Chapter 3: User Roles & Permissions
Chapter Overview
What You'll Learn:
- Platform roles vs agency roles
- What each standard agency role can do (aligned with current permissions)
- Surveyor (read-only chart review)
- Custom Role Builder and plan gating
- Per-branch role assignment and custom permission overrides
Time to Complete: 15–20 minutes
Who Should Read This: Agency Administrators and anyone who manages staff access
Prerequisites: Chapter 1, Chapter 2
Text-only. Permission names in the product use forms like
patient:create(resource:action), not olderCREATE_PATIENTstyle labels in outdated docs.
3.1 Roles vs Permissions
| Concept | Meaning |
|---|---|
| Role | A job package with a set of permissions (e.g. Biller) |
| Permission | One allowed action (e.g. generate a claim) |
| User | Person who gets a role (often per branch) |
Where to manage (Agency Administrator):
- Settings → User Management — create users, assign branch + role
- Settings → Roles & Permissions — view standard roles; create custom roles if your plan includes Custom Role Builder
Billing-only agencies typically do not show User Management / Roles in Settings the same way — access is managed through Betasky onboarding for that product mode.
3.2 Platform Roles (Betasky staff only)
| Role | Purpose |
|---|---|
| Super Administrator | Full platform management |
| Sales & Onboarding | Agency setup and onboarding |
| Support Engineer | Support access |
Agency admins cannot create or assign these roles.
3.3 Standard Agency Roles
| Role | Typical job |
|---|---|
| Agency Administrator | Owner / administrator |
| Clinical Manager | DON / clinical director |
| Scheduler | Scheduling coordinator |
| Biller | Revenue cycle / claims |
| Intake Coordinator | Admissions |
| RN Case Manager | RN care coordination |
| LPN / LVN | Licensed practical nurse |
| Therapist | PT / OT / SLP |
| Home Health Aide | HHA / CNA |
| Surveyor | External chart review (grant-based, read-only) |
Plus custom roles when Custom Role Builder is enabled on your plan.
3.4 What Each Role Can Do (current product)
Summaries below match seeded permissions. Exact menus still depend on agency mode (sandbox / billing-only) and feature flags.
Agency Administrator
Full agency control: users and roles, branches, payers, physicians, pharmacies, visit types, fee/service rates, patients and clinical workflows, scheduling, QA, claims, prior auth, payments, OASIS, reports, payroll, communications, EVV, support tickets, go-live request.
Clinical Manager
Clinical oversight: view/edit clinical patient data, care orders (view/edit), medications, schedule view, QA review/approve, clinician list, documentation, reports, SMS/fax/inbox as permitted.
Does not (by default seed): create patients, create care orders, create visits, or manage OASIS submissions the way a Biller/Admin might.
Scheduler
Patients (non-clinical-focused access), create/edit/cancel visits, compliance-related scheduling tasks, communications as permitted.
Does not (by default): manage care-order create the way Intake does.
Biller
Patients (billing context), generate/manage claims, fee schedules, prior authorizations, payment posting, OASIS submission tools, reports, payroll, EVV exceptions, communications usage/view as seeded.
Broader than “claims only” — includes several revenue-adjacent modules.
Intake Coordinator
Create/edit patient demographics, create care orders, non-admit flows.
Does not (by default): manage pharmacies/physicians setup.
RN Case Manager
Assigned/clinical patient access, care order view, medications, documentation, My Schedules, create/edit/cancel visits, communications view.
Does not (by default): create care orders or create patients agency-wide.
LPN / LVN
Clinical patient access, medications, documentation, My Schedules, visits create/edit, communications view.
Therapist
Clinical patient access, care order view, documentation, My Schedules, visits, communications view. Discipline (PT/OT/SLP) is assigned on the user/branch row.
Home Health Aide
Restricted patient view, HHA documentation, My Schedules, visits, communications view.
Surveyor
Read-only, grant-scoped access to selected patient charts (patient:view, document:view, care-order:view). Uses the Surveyor app experience (not the normal full SideNav). Agency Admin grants access from User Management (Grant Access). Optional medication view via grant settings.
There is no separate seeded role named “QA Reviewer.” QA work uses permissions such as view/approve on roles like Clinical Manager or Agency Administrator.
3.5 Custom Role Builder
Path: Settings → Roles & Permissions → + Create Custom Role
| Topic | Current product |
|---|---|
| Feature name | Custom Role Builder (custom_role_builder) |
| Plans that include it | Pro Tier and Enterprise Tier (not Growth; not Billing Essentials) |
| Without the feature | Upgrade message instead of full custom-role control |
| Editor | Name, description, status, permission checkboxes grouped by area (patient, billing, qa, evv, communications, payroll, …) |
There is no separate “test this role” wizard step — assign the role to a user in User Management to validate.
3.6 Per-Branch Roles and Overrides
If Multi-Branch Management is enabled:
- Open User Management → create or edit a user.
- Under Branch assignments, each row has Branch + Role (and Discipline when clinical).
- Optional Custom Permissions overlays can add/remove specific permissions for that user.
- The top-bar Branch switcher changes which branch context (and effective role) is active.
Surveyor assignments skip the normal custom-permissions tab and use grant access instead.
3.7 Inviting Users (related)
In User Management, Create New User always sends an email set-password invite (plus Resend Invite when needed). Invites are email-based, not SMS.
Tabs: Active Users / Inactive Users. Other actions can include compliance/credentials and remove-from-agency — see Chapter 8: User Management.
3.8 Best Practices
- Limit Agency Administrator to a small trusted set.
- Prefer Clinical Manager for QA oversight instead of inventing a “QA Reviewer” role unless you build a custom role carefully.
- Give Billers only what revenue staff need; remember the seeded Biller role is fairly broad.
- Use Surveyor + grants for external auditors — do not reuse Admin.
- On multi-branch agencies, assign the correct role per branch.
- Re-check access after switching to billing-only or after plan changes (Custom Role Builder gating).
3.9 Common Mistakes
- Assuming Clinical Manager can create patients/care orders/visits — seeded permissions are narrower.
- Looking for a QA Reviewer standard role — it does not exist.
- Expecting Custom Role Builder on Growth / Billing Essentials.
- Using outdated permission names like
CREATE_PATIENTin training materials — use the checkbox labels in Roles & Permissions. - Forgetting Surveyor needs Grant Access, not only a role checkbox.
3.10 Quick Checklist
- Know which standard role fits each staff member
- Agency Admin can open Roles & Permissions and User Management
- Multi-branch: roles assigned per branch
- Surveyor path understood if you use chart review grants
