Cloud built for KVKK compliance Developed in Türkiye

Specialties

A shared core, screens tailored to your specialty

Appointments, patient record and finance are the same in every specialty. The examination screen adapts to yours.

All specialties

Clineo Lab

A separate program for dental labs

Turn the case sent by a clinic into a work order, follow production on a board and manage each clinic’s account in one place.

Dental lab software

Blog

How to set up roles and permissions in a clinic

Everyone seeing every screen isn’t convenience, it’s risk. How to grant only the access each job needs.

Updated: 2 August 20263 min read

Why shouldn’t everyone see everything?

The reason is not only trust.

In small clinics the topic of permissions is often closed with "we trust each other". The trust may be real, but the reason for setting permissions is not distrust.

The first reason is legal: health data is a special category of personal data, and access is expected to be limited to what the job requires. In a setup where everyone can reach every record, you cannot show that limit.

The second reason is practical: who did what can only be determined if there are permissions and separate users. In a clinic working with a shared account, you will never find out who deleted a record by mistake.

The third is simplicity. Someone who does not see unnecessary screens works faster; limiting permissions also simplifies the interface.

Typical roles and what they see

Four roles are enough for most clinics to start with.

Clinic owner

All modules and reports. This is usually the only role that can change permission settings.

Doctor

The clinical record, treatment plan and appointments of their own patients. On the finance side, visibility limited to their own transactions is usually enough.

Front desk / reception

Appointments, patient registration and payments. Access to clinical notes is usually not needed and is best left closed.

Assistant / support staff

Appointment viewing and limited patient information. Write access is limited to the fields the job requires.

These four roles are a starting template; they change with each clinic’s own workflow. What matters is not the role’s name, but having in writing what that role can do on which screen.

Read, write and full control

Permissions are not on/off; they have three levels.

Setting permissions as "can access / cannot access" falls short in most clinics. Front desk staff need to see payment records but not delete them; a doctor needs to see appointments but may not need to change someone else’s.

That is why three levels per module work better: read, write and full control. Read means seeing the information, write means adding and editing records, and full control covers deleting and changing settings.

In Clineo the permission matrix works on this logic; each role has a default, and exceptions can be set per person on top of it. We explain the details on the security page.

Some records should be hidden by role

Especially in psychology and psychiatry.

Not all clinical records are equally sensitive. Therapy session notes, psychiatric assessments and similar records should not be open even to the clinic’s other staff. Beyond confidentiality, this is a professional requirement.

In practice, what needs to be set up is this: appointment and payment information is visible at the front desk, while the content of a session note stays only with the specialist who ran that session. Seeing that a patient file exists and reading its content must be separated.

We describe a setup that supports this separation on the confidential session notes page.

Departing staff and the audit trail

The two most often skipped steps.

The most forgotten side of permissions is offboarding. If a departing person’s access is not closed the same day, the risk quietly continues; in most clinics this step is noticed months later.

Close it the same day

Deactivating the account on the day someone leaves should become a standard step.

Don’t delete the account, deactivate it

If the account is deleted, the trail of what that person did in the past may be lost too. Deactivating both cuts access and preserves the record.

Change shared passwords

If there is a shared password, it should be changed. The real solution is not to use shared passwords at all.

Check the audit trail

If it is recorded who opened sensitive records and when, the period before departure can be reviewed.

FAQ

Most asked about this topic

Ask in the demo
Isn’t setting permissions overkill for a small clinic?
Even in a two-person clinic users should be separate. There may be few roles, but using a shared account is a problem at any size.
Should a doctor see patients other than their own?
It depends on how the clinic works. If patients see more than one doctor, visibility is needed; if not, limiting it is better.
Is a history of permission changes kept?
In systems that keep an audit log, permission changes are recorded too. That is the only answer to the later question "who opened this?".
Is role-based access mandatory under KVKK?
KVKK (Turkey’s data protection law) expects access to be limited to what the job requires and technical measures to be taken. Role-based permissions are the most common way to meet that expectation.

If you’d like to try it

Move your clinic onto one dashboard.

Try it free for 14 days, with your own patients, in your own way.