Running a practice on it · 1 of 4
Who sees what
Job titles do not grant anything. What someone can do is set per person, what they can see is bounded by the practice, and the defaults start open.
Two different questions hide inside who sees what, and Mesio answers them differently. What somebody can do is set person by person. What somebody can see is bounded by the practice.
Job titles do not grant anything
You pick a role when you invite someone, and it fills in a sensible starting set of permissions. After that the role is a label. What is enforced is the individual switches on that person.
That is why a practice manager and a hygienist can each be an administrator, and why a dentist you brought in for two days a week can have exactly the access you meant rather than everything a dentist usually gets.
The switches that matter
- Signing a note requires both being the provider on that visit and holding the signing permission. Being an owner does not let you sign someone else's note.
- Dictating is separate from note-writing. A hygienist can chart perio by voice without having access to write notes.
- Perio charting is its own permission, so it can be granted to the people who actually chart.
- Changing a fee is an owner or administrator act. Fees decide what patients are quoted, so editing them by hand is deliberately not something any team member can do.
What everyone in the practice can see
Being straightforward about this, because it is the question an owner should ask.
| Action | Who |
|---|---|
| Open any note in the practice | Anyone with a login there |
| Sign a note | The provider on that visit, and holding the signing permission |
| Dictate and chart perio | Anyone granted it — separate from note access |
| Change a fee | Owner or administrator only |
| Manage people | Administrator or owner |
| Integrations, locations, the agreement | Owner only |
Today, anyone with a login at your practice can open any note in that practice. Access is scoped by what people can do, not yet by what they can read. Nobody outside your practice can see any of it, and a practice is a hard boundary.
In other words, Mesio currently matches the boundary your practice management system already draws, rather than drawing a tighter one inside it. Narrowing read access so that front-desk roles do not see clinical note content is work in progress and is the next thing to land here.
The defaults are permissive. New members start with most permissions on, because that matches how the product behaved before per-person permissions existed. A team you never tightened is an open team. Ten minutes on the people list is worth it, and the person to start with is whoever should not be signing.
Owner is deliberately hard to get
There is a ladder. Members do the work, administrators manage people, and owners additionally control integrations, locations, the agreement and ownership itself.
Ownership is never handed out by picking a role, it is always an explicit act, and the last owner of a practice cannot be removed.
The defaults are permissive — start with whoever should not be signing.