Create employee records, send login setup links, choose a role bundle and limit day-to-day work by branch.
Who can do this: Owner (Super Admin) with users.manage; restricted-record changes also need patient.update and patient.readRestricted.
Where: Admin → Employee Management (/app/employees).
Before you start
- Create at least one branch.
- Keep full name, phone, email and branch ready.
- For doctors/practitioners, keep qualification, specialization and registration number ready.
Add an employee
- Open Employee Management.
- Click Add New Employee.
- Fill Full Name and Phone Number.
- If the person should login, keep Allow app login for this employee ticked and enter Email Address.
Result: On creation, a 72-hour Set Your Password link is emailed.
- Select Employee Role and Branch.
- For Practitioner, Doctor or Therapist, fill Professional Details: Display Name, Contact Number, Qualification, Specialization, Designation, License / Registration No. and Bio.
- Click Create Employee.
Result: You see Employee created! A set-password email has been sent. or Employee created without login credentials.
The create screen offers Receptionist, Support Staff (Non-medical), Practitioner, Doctor, Therapist, Accountant, Branch Manager and Super Admin. The backend role catalog treats Therapist as an alias of Practitioner, and Practitioner, Doctor and Therapist behave the same everywhere a clinician is meant (staff pickers such as Treating Doctor, own-bill access, notifications about their own bills and patients, payouts, reports). There is no separate assignable Nurse role in roles.js; choose Practitioner (designation Nurse), Receptionist or a non-login support-staff record based on duties.
Public website listing
Only clinicians opted in to public visibility appear on the public website, the online booking page and the doctor list shown to patient logins. Doctor and Therapist are listed by role. A Practitioner is listed only when every designation on record — Designation under Professional Details, or the one set in the onboarding wizard — is patient-facing (Doctor, Dentist, Physiotherapist, Occupational Therapist, Speech Therapist, Audiologist, Psychologist, Nutritionist); Nurse, Lab Technician or a free-text designation on either record, or no designation, keeps them private. Signature, seal and registration number are never public.
- Practitioners invited in the onboarding wizard with a patient-facing designation are listed by default.
- Create Employee and Edit Employee save the employee as not publicly listed; this screen has no visibility switch today.
- Designation is owner-only: staff cannot change it from My Profile; set it here (Professional Details) or in the onboarding wizard.
- Clinicians keep their own medical council registration number and council up to date under My Profile → Professional Details; these print on prescriptions.
See Practitioner.
Edit or deactivate access
- Open Employee Management.
- Search by name, email or phone, or filter by role.
- Click Edit.
- Change phone, role, branch, status or professional details.
- To reset a password in edit mode, tick Change User Password and enter New Password and Confirm New Password.
- Click Update Employee.
- To stop access, click Deactivate on the employee row.
Result: Status changes to Inactive and the user cannot use the system.
Choose the right role
| Role | Use it for | Scope |
|---|
| Owner (Super Admin) | Clinic owner / accountable admin | Tenant-wide across all branches |
| Admin (legacy) | Limited legacy branding/subscription access | Tenant-wide across all branches |
| Branch Manager | Branch operations and cash closing | Assigned branch(es) |
| Receptionist | Registration, appointments, queue, bills and WhatsApp inbox | Assigned branch(es) |
| Practitioner / Doctor | Encounters, Rx, clinical documents and care plans | Assigned branch(es) |
| Accountant | Finance dashboards and reconciliation | Assigned branch(es) |
| Staff / Support Staff | Minimal or non-login staff records | Assigned branch(es) |
Tenant-wide roles are Super Admin, Admin and Platform Admin. Normal clinic staff roles are branch-scoped.
Working in several workspaces
A doctor or manager who works for more than one clinic / hospital on this platform uses one login:
- Signing in with the same e-mail and password in both workspaces links them automatically.
- Otherwise an administrator of the other workspace creates the employee with the same e-mail and clicks Invite to link login. Open My workspaces from the profile menu and enter the invitation ID and 8-digit code from email.
- A workspace switcher appears in the header. Your role in each workspace is the one that workspace gave you.
- An administrator can suspend a person's access to their workspace; it takes effect immediately.
Restricted records permission
patient.readRestricted lets a user open restricted patient records (VIP, psychiatry, HIV, employee health). Only the Owner (Super Admin) has it by default; practitioners see a restricted patient only when they are assigned to that patient. Every allowed or denied access is audited. A denied read is returned as not found so the system does not reveal the record exists.
Clinical documents also have clinical.document.readRestricted. The generated matrix does not grant it to standard bundles; restricted documents are otherwise visible to the author unless a custom policy grants access.
Permissions matrix
The following matrix is generated from the backend permission and role catalog on every docs build; do not edit it by hand.
Role summary
| Role | Permissions | Scope |
|---|
| Owner (Super Admin) | 68 | All branches of the workspace |
| Branch manager | 29 | Assigned branch(es) |
| Receptionist | 21 | Assigned branch(es) |
| Practitioner / Doctor | 41 | Assigned branch(es) |
| Accountant | 5 | Assigned branch(es) |
| Admin (legacy) | 3 | All branches of the workspace |
| Staff | 1 | Assigned branch(es) |
Patients
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
patient.read | View patient list and demographics | ✅ | ✅ | ✅ | ✅ | — | — | — |
patient.create | Register new patients | ✅ | ✅ | ✅ | ✅ | — | — | — |
patient.update | Edit patient demographics and compliance data | ✅ | ✅ | ✅ | ✅ | — | — | — |
patient.delete | Delete (soft-delete) patient records | ✅ | — | — | — | — | — | — |
patient.merge | Merge / unmerge duplicate patient records | ✅ | — | — | — | — | — | — |
patient.export | Export patient lists | ✅ | — | — | — | — | — | — |
patient.readRestricted | Open patient records flagged as restricted (VIP, psychiatry, HIV, employee health) | ✅ | — | — | — | — | — | — |
patient.documents.read | View and download documents in the patient documents vault | ✅ | ✅ | ✅ | ✅ | — | — | — |
patient.documents.upload | Upload reports, scans and ID proofs to the patient documents vault | ✅ | ✅ | ✅ | ✅ | — | — | — |
patient.documents.delete | Delete (soft-delete) documents from the patient documents vault | ✅ | ✅ | — | ✅ | — | — | — |
Front office
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
appointment.read | View appointments and calendars | ✅ | ✅ | ✅ | ✅ | — | — | — |
appointment.manage | Book, confirm, reschedule, cancel and complete appointments | ✅ | ✅ | ✅ | ✅ | — | — | — |
queue.manage | Operate the token / queue desk | ✅ | ✅ | ✅ | — | — | — | — |
Clinical
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
encounter.read | View encounters | ✅ | — | — | ✅ | — | — | — |
encounter.write | Open and document encounters | ✅ | — | — | ✅ | — | — | — |
vitals.write | Record vitals | ✅ | — | — | ✅ | — | — | — |
clinical.document.read | View clinical documents and reports | ✅ | — | — | ✅ | — | — | — |
clinical.document.create | Create clinical documents | ✅ | — | — | ✅ | — | — | — |
clinical.document.update | Edit draft clinical documents | ✅ | — | — | ✅ | — | — | — |
clinical.document.sign | Sign clinical documents | ✅ | — | — | ✅ | — | — | — |
clinical.document.amend | Amend or add addenda to signed documents | ✅ | — | — | ✅ | — | — | — |
clinical.document.void | Void clinical documents | ✅ | — | — | — | — | — | — |
clinical.document.share | Share clinical documents with patients / third parties | ✅ | — | — | ✅ | — | — | — |
clinical.document.readRestricted | View documents flagged as restricted (psychiatry, HIV, VIP …) | — | — | — | — | — | — | — |
clinical.template.read | Browse clinical templates | ✅ | — | — | ✅ | — | — | — |
clinical.template.manage | Clone, edit and publish clinical templates | ✅ | — | — | — | — | — | — |
rx.read | View prescriptions | ✅ | — | — | ✅ | — | — | — |
rx.write | Write prescriptions | ✅ | — | — | ✅ | — | — | — |
careplan.manage | Assign and edit care plans / home programmes | ✅ | — | — | ✅ | — | — | — |
package.manage | Sell and track treatment / session packages | ✅ | ✅ | ✅ | ✅ | — | — | — |
ai.assist.use | Use AI dictation, AI drafts, summaries and ICD suggestions (when the workspace enabled AI assist) | ✅ | — | — | ✅ | — | — | — |
careplan.read | View care plans / home programmes and care-plan templates | ✅ | — | — | ✅ | — | — | — |
consent.read | View patient consent records | ✅ | ✅ | ✅ | ✅ | — | — | — |
consent.capture | Record and withdraw patient / guardian e-consent | ✅ | ✅ | ✅ | ✅ | — | — | — |
immunization.read | View vaccination records and the due schedule | ✅ | ✅ | ✅ | ✅ | — | — | — |
immunization.write | Record vaccinations and send vaccine reminders | ✅ | — | — | ✅ | — | — | — |
teleconsult.conduct | Start and conduct teleconsultations (NMC Telemedicine Practice Guidelines) | ✅ | — | — | ✅ | — | — | — |
Billing & finance
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
billing.read | View bills | ✅ | ✅ | ✅ | ✅ | — | — | — |
billing.create | Create bills and record payments | ✅ | ✅ | ✅ | ✅ | — | — | — |
billing.refund | Cancel bills, issue credit notes and refunds | ✅ | ✅ | — | — | — | — | — |
finance.read | View income, expenses and financial dashboard | ✅ | ✅ | — | — | ✅ | — | — |
reports.financial | View financial reports | ✅ | — | — | — | ✅ | — | — |
finance.cashClosing.approve | Approve or reopen daily counter cash closings | ✅ | ✅ | — | — | — | — | — |
finance.reconcile | Reconcile UPI / digital payments against bank statements | ✅ | ✅ | — | — | ✅ | — | — |
finance.payout.manage | Edit practitioner revenue-share (payout) rules | ✅ | — | — | — | — | — | — |
Administration
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
reports.operational | View visit and practitioner analysis reports | ✅ | ✅ | — | — | — | — | — |
settings.read | Read workspace and clinical configuration | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
settings.manage | Change workspace and clinical configuration | ✅ | — | — | — | — | — | — |
users.manage | Create and manage employees | ✅ | — | — | — | — | — | — |
branches.manage | Create and manage branches / facilities | ✅ | — | — | — | — | — | — |
services.manage | Manage the service & price list | ✅ | ✅ | — | — | — | — | — |
feedback.read | View patient reviews and feedback | ✅ | ✅ | — | — | — | — | — |
branding.manage | Manage branding, letterheads and online listings | ✅ | — | — | — | — | ✅ | — |
subscription.manage | Manage the workspace subscription and platform billing | ✅ | — | — | — | — | ✅ | — |
audit.read | View audit logs | ✅ | — | — | — | — | — | — |
data.export | Export workspace data | ✅ | — | — | — | — | — | — |
data.import | Import patients / services from CSV and roll imports back | ✅ | — | — | — | — | — | — |
privacy.request.manage | Handle DPDP data-principal requests (access, correction, erasure, grievance) | ✅ | — | — | — | — | — | — |
Communication
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
whatsapp.use | Use the WhatsApp inbox | ✅ | ✅ | ✅ | — | — | — | — |
Workspace
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
dashboard.operations | Operations dashboard | ✅ | ✅ | ✅ | — | ✅ | — | — |
dashboard.practitioner | Practitioner (my patients / my day) dashboard | — | — | — | ✅ | — | — | — |
letterpad.use | Personal letterpad and professional profile | ✅ | — | — | ✅ | — | — | — |
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
platform.admin | Platform (cross-tenant) administration | — | — | — | — | — | — | — |
lab
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
lab.order.manage | Create and manage pathology lab orders | ✅ | ✅ | ✅ | ✅ | — | — | — |
lab.sample.manage | Accession, collect and track lab specimens | ✅ | ✅ | ✅ | ✅ | — | — | — |
lab.result.enter | Enter lab results | ✅ | — | — | ✅ | — | — | — |
lab.result.verify | Pathologist e-signature: verify results and sign lab reports | ✅ | — | — | ✅ | — | — | — |
lab.testMaster.manage | Manage the lab test master, reference ranges and panels | ✅ | — | — | — | — | — | — |
radiology
| Permission | What it allows | Owner (Super Admin) | Branch manager | Receptionist | Practitioner / Doctor | Accountant | Admin (legacy) | Staff |
|---|
radiology.order.manage | Create and manage radiology orders | ✅ | ✅ | ✅ | ✅ | — | — | — |
radiology.study.manage | Schedule and manage radiology studies / worklist | ✅ | ✅ | ✅ | ✅ | — | — | — |
radiology.report.verify | Radiologist e-signature: verify and sign radiology reports | ✅ | — | — | ✅ | — | — | — |
71 permissions in the catalog. ✅ = included in the role bundle, — = not included.
Troubleshooting
| Problem / message | What it means | What to do |
|---|
| Access denied. Only SUPER_ADMIN can manage employees. | Your role cannot manage users | Ask the owner |
| Enter an email address to create a login for this employee. | Login is enabled but email is blank | Add email or untick login |
| Employee created without login credentials. | App login is off | Use for non-login staff; edit later if needed |
| Password has already been set. This link can only be used once. | Link was used | Use Forgot Password or admin reset |
| Restricted patient appears missing | Caller lacks restricted access | Owner or assigned practitioner should open it; check audit |