Team and security
Team
Administrators only. This is where you see who has access and with what role, and invite new people. The full procedure is in Invite your team.
Review this list periodically. Accounts left active after someone leaves the clinic are the most common security lapse there is, and in a dashboard holding patient phone numbers that matters.
When you remove someone
They lose access immediately for any new action. An already-open session can stay alive for up to an hour. If the reason is sensitive and you need an immediate cut, write to us.
Security
This screen belongs to each user, not to the administrator: everyone manages their own account.
Two-factor authentication
A temporary code, on top of your password, generated by an app on your phone (Google Authenticator, Authy, 1Password — whichever you prefer). It's optional, and strongly recommended at least for administrators.
To turn it on:
- Your email must be verified. If it isn't, the flow asks you to do it.
- You may be asked to re-enter your password, since this is a sensitive operation.
- Scan the code with your app.
- Enter the six-digit code to confirm.
From then on, every sign-in asks for the code.
Keep your backup. If you lose the phone with the app and have no other way to generate the code, you cannot get back in on your own. Recovery requires writing to us and verifying your identity outside the system. It is not instant.
We don't offer SMS as a second factor: it's the easiest method to intercept and we'd rather not present it as an option.
Passwords
One long, unique password per person. A password manager solves this better than any rule we could write here.
Never share an account between people. Beyond the risk, it makes it impossible to know who made which change.