Trust and security
Roles, permissions, and sensitive actions
Choose least-privilege clinic roles, understand record scopes, and confirm high-risk changes safely.
Last updated: 2026-07-22
Step-by-step guide
- 1Use Clinic owner only for the accountable clinic owner. Ownership, subscription changes, unrestricted export, clinic erasure, and access-role assignment stay owner-only.
- 2Use Administrator for trusted operational leaders who need team, settings, private service records, finance, reporting, marketing, and integration workflows without ownership controls.
- 3Use Front desk for scheduling, client contact details, package sales, invoices, and payment collection. It excludes private service notes, refunds, exports, settings, and integrations.
- 4Use Service provider for the person’s own schedule and clients assigned to them through bookings. This access does not include other providers’ records or clinic administration.
- 5Set online-booking visibility separately. Turning booking visibility off does not grant or revoke workspace permissions.
- 6When Appointa displays Confirm it’s you, enter your current account password. The original action resumes automatically after successful confirmation.
- 7Recent password confirmation is required for access changes, refunds and reversals, financial or audit exports, privacy erasure, payment configuration, billing, and integration connection changes.
- 8Role and access-status changes are recorded in the clinic audit log with the actor and before-and-after state.
- 9If a person changes duties, update their role immediately. Turn off their access promptly when they leave, while retaining historical appointment attribution.
- 10Review access quarterly and after staff, contractor, finance-provider, or clinic-owner changes.