Browse documentation
User Roles and Permissions
Reading time: 4 minutes
viggoVet uses a flexible permission system with predefined roles and granular individual permissions for each staff member. Roles provide a baseline, and then each user can have more or less access than their assigned role.
How permissions work
The system operates on two layers:
Roles. Predefined permission templates that come with the system (Admin, Veterinary Doctor, Receptionist, Nurse, Technician, etc.). You cannot add new roles, but you can edit the permissions within each role.
Individual permissions. Specific access rights that override the role baseline. You can grant extra permissions or remove existing ones for any individual user.
A staff member’s effective access is their role’s permissions plus or minus any individual overrides.
Note: Roles are fixed in the system. You cannot create new ones. Instead, customize access by editing a role’s permissions (which affects everyone with that role) or by adjusting individual user permissions (which affects only that person).
Permission categories
Permissions fall into four groups:
Category | Controls |
|---|---|
Read | Viewing data |
Write | Creating, editing, deleting |
Administrative | System configuration and user management |
Financial | Financial data and reports |
Permission risk flags
Some permissions carry risk indicators to help administrators make informed decisions:
Dangerous (red). Grants access to critical functions that could affect system security or data integrity. Examples: Delete user, Manage staff permissions, Delete invoice, and most financial reporting permissions.
Worrisome (yellow). Affects system configuration or business operations at a lower risk level. Example: update company details.
Standard. Regular operational permissions without special flags.
Warning: Grant dangerous (red) permissions only to trusted senior staff. These allow actions like deleting users, managing other people’s permissions, and accessing sensitive financial reports. The permission interface displays colored labels so you can see at a glance which grants carry elevated risk.
User Permissions Sample
Setting up staff and roles
You manage roles and staff through Configuration > Staff and Roles.
Editing role permissions
Roles are listed in the Roles tab. Click the edit icon on any role to modify its included permissions. Changes to a role affect all users assigned to that role (unless they have individual overrides). Roles serve as templates, instead of granting dozens of individual permissions to each new hire, assign them a role.
Adding or editing staff
In the Staffs tab:
- Click Add to create a new staff member, or click the edit icon next to an existing one.
- Enter the staff member’s information.
- Assign one or more roles.
- Click Save.
To adjust individual permissions beyond what the roles provide, click the Manage Permissions icon in the Actions column. The permissions modal shows every available permission with checkboxes. Use the search field to filter the list. Dangerous and worrisome permissions display with their colored labels.
Tip: Start with roles for the broad access level, then use individual permissions for exceptions. For example, a receptionist role might not include: Read financial reports, but you might grant it individually to your senior receptionist who helps with monthly reconciliation.
Common permission patterns
While every clinic is different, most practices create roles along these lines:
Practice owner / Senior admin. Full access including dangerous permissions. Complete system control.
Clinical staff. Patient records, medical notes, prescriptions, diagnostics, lab results. No financial or administrative permissions.
Front desk. Appointment scheduling, client registration, check-in/checkout, basic invoicing, payment processing. No access to detailed financial reports or system configuration.
Financial operations. Invoice management, expense tracking, payment processing, and financial reporting. May include or exclude dangerous financial permissions based on seniority.
Inventory management. Purchase orders, stock adjustments, item management, receiving. May include expense management depending on your organizational structure.
How permissions are enforced
viggoVet checks permissions at every level:
- Interface. Buttons, menu items, and page sections you don’t have access to are hidden from view
- Navigation. Attempting to visit a restricted page redirects you to an access denied message
- Data. All operations verify your permissions before executing, even at the API level
Password management
Administrators can reset a staff member’s password through Configurations > Staff and Roles > Staffs. Click the password reset icon in the Actions column. The system generates a temporary password, provide it securely to the staff member, who should change it on their next login.
Security best practices
- Least privilege. Grant only the permissions each person needs for their job. Avoid blanket admin access.
- Individual accounts. Never share login credentials. Each staff member needs their own account for proper audit trails.
- Regular audits. Periodically review staff permissions, especially when someone changes roles or leaves the practice.
- Document your roles. Keep an internal record of which roles exist and what permissions each includes. This makes onboarding new staff consistent.
Multi-clinic permissions
For practices with multiple locations, permissions can be scoped to specific clinics or granted across all locations. Staff who work at multiple clinics get appropriate access at each one, while single-location staff are restricted to their clinic’s data.