Managing users and roles
Step 1 — Open the Users page
Open Settings → Users (/settings/users). This page is admin-only: you need a role that carries the Manage users permission (Admin or Super admin) to see it — anyone else lands on an "Admins only" notice instead. The roster lists every login account in your organization with its name, email, and role, plus a count of total users. A "Must change password" badge marks accounts that still hold a temporary password, and a "Deactivated" badge marks accounts whose access has been turned off — your at-a-glance view of who can sign in and who hasn't finished setting up.
Step 2 — Understand the six roles
Mindbill has six roles, each a fixed bundle of permissions — assign the narrowest one that lets a person do their job. Super admin: the MindBill platform owner, full access everywhere. Admin: full access inside your organization, including settings and user management. Manager: the billing-team lead — all billing operations plus reports, exports, channel configuration, and task assignment, but not user management or org settings. Biller: the operational core — create, edit, and send bills, post EOR payments, assign tasks, and view reports. Member: a legacy role kept identical to Biller so older accounts never lose access. Viewer: read-only, for physicians or auditors who need to see bills and reports without changing anything.
Step 3 — Add a teammate
Click Add user, then enter the teammate's email and full name and pick a role. An Admin can assign Admin, Manager, Biller, Member, or Viewer; only a Super admin can assign the Super admin role. On save, Mindbill creates the account and shows a one-time banner with a temporary password — copy it and relay it to the teammate securely, because it is shown only once and is never stored in plaintext. The banner also offers a single-use invite link (it expires in seven days, and is emailed automatically once email delivery is enabled) so the new user can set their own password instead. Either way you never handle their permanent credentials, and the account is flagged Must change password until they replace the temporary one at first login.
Step 4 — Change roles, reset passwords, and deactivate
Each user row has a menu (the … button) for ongoing management. Set role switches the account to any role you're allowed to assign, taking effect immediately. Reset password mints a fresh temporary password, shown once in the same banner — use it when a teammate is locked out. Deactivate revokes an account's access without deleting it (the row dims and shows a Deactivated badge), and Reactivate restores it. A few guardrails are enforced for safety: you can't change your own role or deactivate yourself, and a plain Admin can't modify a Super admin account. The server re-checks every one of these actions, so the menu reflects exactly what you're permitted to do.
A billing system holds protected health information and the keys to a practice's cash, so who can do what matters. Mindbill's user controls are role-based: every action is checked against a specific permission, and each teammate is assigned one of six roles that grants the right slice of those permissions. New accounts are created by an admin — there are no self-serve signups — and the new user signs in with a one-time temporary password or invite link that they must replace on first login. This walkthrough covers the Users page, the six roles, adding a teammate, and the day-to-day actions for changing roles, resetting passwords, and deactivating accounts.