Roles & permissions
The six staff roles, the practitioner flag, and who can read, write, and delete what.
The six roles
Every team member has exactly one role at your clinic:
- Owner — the clinic's principal. Everything, including destructive actions and billing. Each clinic has a single owner; ownership can be transferred.
- Admin — practice manager. Runs the business side: team, settings, billing, reports.
- Doctor — sees patients and writes medical records.
- Nurse — clinical support: vitals, allergies, lab legwork.
- Receptionist — the front desk: booking, check-in, payments, waitlist, recalls.
- Assistant — general clinic support, similar reach to reception.
The practitioner flag
Separately from the role, a member can be a practitioner — someone whose name may go on a medical-legal record. Doctors always are. An owner can be, by turning on "sees patients" in their membership. An office admin is never one, no matter the role's other powers: they can manage the whole clinic but cannot chart a visit, finalize a record, or sign off a lab result.
Billing counts doctor seats: owner and doctor roles are billable; nurses, reception, admins and assistants are free.
The one rule
Reads are open to the clinic. Writes are scoped to the job. Destruction is scoped to ownership.
Anyone at the clinic can look at a patient's chart — care is a team sport, and hiding the chart from the nurse helps nobody. Changing things is scoped to whose job it is. Deleting things is for owners and admins.
Deliberate exceptions
- Business surfaces are closed reads: the audit trail, data export, billing, clinic configuration and team management belong to owner/admin.
- Safety-critical retraction: adding an allergy is everyone's job — over-reporting is safe. Removing one is a clinical decision and needs a practitioner.
- Vitals: nurses and assistants can record vitals on a visit that's still a draft, even though the rest of the visit belongs to the doctor.
- Lab results: anyone at the desk can log a result as it arrives, but marking it reviewed is a clinical sign-off and needs a practitioner.
- Drug-safety switches: turning allergy or interaction alerts off is owner-only and is recorded in the audit trail. Turning them back on is owner or admin — restoring a safeguard is never restricted.
What this looks like in the app
The app never shows you a button the server would refuse. If you don't see an edit or delete action on something, that's the permission system working — for example, a colleague's shared prescription template shows who added it instead of a delete button.
Still stuck?
If you already use Angel, ask from inside it — Help & support carries your clinic, screen and app version with the message, so nobody has to describe their setup. Otherwise write to us and a human will answer.