Skip to content

Roles and permissions

Thirteen roles: four in an ordinary clinic, eight more in a hospital facility and one on the patient side. What each one sees, what it can change, and why a role cannot be overridden with a single permission.

Required permissions:
Clinic Admin
Reviewed: 2026-08-24

The role a person holds in a clinic decides everything: what they see in the menu, which buttons are active, and what they will not carry out even by typing the page address directly. Heltio checks the permission on every request to the server, so a hidden button is not the only barrier.

There are thirteen roles: four in an ordinary clinic, eight more in a hospital facility, and Patient β€” the role of an account in the patient portal, which grants access to no staff action at all. One person can belong to several clinics and hold a different role in each. A role is not a property of the account, but of the membership of one particular clinic.

Open clinic settings

Roles in an ordinary clinic

The picker used when inviting and when changing a role holds three entries: Administrator, Practitioner, Assistant. Owner is deliberately not on that list β€” it is created when the clinic is set up and nobody can grant or take it away from inside the app.

ActionOwnerAdministratorPractitionerAssistant / Reception
View patient recordsβœ“βœ“βœ“βœ“
Create a patient recordβœ“βœ“βœ“β€”
Delete a patientβœ“βœ“β€”β€”
Book appointmentsβœ“βœ“βœ“βœ“
Cancel appointmentsβœ“βœ“βœ“β€”
Write and sign a clinical noteβœ“βœ“βœ“β€”
Take paymentsβœ“βœ“βœ“βœ“
Refund paymentsβœ“βœ“β€”β€”
Issue invoicesβœ“βœ“βœ“β€”
Invite people and change rolesβœ“βœ“β€”β€”
Read the audit logβœ“βœ“β€”β€”
Change GDPR settingsβœ“βœ“β€”β€”
Manage the Heltio subscriptionβœ“β€”β€”β€”

Heltio checks 102 separate permissions. The Owner holds all of them, the Administrator 101, the Practitioner 42, the Assistant / Reception 26. Owner and Administrator therefore differ in exactly one thing: the Heltio subscription, buying SMS bundles and AI credits are reserved for the owner. On top of that comes a rule you cannot get around: a clinic must have at least one owner, so the last one cannot be demoted or removed.

Hospital roles

A facility registered as a hospital gets eight extra roles, grouped in the picker under the heading Hospital roles. Each carries a short description under its name β€” the same one you read below.

RoleDescription shown in the pickerPermissions of 102
CoordinatorDepartment head β€” manages structure & teams, may countersign notes27
Senior therapistSupervising therapist β€” countersigns notes, plans treatment series17
TraineeDocuments care; notes require countersign before finalisation11
Occupational therapistDocuments their own clinical work; no administration11
Speech therapistDocuments their own clinical work; no administration11
PsychologistDocuments their own clinical work; no administration11
TechnicianExecutes ordered procedures; cannot create or sign orders8
Clinical (read-only)Read-only clinical access; cannot change any data7

These roles do not form a ladder, and that is the difference people trip on most easily. In an ordinary clinic a higher role holds everything a lower one holds. Here every permission is granted separately, by name: Clinical (read-only) sees patient records and the ward but changes nothing in them, even though on a hierarchy it would look higher than reception. A rehabilitation order is signed by a Coordinator alone β€” a Senior therapist can create and carry it out, but not sign it.

In an ordinary clinic you will not see these roles β€” neither in the picker nor on the server side, which rejects any attempt to grant one.

How to change a role

01

Open the Members section

In Settings, scroll down to the Members section. The table shows the columns Name, Email, Role and Joined; your own row carries a (you) note.

02

Choose Change Role

From the menu on the row, choose Change Role. The dialog shows Current role: … and a New Role list. In a hospital facility the list is split into Staff and Hospital roles.

03

Confirm

Click Update Role. Heltio confirms with Role updated to … and the new permissions take effect at once.

When something does not work

Warning

Cannot demote the last owner.

What this means: You are trying to change the role of the only person who owns the clinic.

What to do: The **Owner** role cannot be granted from inside the app today β€” it is not in the picker. Leave that person as owner; if the clinic is to change hands, write to Heltio support.
Warning

Cannot remove the last owner of the clinic.

What this means: The same rule as above, seen from the removal side.

What to do: Add a second owner first β€” today only through Heltio support β€” and remove afterwards.
Warning

Team member management is available to clinic owners and administrators only.

What this means: You opened the Members section in a role that does not change roles.

What to do: Ask a clinic administrator. The heading above this message reads **Access Restricted**.
Warning

You don't have permission to perform this action

What this means: The role you hold in the active clinic does not cover this action.

What to do: Check in the **Active clinic** switcher that you are working in the right clinic β€” you may hold a different role in the other one. If the clinic is right, ask an administrator to change your role.

Who has access

Clinic Admin

Roles are changed by the clinic owner and administrator only. Every change leaves a trace in the audit log β€” who changed it, for whom, and to what.

Was this article helpful?

Didn't find an answer? Write to us.

Open the contact form