Skip to main content

Manage user permissions

warning

RehabAlpha is still under active development. It is not yet HIPAA compliant and should only be used with dummy data.

Set a member's access level, organization permissions, and facility profiles to control what they can view or change after signing in. You can configure access before inviting the member or update it later as their responsibilities change.

Before you start​

  • You need Owner or Admin access to manage another member's permissions. Only an Owner can change another Owner's permissions or assign Owner access.
  • The member record must already exist. The member does not need a linked user account.
  • You can review your own permissions, but you cannot change them.

Understand the relationship between members and users​

A member record stores information about someone who belongs to the organization, such as a therapist, physician, or associate.

Accepting an invitation links the member to a user account so they can sign in to the organization.

The member's Role—Therapist, Physician, or Associate—controls how that person appears in clinical and operational workflows. A role does not grant application access. The user's access level, organization permissions, and facility profiles determine what they can view or change.

New members start with Custom access, no organization Create, Update, or Delete permissions, and no facility assignments. Read is off for Payor arrangements, Fee schedules, Billing providers, and Timesheets. Patients belong to facilities and cannot be users.

Review and update a user's permissions​

  1. Open People, then select All staff.
  2. Select the member.
  3. Open Settings.
  4. Under User permissions, choose an Access level using the descriptions below.
  5. If you choose Custom access, set Organization permissions and Facility access.
  6. Click Save in the User permissions section. Use Cancel to discard unsaved changes.

Choose an access level​

  • Owner has full organization and facility access, including assigning Owner access and deleting the organization.
  • Admin has full operational access across all facilities but cannot assign or modify an Owner or delete the organization.
  • Custom access uses individual organization permissions and facility profiles.

More than one user can be an Owner. RehabAlpha protects the last active Owner whose member record is linked to a user account from losing Owner access, being suspended, or being unlinked.

Changing access levels

Saving a change from Custom access to Owner or Admin discards the saved custom organization permissions and facility assignments. If you later return the member to Custom access, configure those permissions and assignments again before saving. All four permissions for Payor arrangements, Fee schedules, Billing providers, and Timesheets start unchecked when changing an existing Owner or Admin to Custom access.

Set custom organization permissions​

For Custom access, the Organization permissions table covers:

  • Payors
  • Payor arrangements
  • Fee schedules
  • Billing providers
  • Physicians
  • Therapists
  • Associates
  • Timesheets
  • Facilities

Read access is included for the organization resources other than Payor arrangements, Fee schedules, Billing providers, Timesheets, and Facilities. Facility read access comes from the facility assignments described below. Select Create, Update, or Delete for each resource as needed.

For Payor arrangements, Fee schedules, and Billing providers, enable Read before granting Create, Update, or Delete. Read alone lets the member view the resource without changing it. Each Read permission applies across the organization, even when the member has access to only one facility. Owners and Admins always have access to these resources while their membership is active.

You can grant each Read permission independently. Viewing a payor arrangement does not require fee schedule Read, but creating or editing an arrangement that uses Custom fee schedule does. Creating or editing an arrangement that targets specific billing providers requires billing provider Read. Arrangements that apply to all billing providers do not require it.

To turn any of these Read permissions off, first clear that resource's Create, Update, and Delete permissions and change or remove any Facility manager, Biller, or Auditor assignments. The form explains which permissions and assignments still require Read.

Without billing provider Read, clinical staff can still see provider names saved on admissions they can access. Saved episodes retain their provider when the payor stays the same; new episodes and payor changes use the facility's default rules. Manually selecting or clearing a provider requires Read. Configuring facility defaults also requires billing provider Read, Update for Facilities, and access to that facility.

For Timesheets, select Read to let the user view other members' entries at custom work locations and with No location, even when no facilities are assigned to them. Entries at facilities or service locations also require access to the associated facility. A user with Selected facilities access therefore sees entries at those facilities and their service locations, plus custom locations and entries with No location.

The Timesheets row applies only to other members' entries. Leaving all four boxes unchecked still allows the user to view their own timesheet and modify it as permitted by their timesheet settings. Select the help icon beside Timesheets for this explanation in the app.

Each Timesheets permission is independent. Select Read alone for review access, Create to allow new entries, Read and Update for corrections, or Read and Delete for removal. Create alone allows new entries without displaying existing ones. See Configure timesheets for the available combinations and facility restrictions.

Creating facilities requires both All facilities access and Create permission in the Facilities row. These organization permissions do not grant the ability to manage user access; that requires Owner or Admin access.

Assign facility access​

For Custom access, choose one approach under Facility access:

  • Select All facilities, then choose a Facility profile that applies to every current and future facility.
  • Select Selected facilities, choose the facilities in Facilities, then assign a profile to each one. Selecting no facilities gives the user no facility access.

Each assigned facility has one profile for that user. The Facilities row in the organization permissions table separately controls whether the user can create, update, or delete the facility record itself. Updating or deleting a facility also requires access to that facility.

Available profiles are:

ProfileAccess
Facility managerFull access to data and workflows inside the facility.
Director of rehabCan manage clinical records, events, service locations, planner settings, and signature workflows and can sign documents, without access to facility financial data.
BillerCan read core and financial data and manage billing workflows and reimbursement controls. Does not grant clinical or coverage management.
AuditorCan read core and financial data without editing.
TherapistCan create, update, and delete therapy cases and their clinical documents only in the disciplines listed in the therapist's licenses. Can manage eligible events and sign eligible clinical documents, without access to facility financial data or signature management.
Therapy assistantCan create, update, and delete treatments only in licensed disciplines. Can manage patients, coverages, events, and uploaded files and sign eligible clinical documents with the same permissions as Therapist. Cannot create, update, or delete admissions, cases, evaluations, re-evaluations, discharges, or progress reports.
Physician / Nurse practitionerCan read clinical data and sign clinical documents, without editing them or accessing facility financial data or signature management.

Facility manager, Biller, and Auditor require Read for Payor arrangements, Fee schedules, and Billing providers. These profiles remain unavailable until all three permissions are enabled. The form identifies any missing permission beside the profile selector. The clinical profiles do not require these Read permissions.

Choose a profile explicitly for each newly selected facility and when first configuring All facilities. There is no default profile. Removing and re-adding a facility requires choosing its profile again.

When switching between All facilities and Selected facilities, the form keeps compatible unsaved profile choices. If a retained choice requires a Read permission that is now off, the form clears that choice and explains why. Choose an available profile before saving.

Switching to Selected facilities clears Create permission for Facilities. If you later select All facilities, select Create again if the user needs it.

Profiles that include signing still require an eligible signer and a document ready for signature. For therapists, check the license requirements; a signing profile alone is not enough.

With the Therapist or Therapy assistant facility profile, you can view cases in other disciplines and download their clinical documents, but cannot change or sign them. For example, a therapist with only PT licenses cannot create an OT case or change an OT evaluation, re-evaluation, progress report, treatment, or discharge. With Therapist access, changing a case's discipline requires a license for both its current and new disciplines. If your permissions or licenses change while a clinical form is open, editing and draft autosave stop until you have the required access again.

Choose Therapy assistant under Facility access while keeping the member's Role set to Therapist. This profile allows treatment changes, including scheduling and therapist assignment, while the case and other clinical documents remain read-only. It retains Therapist signing permissions: signing an eligible document does not require permission to edit its contents. Existing license and signer requirements still apply. Therapy assistants have the same access to patient details, patient settings, coverages, events, and uploaded files as Therapists, without facility financial access or signature management.

Saving, rescheduling, or deleting a treatment can automatically create, adjust, or remove scheduled progress-report and re-evaluation drafts. These automatic updates continue for Therapy assistants, even though they cannot edit those documents directly.

This permission check uses the disciplines in your licenses, regardless of state or license dates; signing has additional license requirements. Without therapist licenses, the Therapist profile cannot create or change therapy cases, and the Therapy assistant profile cannot create or change treatments. Owner, Admin, Facility manager, and Director of rehab access retain their existing case permissions. Events and uploaded files keep their existing permissions.

Set permissions before inviting a user​

Use this sequence when you want the user to have the right access the moment they accept the invitation.

  1. Create the member record with Invite user turned off, then click Save.
  2. Open People, select All staff, and open the member.
  3. Open Settings.
  4. Set the correct access level, organization permissions, and facility profiles.
  5. Save the permissions.
  6. Under User settings, click Invite user, confirm Email invitation to, and click Send invitation. For invitation details, follow the invite users guide.

When the user accepts the invitation, they join the organization with the permissions you already configured.

You should know​

  • Owners and Admins can read, create, update, and delete other members' timesheet entries. To grant this access to a Custom user, configure their timesheet permissions. Each permission covers custom locations and entries with No location; facility and service-location entries also require facility access. Reports → Labor and Reports → PBJ still require Owner or Admin access. Use timesheets to enter and correct hours.
  • A therapist's availability controls scheduling coverage. Assign facility access separately under User permissions.
  • Events and notices are not in the organization permissions table. Facility event changes depend on the user's facility profile, and notices follow the facilities the user can access. Users can create and manage their own personal events with no facility or patients when they are the only member included.
  • Review access when someone's responsibilities change. Use Owner access for organization ownership, Admin access for organization and user administration, and Custom access for specific responsibilities.

Frequently asked questions​

Why can't I change a member's permissions?​

You cannot change your own permissions. To change another member's permissions, you need Owner or Admin access. If that member is an Owner, only another Owner can make the change.

Can users update their own settings?​

Therapists can update their own availability and planner preferences without Update permission for Therapists. Users still need the matching Update permission for Physicians, Therapists, or Associates to edit their own member details. Only Owners and Admins can change Timesheet settings, including their own. These settings control allowed classifications, manual entries and timestamp changes, clock-in defaults, sign-in prompts, and whether organization screens require the member to be clocked in.

How do I temporarily stop a user's access?​

Open the member's Settings and click Suspend access under User settings. Suspension blocks organization access while preserving the user link, member record, and configured permissions. Click Reactivate access when the user can return; a linked user does not need a new invitation.

The same Owner and Admin limits apply: you cannot suspend yourself, and only an Owner can suspend another Owner.

Can a user leave the organization?​

Yes. Users can open their own member's Settings and click Unlink user under User settings. Unlinking removes the account's connection to the organization and preserves the member record. Rejoining requires a new invitation.

Owners and Admins can unlink other users, but only an Owner can unlink another Owner. Before the last active linked Owner leaves, another Owner must have active access through a linked user account. Assigning Owner access to an unlinked member is not enough.