Skip to main content
“It’s not on my screen” is the most common question we get, and it almost never has one answer. Four separate gates decide what you see, they are checked independently, and any one of them can hide a thing on its own.

The four gates, in the order they are applied

1

Your edition — does this module exist here at all?

A pharmacy has no consultation screen. A diagnostic centre has no ward. This is decided by the kind of business your workspace is, it is fixed when the workspace is created, and no upgrade adds a module your edition does not have. See The three editions.
2

Your plan — has this workspace paid for it?

Inside your edition, your subscription decides which capabilities are unlocked and how much capacity you get. A feature that is not on your plan usually still appears, as a locked card or an upgrade prompt, rather than vanishing. See Change your plan.
3

Your role — may you open this page?

Your role in this workspace decides which pages your sidebar offers. An owner sees everything the edition and plan allow; a cashier sees the till; a phlebotomist sees intake. A page you have no role for is not in your navigation and cannot be reached by typing its address either. See Roles.
4

Your permissions — may you personally do this?

On a page you can open, individual permissions decide which actions you may take: refund a sale, discount an invoice, void a payment, see a profit figure. Two people with the same job title can differ here. See Permissions.
Hospitals add a fifth filter on top: care areas, the statement of which departments the building actually runs. See Care areas.

The gates are not the same thing, and they do not substitute

This is the part worth reading twice. Upgrading a plan will never reveal a module your edition does not have. Giving someone a permission will never let them open a page their role excludes. Switching on a care area will never unlock a feature the plan does not include. They stack; they do not override each other.

Why can’t I see X?

Work down this table in order. The first row that matches is your answer.

Figures degrade, actions refuse

The product treats seeing and doing differently, on purpose.
  • A number you may not see is hidden, not zeroed. It renders as . A blank is honest; a 0 would be a lie you could act on.
  • An action you may not take is refused, and the refusal is recorded. You get a message saying so, and the attempt appears in the audit log — which is what lets an owner tell the difference between “nobody tried” and “somebody was blocked”.

Owners and managers

Owners bypass the permission gate entirely inside their own workspace: they can perform every act their edition and plan allow. Managers sit just below them and can administer staff, roles and permissions. Neither of them bypasses the edition gate, the plan gate, or the two-factor requirement on patient data. An owner who has not enrolled in two-factor in a workspace that requires it is blocked from patient records exactly like anyone else.

Enforcement is opt-in

Per-person permissions only start applying to someone once an owner or manager has actually configured them. Until then that person is governed by their role alone, and nothing is silently denied. That is why a newly invited colleague can often do more than you expected — the fix is to set their permissions, not to change their role.
Adding staff has a cost or a cap depending on your edition: Clinic & Hospital bills each billable seat, while Pharmacy and Diagnostics include their seats and block the next invite when the cap is reached. See Staff seats before you invite.

Invite a staff member

Send an invitation, pick a job title and set the role.

Two-factor on patient data

Why a workspace can require a second factor before records open.