Roles and access
Choose a lab or clinic role and review its allowed and restricted actions before assigning it.
Your role applies to the active organization. You can have different roles in different labs and clinics. Within the areas your role permits, records are visible across that organization.
Lab roles
| Role | Can do | Cannot do |
|---|---|---|
| Owner | Manage daily work, settings, team, finance and ownership | — |
| Lab Manager | Manage orders, production, inventory, dispatch, settings, team and finance, including refunds | Change ownership, subscriptions, Stripe connections, banking details or API keys |
| Technician | Manage orders, scans, files, messages, production tasks and assignments, quality checks, inventory and dispatch | Open finance or report screens; change settings or team roles |
| Accounts | View operational records; manage invoices, credits, payments, refunds, expenses, reconciliation and financial exports | Change orders, production, inventory or dispatch; send operational messages; change settings or team roles |
Owners and Lab Managers can view technician-time reports. Accounts can run other reports and export financial reports; general organization data exports remain restricted to owners and managers. Room assignments and working hours determine who can be scheduled, while job roles determine who can view or manage production.
Clinic roles
| Role | Can do | Cannot do |
|---|---|---|
| Owner | Manage clinic work, clinical reviews, settings, team, finance and ownership | — |
| Practice Manager | Manage patients, orders, files, messages, clinical reviews, settings, team and finance | Change ownership, subscriptions, saved payment methods or API keys |
| Dentist | Manage patients, orders, files and messages; approve CAD designs and surgical reports or request changes | Open finance screens; change settings or team roles |
| Reception | Manage patients, files and messages; submit every order type, including CAD, surgical and payment-required orders | Approve CAD designs or surgical reports, request clinical changes, open finance screens or manage the team |
Reference-doctor selection is separate from the role of the person entering the order. Reception can submit an order for its selected eligible doctor without receiving that doctor's clinical approval permission.
Prices, payments and settings
Operational roles can see case prices and payment status. Reception can complete a payment required to submit an order; this does not grant access to invoice settlement, saved payment-method management or the clinic's finance screens.
Every recognized role can inspect non-financial settings. Changes are restricted to owners and managers. Finance settings are visible only to roles with finance access, and banking details and Stripe controls can be changed only by an owner. Invalid or organization-incompatible roles are denied access.
Assign a role
- Open Settings → Team and choose Invite member, or open an existing member's role dialog.
- Select a role card. The dialog lists what the role can do and cannot do. When editing a member, it also marks permissions being added or removed.
- Review the access before saving. Compare roles opens a side-by-side table for the active organization.
- Invitees accept from Account Settings → My Invitations. A join request also opens a role dialog before approval.
Only an owner can grant another person ownership. Managers can assign the other roles for their organization. Existing owner and self-change protections still apply. Shareable join codes offer Technician or Lab Manager for labs, and Reception or Practice Manager for clinics; they never grant Owner, Accounts or Dentist.
Existing Staff memberships, invitations and codes remain compatible: Staff is shown and enforced as Technician in a lab and Reception in a clinic. Newly assigned roles use the explicit job name. Selecting the equivalent job for an existing Staff member does not rewrite their membership.