Trust and security

Roles, permissions, and sensitive actions

Choose least-privilege clinic roles, understand record scopes, and confirm high-risk changes safely.

Last updated: 2026-07-22

Step-by-step guide

  1. 1Use Clinic owner only for the accountable clinic owner. Ownership, subscription changes, unrestricted export, clinic erasure, and access-role assignment stay owner-only.
  2. 2Use Administrator for trusted operational leaders who need team, settings, private service records, finance, reporting, marketing, and integration workflows without ownership controls.
  3. 3Use Front desk for scheduling, client contact details, package sales, invoices, and payment collection. It excludes private service notes, refunds, exports, settings, and integrations.
  4. 4Use Service provider for the person’s own schedule and clients assigned to them through bookings. This access does not include other providers’ records or clinic administration.
  5. 5Set online-booking visibility separately. Turning booking visibility off does not grant or revoke workspace permissions.
  6. 6When Appointa displays Confirm it’s you, enter your current account password. The original action resumes automatically after successful confirmation.
  7. 7Recent password confirmation is required for access changes, refunds and reversals, financial or audit exports, privacy erasure, payment configuration, billing, and integration connection changes.
  8. 8Role and access-status changes are recorded in the clinic audit log with the actor and before-and-after state.
  9. 9If a person changes duties, update their role immediately. Turn off their access promptly when they leave, while retaining historical appointment attribution.
  10. 10Review access quarterly and after staff, contractor, finance-provider, or clinic-owner changes.

Related articles