system does not reveal the record exists.

Clinical documents also have clinical.document.readRestricted. The generated matrix does not grant it to standard bundles; restricted documents are otherwise visible to the author unless a custom policy grants access.

Permissions matrix​

The following matrix is generated from the backend permission and role catalog on every docs build; do not edit it by hand.

Role summary​

RolePermissionsScope
Owner (Super Admin)68All branches of the workspace
Branch manager29Assigned branch(es)
Receptionist21Assigned branch(es)
Practitioner / Doctor41Assigned branch(es)
Accountant5Assigned branch(es)
Admin (legacy)3All branches of the workspace
Staff1Assigned branch(es)

Patients​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
patient.readView patient list and demographics✅✅✅✅———
patient.createRegister new patients✅✅✅✅———
patient.updateEdit patient demographics and compliance data✅✅✅✅———
patient.deleteDelete (soft-delete) patient records✅——————
patient.mergeMerge / unmerge duplicate patient records✅——————
patient.exportExport patient lists✅——————
patient.readRestrictedOpen patient records flagged as restricted (VIP, psychiatry, HIV, employee health)✅——————
patient.documents.readView and download documents in the patient documents vault✅✅✅✅———
patient.documents.uploadUpload reports, scans and ID proofs to the patient documents vault✅✅✅✅———
patient.documents.deleteDelete (soft-delete) documents from the patient documents vault✅✅—✅———

Front office​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
appointment.readView appointments and calendars✅✅✅✅———
appointment.manageBook, confirm, reschedule, cancel and complete appointments✅✅✅✅———
queue.manageOperate the token / queue desk✅✅✅————

Clinical​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
encounter.readView encounters✅——✅———
encounter.writeOpen and document encounters✅——✅———
vitals.writeRecord vitals✅——✅———
clinical.document.readView clinical documents and reports✅——✅———
clinical.document.createCreate clinical documents✅——✅———
clinical.document.updateEdit draft clinical documents✅——✅———
clinical.document.signSign clinical documents✅——✅———
clinical.document.amendAmend or add addenda to signed documents✅——✅———
clinical.document.voidVoid clinical documents✅——————
clinical.document.shareShare clinical documents with patients / third parties✅——✅———
clinical.document.readRestrictedView documents flagged as restricted (psychiatry, HIV, VIP …)———————
clinical.template.readBrowse clinical templates✅——✅———
clinical.template.manageClone, edit and publish clinical templates✅——————
rx.readView prescriptions✅——✅———
rx.writeWrite prescriptions✅——✅———
careplan.manageAssign and edit care plans / home programmes✅——✅———
package.manageSell and track treatment / session packages✅✅✅✅———
ai.assist.useUse AI dictation, AI drafts, summaries and ICD suggestions (when the workspace enabled AI assist)✅——✅———
careplan.readView care plans / home programmes and care-plan templates✅——✅———
consent.readView patient consent records✅✅✅✅———
consent.captureRecord and withdraw patient / guardian e-consent✅✅✅✅———
immunization.readView vaccination records and the due schedule✅✅✅✅———
immunization.writeRecord vaccinations and send vaccine reminders✅——✅———
teleconsult.conductStart and conduct teleconsultations (NMC Telemedicine Practice Guidelines)✅——✅———

Billing & finance​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
billing.readView bills✅✅✅✅———
billing.createCreate bills and record payments✅✅✅✅———
billing.refundCancel bills, issue credit notes and refunds✅✅—————
finance.readView income, expenses and financial dashboard✅✅——✅——
reports.financialView financial reports✅———✅——
finance.cashClosing.approveApprove or reopen daily counter cash closings✅✅—————
finance.reconcileReconcile UPI / digital payments against bank statements✅✅——✅——
finance.payout.manageEdit practitioner revenue-share (payout) rules✅——————

Administration​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
reports.operationalView visit and practitioner analysis reports✅✅—————
settings.readRead workspace and clinical configuration✅✅✅✅✅✅✅
settings.manageChange workspace and clinical configuration✅——————
users.manageCreate and manage employees✅——————
branches.manageCreate and manage branches / facilities✅——————
services.manageManage the service & price list✅✅—————
feedback.readView patient reviews and feedback✅✅—————
branding.manageManage branding, letterheads and online listings✅————✅—
subscription.manageManage the workspace subscription and platform billing✅————✅—
audit.readView audit logs✅——————
data.exportExport workspace data✅——————
data.importImport patients / services from CSV and roll imports back✅——————
privacy.request.manageHandle DPDP data-principal requests (access, correction, erasure, grievance)✅——————

Communication​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
whatsapp.useUse the WhatsApp inbox✅✅✅————

Workspace​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
dashboard.operationsOperations dashboard✅✅✅—✅——
dashboard.practitionerPractitioner (my patients / my day) dashboard———✅———
letterpad.usePersonal letterpad and professional profile✅——✅———

Platform​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
platform.adminPlatform (cross-tenant) administration———————

lab​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
lab.order.manageCreate and manage pathology lab orders✅✅✅✅———
lab.sample.manageAccession, collect and track lab specimens✅✅✅✅———
lab.result.enterEnter lab results✅——✅———
lab.result.verifyPathologist e-signature: verify results and sign lab reports✅——✅———
lab.testMaster.manageManage the lab test master, reference ranges and panels✅——————

radiology​

PermissionWhat it allowsOwner (Super Admin)Branch managerReceptionistPractitioner / DoctorAccountantAdmin (legacy)Staff
radiology.order.manageCreate and manage radiology orders✅✅✅✅———
radiology.study.manageSchedule and manage radiology studies / worklist✅✅✅✅———
radiology.report.verifyRadiologist e-signature: verify and sign radiology reports✅——✅———

71 permissions in the catalog. ✅ = included in the role bundle, — = not included.

Troubleshooting​

Problem / messageWhat it meansWhat to do
Access denied. Only SUPER_ADMIN can manage employees.Your role cannot manage usersAsk the owner
Enter an email address to create a login for this employee.Login is enabled but email is blankAdd email or untick login
Employee created without login credentials.App login is offUse for non-login staff; edit later if needed
Password has already been set. This link can only be used once.Link was usedUse Forgot Password or admin reset
Restricted patient appears missingCaller lacks restricted accessOwner or assigned practitioner should open it; check audit