Skip to main content

Staff & Permissions

Every person on your team gets their own login with a role — a named bundle of permissions that decides what they can see and do in the platform. Roles keep the front desk out of health records, keep coaches from issuing refunds, and keep sensitive numbers like revenue visible only to the people you choose. Setting roles correctly is also a HIPAA matter: staff should only be able to access the patient data their job actually requires.

This page explains the five built-in roles in plain language, how to invite staff, how to customize permissions when the defaults don't fit, and the two special permissions that are never granted automatically.

The five built-in roles

Ready Practice ships with five roles that cover the typical shapes of a clinic team. Assign the one that matches the person's job — you can always adjust later.

RoleBest forIn short
AdminOwners and practice managers who run everythingFull access to every feature, all settings, revenue, and billing
ManagerOperations leadsRuns scheduling, clients, staff, and billing — but no client health data
MedicalClinicians, nutritionists, PTsSchedule, clients, and full health data (labs, metrics, notes)
Customer ServiceFront deskScheduling, clients, forms, and billing — no health data at all
CoachCoaches and trainersMostly view-only: sees schedule, clients, and health data; adds notes

Here's what each role means day to day:

  • Admin can do everything — every setting, every client, revenue reports, integrations, and this permissions system itself. Reserve it for the people who genuinely run the organization; most teams need only one or two Admins.
  • Manager is the operations role. Managers manage the schedule (including canceling sessions), edit client and staff records, handle billing and issue refunds, edit services, message clients, and see reports — but not revenue reports, and they have no access to client health data beyond visit notes.
  • Medical is the clinical role. Medical staff manage the schedule and their availability, edit client records, and see the full clinical picture — labs, wearable metrics, imaging, conditions, medications — and write visit notes. They can't issue refunds or change organization settings.
  • Customer Service is the front-of-house role. They book and adjust appointments, create and edit clients, send and manage intake forms, message clients, and handle billing — but cannot refund, and they see no health data (no labs, no metrics), only basic notes.
  • Coach is the lightest role. Coaches view the schedule, client profiles, documents, and health data (labs, metrics, sleep, workouts) and can add visit notes — but they can't book, cancel, or edit appointments, and they can't touch money.
Match the role to the data the job needs

Giving the front desk a Medical role "to be safe" exposes client health records to people who don't need them — that's a HIPAA exposure, not a convenience. When in doubt, assign the narrower role; you can grant more later in seconds.

Invite a staff member

Adding someone takes under a minute, and they get an email invitation to set up their own login.

  1. In the Provider web portal, open Staff from the main menu and click Add Staff. The Add Staff Member form opens.

  2. Enter their email address (this becomes their login), their first and last name, and pick their Role from the dropdown — the five built-in roles plus any custom roles you've created. If you run multiple locations, choose their home location too.

  3. Click save. The person receives an invitation email with a link to create their password, and they appear in your staff list right away. If the email gets lost, open their row in the staff list and choose Resend invite.

Ask Atlas

You can skip the form entirely: tell Atlas "add jane@myclinic.com as Customer Service at the Downtown location" and approve the card it stages.

Customize permissions and create custom roles

The built-in roles fit most teams, but you're not stuck with them. Under Settings → Permissions you'll find the full permission matrix — every role as a column, every permission as a row — where an Admin can tune exactly what each role can view and edit. Most permissions come in view and edit pairs (for example, viewing the schedule vs. changing it), so you can give someone eyes on an area without the ability to change it.

If no built-in role fits — say, a billing specialist who needs claims but nothing clinical — click Create Custom Role, name it, and tick exactly the permissions it should carry. Custom roles then appear in the role dropdown when you add or edit staff, just like the built-ins. You can delete a custom role from the same screen when you no longer need it.

Changes apply to everyone with the role

Editing a role's permissions changes what every staff member holding that role can do, immediately. If one person needs an exception, create a custom role for them rather than widening a shared one.

Two permissions that are never automatic

Two sensitive permissions are standalone — no role implies them, not even broad operational ones. An Admin must grant them explicitly in Settings → Permissions:

  • View revenue (view_revenue) — access to revenue figures in analytics and reports. A Manager sees operational reports but not money totals until you grant this deliberately.
  • Override booking parameters (override_booking_parameters) — lets a staff member bypass your booking rules (minimum notice, booking windows) when placing an appointment. Useful for a trusted scheduler who handles exceptions; risky as a default, because it makes every guardrail optional for that person.

Provider availability

Once your clinical staff are in, set up when and where they can be booked: give each provider their working hours per location, add exceptions for vacations and holidays, and link each service to the providers who deliver it. This is what makes the right slots appear on your calendar and booking links — the details live in the scheduling guide below.

Next steps

  • Set provider hours and services → configure availability and service links in Scheduling Defaults so bookable slots appear.
  • Give each person their learning path → point new staff at the role tracks: Admin / Owner, Provider / Clinician, and Front-Desk — each is a curated tour of the features that role uses daily.
  • Next up: Client Onboarding — bring in your first clients now that your team is set.