Mesio.Learn

Running a practice on it · 1 of 4

Who sees what

Job titles do not grant anything. What someone can do is set per person, what they can see is bounded by the practice, and the defaults start open.

Two different questions hide inside who sees what, and Mesio answers them differently. What somebody can do is set person by person. What somebody can see is bounded by the practice.

Job titles do not grant anything

You pick a role when you invite someone, and it fills in a sensible starting set of permissions. After that the role is a label. What is enforced is the individual switches on that person.

That is why a practice manager and a hygienist can each be an administrator, and why a dentist you brought in for two days a week can have exactly the access you meant rather than everything a dentist usually gets.

The switches that matter

What everyone in the practice can see

Being straightforward about this, because it is the question an owner should ask.

ActionWho
Open any note in the practiceAnyone with a login there
Sign a noteThe provider on that visit, and holding the signing permission
Dictate and chart perioAnyone granted it — separate from note access
Change a feeOwner or administrator only
Manage peopleAdministrator or owner
Integrations, locations, the agreementOwner only
Reads are practice-wide today; writes are scoped per person. Narrower read access, so front-desk roles do not see clinical note content, is in progress.

Today, anyone with a login at your practice can open any note in that practice. Access is scoped by what people can do, not yet by what they can read. Nobody outside your practice can see any of it, and a practice is a hard boundary.

In other words, Mesio currently matches the boundary your practice management system already draws, rather than drawing a tighter one inside it. Narrowing read access so that front-desk roles do not see clinical note content is work in progress and is the next thing to land here.

The defaults are permissive. New members start with most permissions on, because that matches how the product behaved before per-person permissions existed. A team you never tightened is an open team. Ten minutes on the people list is worth it, and the person to start with is whoever should not be signing.

Owner is deliberately hard to get

There is a ladder. Members do the work, administrators manage people, and owners additionally control integrations, locations, the agreement and ownership itself.

Ownership is never handed out by picking a role, it is always an explicit act, and the last owner of a practice cannot be removed.

Do it in MesioReview who can do what

The defaults are permissive — start with whoever should not be signing.