Skip to main content
What a person can do in a dental clinic comes from three things, all set on the Team screens (see Team):
  1. Role: Owner, Administrator or Member. A role is a template: it includes a few permissions and a few extra powers over the team.
  2. Permissions: the actions and information the person can use, granted one by one.
  3. Locations and warehouses: the sites where those permissions apply.
Permissions are not inherited from role names. An Owner does not see inventory, orders, approvals, deliveries or reports until someone ticks those permissions for them, often on their own page. Always check the permission list, not the role.

How access is decided

A person’s effective permissions are:
  • the permissions their role includes, plus
  • the permissions granted to them on the Team screens, plus
  • the permissions that a granted permission includes: inventory.adjust (Adjust and count stock) includes inventory.receive, inventory.consume and inventory.transfer.
muveya checks the effective permissions and the site access on the server, for every request. The console hides what you cannot use, but hiding is only a convenience: if you reach a screen anyway, the server refuses the action (Your account does not have permission for this action.), returns the item as not found, or leaves out the information you cannot see. Changes to permissions and site access apply from the person’s next action. They do not need to sign in again.

Role templates

  • The person who creates a dental clinic is its first Owner, with access to all locations and warehouses.
  • Nobody can be invited as Owner: ownership is transferred. A clinic always keeps at least one active owner.
  • Only an owner changes roles, and only between Administrator and Member.
  • Starting a catalog CSV import or export requires the Owner or Administrator role; catalog.manage alone is not enough, even though the console shows the buttons to members who hold it.
  • No role includes any inventory, orders, approvals, delivery, report, cost, order value or patient reference permission.

Permission catalog

These are all 26 permissions. The label is what the Team screens show.

Catalog

Inventory

Orders

Approvals

Fulfillment (deliveries)

Any of these six permissions also lets the person see all orders of their locations.

Reports and audit

Administration

What each console area needs

Account security (console.muveya.com/account/security) needs no permission. Screens that say you lack a permission:
The Dispatch order button is on the picking screen, which requires fulfillment.pick. Give Prepare orders to anyone who dispatches. Without inventory.read, Stock alerts, Counts and count campaigns show only their loading message.

Site scope

Each person has one setting for locations and one for warehouses: Location access applies to orders, approvals and custody. Warehouse access applies to stock. The permission decides what a person can do; the site access decides where. API keys are not people: they always reach every site of the clinic.

What muveya hides without permission

muveya removes this information on the server before it reaches the console, the API or MCP. The field is absent, not blank. Some places never show these values to anyone: custody history, pick lists, stock alerts, analytics reports and exports, and WhatsApp messages. API keys can never read order values or patient references. See Security and privacy.

API scopes and permissions

API keys carry scopes, written with a colon. Each scope maps to one permission:
  • There is no scope for orders.value.read or orders.patient_ref.read: those values are always removed for API keys.
  • There are no write scopes and no wildcard.
  • The console has no screen to create or revoke API keys yet; write to team@muveya.com. See API scopes.

Common setups

These combinations work with how muveya checks access today. Adjust the sites to each person. An approver cannot approve their own order, and an approval rule’s step can require an extra permission from its approvers. See Approval policy.

Team

Change roles, permissions and site access.

Security and privacy

Isolation, redaction and audit.

Locations

The sites you assign to people.

API scopes

Scopes for API keys.