Staff and Roles
Everyone who signs in has their own account. What each person can reach is decided by the role you assign them. No roles ship ready-made — you build the ones your clinic needs.
Everything here lives under the Employee menu.
Where to Find It
Click an address to open that screen on your own clinic. The first click asks which clinic you are, then remembers it. Addresses holding a {id} or {token} need a specific record, so they are shown but not linked.
| Screen | Address |
|---|---|
| Roles | /roles |
| New role | /new-role |
| Role details | /show-role/{id} |
| Edit role | /edit-role/{id} |
| All employees | /all-user |
| New employee | /new-user |
| Employee details | /view-user/{id} |
| Edit employee | /edit-user/{id} |
| Staff custom fields | /custom-fields/user |
| What a disabled account sees | /account-disabled |
| What a missing permission shows | /access-denied |
Step 1 — Build the Role First
| Field | Notes |
|---|---|
| Role Name * | Must be unique, e.g. Receptionist, Nurse. It is what you pick from when giving someone a role, so name the job |
| Description | Optional, shown in the roles list |
Under the name come the permissions. First choose what kind of role it is:
| Choice | What it means |
|---|---|
| Chosen permissions | You decide, section by section, what the role may do |
| Everything (admin) | The role holds every permission — see below |
Start from a role you already have
Beside that choice, the Copy from a role dropdown lists every other role in your clinic, each with how many permissions it holds and how many people hold it. Picking one copies its permissions into the new role; change what you like afterwards. The dropdown keeps showing that role's name until your first change. While it does, its first row, Stop copying, puts back the permissions you had before you copied. Its last row, Manage roles, opens the roles list. The original role is not touched, and the two are not linked once you save. Undo on the notice puts back what you had before.
A senior receptionist, for example, is the receptionist's permissions plus two more — copy, then tick the two.
The permission grid
Each row is one section of the system — Patients, Invoices, Shifts, Stocktake — grouped into five areas: Clinic, Money, Stock and purchasing, Human resources and Administration.
- The four columns are the plain actions: View, Add, Edit, Delete. A dash means the section has no such action.
- Anything else a section can do sits as a chip on its own row: View medical records on Patients, Approve a difference over the limit on Shifts. Hover a shortened chip to read its full wording.
- Click a row's name to tick or clear the whole row. Click a column heading to tick or clear that action on every row shown. Each area and each group has its own Select all.
- The tabs above the grid show one area at a time with its count; Find a permission filters the rows as you type; Selected only hides everything not yet ticked.
- Delete boxes, and sensitive chips, turn red when ticked.
On a phone the columns fold away and each row shows its actions as named chips.
Prerequisites tick themselves — and say so
Hover a permission and the ones it needs are outlined. Ticking it pulls them in, all the way down:
- Edit Medical Records → also ticks View Medical Records → which ticks View Patients
- Mark Payroll as Paid → also ticks Approve Payroll → which ticks View Payroll
Un-ticking works the other way: clearing View Patients clears the other patient permissions that cannot work without it. Either way a notice names what was added or removed, with Undo.
The summary beside the grid
The card beside the grid reads the role back as you build it: its name, how many permissions it holds out of the total, a bar for each area, and Sensitive permissions — every delete, approval, payroll payment, settings change and user or role change it holds, by area. Click one to jump to its row. Check this list before saving.
Everything (admin) versus ticking everything
They are not the same. Everything (admin) is a standing grant — the role keeps full access, including permissions added in future releases. Ticking every box grants exactly today's list, and a new feature would arrive switched off. For a genuine deputy, choose admin; for a bounded job, tick what it needs.
While admin is chosen, the grid is replaced by a short note. Switch back to Chosen permissions and your previous ticks come back.
Step 2 — Create the Employee
| Field | Notes |
|---|---|
| Name * | |
| Email * | Must be unique — it is the sign-in name |
| Phone * | |
| Password * | At least 5 characters. Leave empty when editing to keep the current one |
| Confirm Password * | Must match |
| Address | The form will not submit without it |
| Assistant Photo | Optional |
| Role | Pick the role you built. — No Role — means no access to anything |
| Assigned Branches | Only on a clinic with more than one branch — see below |
| Default Branch | The branch this person lands in when they sign in |
| Access to all branches | Includes every branch, including ones opened later |
| This user is a doctor | Puts the person on the doctor lists — see below |
| Discount limit (% of record total) | The most this person may take off one record as a discount. Empty means no limit. Shown only to someone who may give discounts themselves, and it only matters if this person's role may give them too |
| Active | Edit screen only. New accounts start active |
Choosing a role shows a preview strip beside the select: the role's name and either its permission count or Full Access.
If the HR module is switched on, a Human Resources block appears with employee code (auto-generated), national ID, gender, date of birth, department, job title, emergency contact and notes. All optional. Turning Mark as Employee back off and saving clears those HR fields.
Any custom fields your clinic defined for staff appear at the bottom of the form.
Which Branches Someone Works In
Assigned Branches is a multi-select: pick as many branches as the person actually works in — hold Ctrl (⌘ on a Mac) to add to the selection, or drag down the list. One person can hold one branch, three, or all of them.
The block only appears when there is a choice to make: your clinic has more than one branch, and you hold the Assign Users to Branches permission. On a single-branch clinic there is nothing to assign, so the fields stay hidden and everyone works in the one branch.
| Field | What it does |
|---|---|
| Assigned Branches | Every branch this person may switch into. Their branch menu lists exactly these |
| Default Branch | Which of the selected branches they land in at sign-in. Only the branches you selected can be picked — the list narrows as you choose. It follows them: when that person switches branch from their own menu, the branch they switch into becomes their default |
| Access to all branches | A standing pass instead of a list. Branches opened later are included without you editing the account |
Notes worth knowing:
- Leaving the selection empty removes the person from every branch, and they fall back to the clinic's default branch.
- If you clear the default, or the branch that held it is taken out of the selection, the first selected branch becomes the landing branch — nobody is left signing in with nowhere to go.
- Assigning branches is its own permission, separate from editing users: a role that can rename a receptionist is not thereby allowed to move them to another branch.
- Taking a branch away from someone who is working in it does not break their session. The next page they open moves them to a branch they can still reach and says so.
The "doctor" flag is not a role
Ticking This user is a doctor puts that person on every doctor list — the doctor picker when booking an appointment, assigning a patient, the queue settings, the pediatrics filters. It grants no permissions: what they can open is still decided by the role you select.
Two things follow:
- Anyone who may add or edit employees can set it. Because it unlocks nothing, there is no reason to hold it back from the person who manages staff.
- A doctor still needs a role. Pick one that covers the screens they work in — patients, appointments, prescriptions. The clinic owner account keeps full access regardless of roles.
TIP
A doctor missing from the booking list? Open their record, tick This user is a doctor, and make sure the account is active.
Disabling Someone Who Leaves
Do not delete them — edit the employee and switch Active off.
Deletion is refused for anyone attached to an appointment, a patient or a payment, and the message says as much: you cannot delete this assistant but you can disable this account.
A disabled person can still sign in, but the next page is a block screen reading Your account is disable — Please contact to your system admin, and nothing else is reachable. Switch Active back on to restore them. Their history and activity log survive either way.
TIP
That block page is English-only, even on an Arabic system. Worth mentioning to staff so it is not mistaken for a fault.
The Employee List
Employee → All Employees shows, per row, the person's name and photo (with a Doctor pill where relevant), phone and email, address and join date, and an Active/Inactive badge. Header pills count how many are registered, active, and doctors.
Filter by status, search by name, phone or email, and sort by name. Row actions: View, Edit, Delete. The detail page adds a Permissions tab showing what the assigned role actually allows, and an Activity Log tab.
Deleting a Role
A role cannot be deleted while a single account still holds it — active or disabled, the message is Cannot delete this role — it is assigned to one or more users. This is deliberate: no account is ever left with a dangling role and an unclear permission set.
To retire a role: open All Employees, find everyone holding it, move them to another role or to — No Role —, then delete it.
Permission Reference
| Group | Permissions |
|---|---|
| Prescriptions | View · Create · Edit · Delete · Manage Drugs · Manage Questions |
| Appointments | View · Create · Edit · Delete · View All · View Own |
| Patients | View · Create · Edit · Delete · View Medical Records · Edit Medical Records · View Patient Payments |
| Payments | View · Add · Delete · Discounts and write-offs — giving or undoing a discount on what a patient owes and editing the reasons list. On upgrade it went to every role that may edit settings, and to no one else |
| Income & Expense (manual) | View · Create · Edit · Cancel (void journal) · Permanently delete |
| Reports | View · Export |
| Settings | View · Edit |
| Backup | Create a backup (the only card in this group) |
| Enquiries | Manage Enquiries — one card covering the whole screen: recording, following up, bringing in messages from your page, and replying |
| Users & Roles | View/Create/Edit/Delete Users · View/Create/Edit/Delete Roles · Edit own custom fields |
| Branches | View · Create · Edit · Delete · Assign Users to Branches |
| Till | Open, work and close your own shift · Approve a difference above the threshold · See other cashiers' shifts and the differences report. The first is granted on upgrade to every role that already handles payments, so nothing stops working. Approve is granted to nobody — a cashier who can approve their own shortage is not a control, so give it to a supervisor deliberately |
| Treatment | Change a saved visit's assignees — who performed a visit, once it is written. Recording it while writing the visit needs only Edit Medical Records; this card is the separation a clinic wants once commission depends on the answer. Every role that already held Edit Medical Records was given it on upgrade, so take it away from the roles you want restricted |
| Human Resources | Departments, Shifts, Attendance (including view own and clock in/out), Leave Types, Leave Requests (submit, approve/reject), Salary Components, Contracts, Payroll (view, create, edit, delete, approve, mark as paid) |
The Human Resources group is always listed in the role builder, but its screens only appear once the HR module is enabled in Site Settings.
Two combinations worth understanding:
- View All Appointments vs View Own Appointments — the second limits a person to appointments they are attached to. Give a receptionist the first, a visiting doctor the second.
- View Medical Records is the gate for the whole clinical half of the patient file (diagnoses, documents, and the specialty tabs). Without it, staff can book and take payments but see no clinical data.
Extra Fields on Staff Records
Employee → Staff Settings → Manage custom fields lets you add your own fields to the staff record: what it is called (English and Arabic), its type, whether it is required, and whether it shows as a column or a filter in the employee list. Up to 30 active fields and 5 list columns.
Field types available: single line, multi-line, number, currency, phone, email, URL, dropdown, multi-dropdown, yes/no, date, time, file upload, and section headers for grouping.
Changes are staged and then Published in one go. Deleting a published field hides it but keeps what was entered — restore it from Deleted fields and the values come back.
For a staff member to fill in one of these fields on their own profile, two things must both be true: their role has Edit own custom fields, and you ticked Staff can edit their own on that specific field. That second gate is what keeps fields like salary out of their reach.