Roles and permissions
Every person at a site has one role. The role decides which pages they see and what they can change. Pages and buttons you aren't allowed to use are left out, so if something described in these docs is missing for you, your role is the likely reason.
A site owner or admin sets roles under Settings › App users (see Staff and app users). The same screen has a ? button that shows what each role allows.
The site roles
Owner. Can do everything at the site, including managing app users and staff, all settings, products, stock, cases, visits, audits and reports. A site's first owner is whoever creates the site. The Owner role can't be handed out when inviting people.
Admin. Has the same abilities as an owner. The difference is who they can manage: an admin can't invite another admin, and can't change or remove owners or admins. Only an owner can do that.
Member. The everyday working role. Members can manage products, procedures, stock, cases and visits, count stock in audits, set up quarterly reports, and see stats and recalls. They can't change site settings, manage app users or staff, or see the activity log.
Viewer. Can look but not change. They see inventory, cases, visits and stats.
Inventory manager. Looks after stock and the product catalog. They can add, edit and remove stock, manage products and barcodes, count stock in audits, set up quarterly reports, and see inventory, stats and recalls. They don't see cases or visits.
Stats viewer. Sees stats and nothing else.
Visit manager. Creates visits and sends invite links to vendor reps. They can also see inventory, visits and stats. This role is only offered when the site uses visits.
Clinician. Creates and edits cases and records the items used. They can also see inventory and stats.
Auditor. Counts stock in an audit, and can see inventory and stats. They count, but don't apply the results. Applying, cancelling and reopening an audit takes a role that manages both products and stock.
Purchaser. Sees inventory, visits, stats and recall matches. They can't change anything.
Compliance. Sees inventory, cases, stats, recall matches and the activity log. They can't change anything.
Site settings. Changes the site's settings: scanning, alerts, branding, locations, visits and stock visibility. They can also see inventory and stats.
Who can do what
This table is built from the same rules the app uses.
| Capability | Owner | Admin | Member | Viewer | Inventory manager | Stats viewer | Visit manager | Clinician | Auditor | Purchaser | Compliance | Site settings |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| See inventory and audits | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | Yes | Yes |
| Add, edit and remove stock; scan stock in and out; confirm or dismiss recall matches | Yes | Yes | Yes | No | Yes | No | No | No | No | No | No | No |
| Manage the product catalog and barcodes | Yes | Yes | Yes | No | Yes | No | No | No | No | No | No | No |
| See cases | Yes | Yes | Yes | Yes | No | No | No | Yes | No | No | Yes | No |
| Create and edit cases; record items used | Yes | Yes | Yes | No | No | No | No | Yes | No | No | No | No |
| Manage procedures (importing cases also needs case access); merge categories in Cleanup | Yes | Yes | Yes | No | No | No | No | No | No | No | No | No |
| See visits | Yes | Yes | Yes | Yes | No | No | Yes | No | No | Yes | No | No |
| Create visits and send invite links | Yes | Yes | Yes | No | No | No | Yes | No | No | No | No | No |
| Count stock in an audit | Yes | Yes | Yes | No | Yes | No | No | No | Yes | No | No | No |
| Apply, cancel and reopen audits | Yes | Yes | Yes | No | Yes | No | No | No | No | No | No | No |
| Report a scanning problem | Yes | Yes | Yes | No | Yes | No | No | Yes | No | No | No | No |
| See recall matches | Yes | Yes | Yes | No | Yes | No | No | No | No | Yes | Yes | No |
| See stats and download the quarterly report | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Set up quarterly reports (format, recipients, send now) | Yes | Yes | Yes | No | Yes | No | No | No | No | No | No | No |
| Change site settings (scanning, alerts, branding, locations, visits, stock visibility) | Yes | Yes | No | No | No | No | No | No | No | No | No | Yes |
| Manage staff (people on cases) | Yes | Yes | No | No | No | No | No | No | No | No | No | No |
| Manage app users and roles; cleanup | Yes | Yes | No | No | No | No | No | No | No | No | No | No |
| See the activity log | Yes | Yes | No | No | No | No | No | No | No | No | Yes | No |
Outside the site roles
Global admin. Someone who looks after the whole installation, not one site. A global admin can open every site. At a site they aren't a member of they act as an owner. Where they are a member, their site role applies. They also use the Admin dashboard to create sites, manage users and review scanning problem reports. See Platform admin. Global admins aren't shown in the table above.
Support. A read-only role for platform support. Support staff can open every site and, at a site they aren't a member of, look at inventory, cases, visits, stats, recalls and the activity log, but can't change anything. Where they are a member, their site role applies. They aren't shown in the table above either.
Visit guests. A vendor rep who gets a visit invite link doesn't have an account and has no site role. The link opens one visit. The rep can see the stock listed on that visit and add stock to it. If a link is no longer valid, the page says "Invitation Not Valid."
Staff and app users
These are two different lists, both under Settings. Staff and app users covers them in full.
- Staff are the people who appear on cases, such as physicians, nurses and techs. They don't have a login, and adding someone here doesn't give them access to the app. Owners and admins manage them under Settings › Staff.
- App users are people who sign in. Each has an email address and a role. Owners and admins manage them under Settings › App users.
Inviting someone
Who can: Owner, Admin
Where: Settings › App users › Invite user
- Enter their email address and choose a role.
- Select Invite.
If they don't have an account yet, they're sent an email and appear under Pending invites, where you can Resend or Cancel the invite. If they already have an account, they get access straight away and no email is sent.
To change someone's role or remove them, use the Members list on the same page.