The role a person holds in a clinic decides everything: what they see in the menu, which buttons are active, and what they will not carry out even by typing the page address directly. Heltio checks the permission on every request to the server, so a hidden button is not the only barrier.
There are thirteen roles: four in an ordinary clinic, eight more in a hospital facility, and Patient β the role of an account in the patient portal, which grants access to no staff action at all. One person can belong to several clinics and hold a different role in each. A role is not a property of the account, but of the membership of one particular clinic.
Roles in an ordinary clinic
The picker used when inviting and when changing a role holds three entries: Administrator, Practitioner, Assistant. Owner is deliberately not on that list β it is created when the clinic is set up and nobody can grant or take it away from inside the app.
| Action | Owner | Administrator | Practitioner | Assistant / Reception |
|---|---|---|---|---|
| View patient records | β | β | β | β |
| Create a patient record | β | β | β | β |
| Delete a patient | β | β | β | β |
| Book appointments | β | β | β | β |
| Cancel appointments | β | β | β | β |
| Write and sign a clinical note | β | β | β | β |
| Take payments | β | β | β | β |
| Refund payments | β | β | β | β |
| Issue invoices | β | β | β | β |
| Invite people and change roles | β | β | β | β |
| Read the audit log | β | β | β | β |
| Change GDPR settings | β | β | β | β |
| Manage the Heltio subscription | β | β | β | β |
Heltio checks 102 separate permissions. The Owner holds all of them, the Administrator 101, the Practitioner 42, the Assistant / Reception 26. Owner and Administrator therefore differ in exactly one thing: the Heltio subscription, buying SMS bundles and AI credits are reserved for the owner. On top of that comes a rule you cannot get around: a clinic must have at least one owner, so the last one cannot be demoted or removed.
Hospital roles
A facility registered as a hospital gets eight extra roles, grouped in the picker under the heading Hospital roles. Each carries a short description under its name β the same one you read below.
| Role | Description shown in the picker | Permissions of 102 |
|---|---|---|
| Coordinator | Department head β manages structure & teams, may countersign notes | 27 |
| Senior therapist | Supervising therapist β countersigns notes, plans treatment series | 17 |
| Trainee | Documents care; notes require countersign before finalisation | 11 |
| Occupational therapist | Documents their own clinical work; no administration | 11 |
| Speech therapist | Documents their own clinical work; no administration | 11 |
| Psychologist | Documents their own clinical work; no administration | 11 |
| Technician | Executes ordered procedures; cannot create or sign orders | 8 |
| Clinical (read-only) | Read-only clinical access; cannot change any data | 7 |
These roles do not form a ladder, and that is the difference people trip on most easily. In an ordinary clinic a higher role holds everything a lower one holds. Here every permission is granted separately, by name: Clinical (read-only) sees patient records and the ward but changes nothing in them, even though on a hierarchy it would look higher than reception. A rehabilitation order is signed by a Coordinator alone β a Senior therapist can create and carry it out, but not sign it.
In an ordinary clinic you will not see these roles β neither in the picker nor on the server side, which rejects any attempt to grant one.
How to change a role
Open the Members section
In Settings, scroll down to the Members section. The table shows the columns Name, Email, Role and Joined; your own row carries a (you) note.
Choose Change Role
From the menu on the row, choose Change Role. The dialog shows Current role: β¦ and a New Role list. In a hospital facility the list is split into Staff and Hospital roles.
Confirm
Click Update Role. Heltio confirms with Role updated to β¦ and the new permissions take effect at once.
When something does not work
Cannot demote the last owner.
What this means: You are trying to change the role of the only person who owns the clinic.
Cannot remove the last owner of the clinic.
What this means: The same rule as above, seen from the removal side.
Team member management is available to clinic owners and administrators only.
What this means: You opened the Members section in a role that does not change roles.
You don't have permission to perform this action
What this means: The role you hold in the active clinic does not cover this action.
Who has access
Clinic AdminRoles are changed by the clinic owner and administrator only. Every change leaves a trace in the audit log β who changed it, for whom, and to what.
Related
- The clinic team β where to change a role and whom to remove.
- Audit log β every role change leaves a trace there.
- Inviting people to the clinic β how a role reaches a new person's account.
Related features
The clinic team
The list of people working in the clinic: who holds which role, how to change it, how to take access away from someone leaving, and what happens to their appointments and notes.
Audit log
A record of who reached for patient data and when, and who changed it. Filters, export to CSV or JSON, the starting point for a GDPR inspection and for internal explanations.
Inviting people to the clinic
The invitation form works, but the invited person has nowhere to click βacceptβ today. What the button actually does, what is missing, and how to add somebody to the team right now.