Inviting users
You can bulk-invite from a CSV: Settings → Team → Bulk invite. Columns:
email,first_name,last_name,role.Assigning roles
| Role | Can do | Cannot do |
|---|---|---|
user | Upload, review, appeal, track — for claims in their assigned queue | See other users’ queues without assignment; change practice settings |
analyst | View dashboards and run reports on aggregated data | View individual PHI-bearing records |
support | Read-only access to assigned customer org | Modify any data; export PHI |
admin | Everything user can do, plus team management, settings, audit logs | Delete the practice |
| Billing admin | Plus billing/subscription management | — |
Managing access
Suspend a user (keep the account)
Suspend a user (keep the account)
Click Suspend. User can’t sign in; their historical actions remain audit-logged. Useful during investigations.
Force 2FA reset
Force 2FA reset
If a user loses their 2FA device, an admin can force a reset. The user must re-enroll on next sign-in. This is audit-logged.
Terminate sessions
Terminate sessions
Settings → Team → [user] → End all sessions kills every active session for that user. Use after suspicion of compromise.
Change assignment queues
Change assignment queues
Assign which denial queues (by payer, by provider, by denial type) each user sees by default.
Offboarding
Revoke access
Settings → Team → [user] → Remove. Active sessions terminated immediately; account marked
deleted.Audit trail retained
Their historical actions remain attributed in the audit log per HIPAA retention requirements (7 years), but the account itself is disabled.
SSO and SCIM
- SAML 2.0 SSO — supported for Okta, Azure AD, Google Workspace, any SAML IdP. See SSO / SAML.
- SCIM provisioning — planned for Q3 2026. Until then, use bulk invite + CSV for large teams.
Delegated signing (for appeals)
Practice admins can grant specific staff the authority to sign appeals on behalf of a provider:- Settings → Team → Signing delegations → Add
- Specify the delegator (provider), the delegate (staff member), and the time-scope.
- Every delegated signature is audit-logged with both identities.