Roles & Permissions
Detailed guide to roles, permissions, and access control
Roles & Permissions
Understand and configure access control for your organization.
Role Hierarchy
Owner
└── Admin
└── Manager
└── Staff
└── ViewerHigher roles inherit all permissions of lower roles.
Permission Matrix
Organization Level
| Action | Owner | Admin | Manager | Staff | Viewer |
|---|---|---|---|---|---|
| View organization | ✓ | ✓ | ✓ | ✓ | ✓ |
| Edit organization | ✓ | ✓ | ✗ | ✗ | ✗ |
| Manage billing | ✓ | ✓ | ✗ | ✗ | ✗ |
| View audit log | ✓ | ✓ | ✗ | ✗ | ✗ |
| Delete organization | ✓ | ✗ | ✗ | ✗ | ✗ |
User Management
| Action | Owner | Admin | Manager | Staff | Viewer |
|---|---|---|---|---|---|
| Invite users | ✓ | ✓ | ✗ | ✗ | ✗ |
| Change roles | ✓ | ✓ | ✗ | ✗ | ✗ |
| Suspend users | ✓ | ✓ | ✗ | ✗ | ✗ |
| Delete users | ✓ | ✓ | ✗ | ✗ | ✗ |
Module Access
| Action | Owner | Admin | Manager | Staff | Viewer |
|---|---|---|---|---|---|
| Install modules | ✓ | ✓ | ✗ | ✗ | ✗ |
| Configure modules | ✓ | ✓ | Assigned | ✗ | ✗ |
| Access assigned | ✓ | ✓ | ✓ | ✓ | Read-only |
| Manage workflows | ✓ | ✓ | Assigned | ✗ | ✗ |
Custom Roles (Enterprise)
Create custom roles with specific permissions:
- Go to Settings → Team → Roles
- Click Create Role
- Name and describe the role
- Select granular permissions
- Assign to users
Example custom roles:
- Finance Manager - Billing, payments, invoices only
- HR Manager - Staff, patients, appointments only
- Inventory Clerk - Stock, suppliers, orders only
- Receptionist - Bookings, patients (read), schedule
Best Practices
- Principle of Least Privilege - Give minimum needed access
- Regular Reviews - Audit permissions quarterly
- Role-Based - Use roles, not individual permissions
- Document Changes - Note why permissions changed
- Separation of Duties - No single user controls everything