The five workspace responsibilities
The owner holds the highest organization authority. Administrators can manage the practice and team within defined limits. Clinicians use the clinical workflow. Staff support scheduling and patient context. Billing and coding users work in the relevant administrative areas.
Exact permissions are enforced by the product and may evolve as capabilities are added. Before assigning a role, the workspace owner should verify what that role can currently view or change and compare it with the person's job.
Apply least privilege in ordinary work
Least privilege reduces both accidental exposure and the impact of a compromised account. It also makes the audit history easier to interpret because each action is associated with the user expected to perform it.
- Do not share accounts, passwords, email codes, or browser sessions.
- Use clinician access only for people who perform the clinical workflow.
- Do not grant administrator access merely to solve a one-time support issue.
- Reassess access when a person changes role, location, or employment status.
- Suspend or remove access promptly through the approved offboarding process.
What audit history can tell you
Porvio records material workspace events such as membership invitations, invitation acceptance, role changes, suspension, and selected clinical or administrative actions. Audit entries can identify the actor, time, action, resource, result, and limited metadata needed to understand the event.
An audit entry is evidence that the system recorded an event. It does not prove that the action was clinically correct, legally authorized, or noticed by the right person. The organization still needs policies, monitoring, incident response, and periodic review.
Create a practical access-review routine
- 01
Monthly
Check pending invitations, inactive accounts, unexpected role changes, and temporary access that should have ended.
- 02
On every workforce change
Update or suspend access immediately, then verify the event appears as expected.
- 03
After a suspected incident
Preserve relevant evidence, follow the practice's incident process, review audit information, and contact authorized support without sending unnecessary patient information.
- 04
At least annually
Reconfirm that each role and administrative responsibility still matches policy and current product behavior.