Skip to main content
Sigma HMIS uses role-based access control to ensure staff only see and do what their job requires. Assign roles carefully — access to billing and claims data is sensitive, and the wrong assignment can expose financial records to staff who do not need them or block staff from completing their work.

Available Roles

Each role is scoped to the minimum access level its job function requires. Review the breakdown below before assigning roles to your team.

Admin

Full access to all modules, settings, user management, and reports. Typically assigned to the clinic manager or owner. Admins can invite and deactivate users, modify clinic settings, and view all financial data.

Billing Staff

Can create and confirm invoices and manage patient records. Cannot submit claims, view claim statuses, or access financial summaries and revenue reports.

Claims Staff

Can prepare and submit insurance claims and view claim statuses. Has read-only access to invoices for reference when building claims. Cannot confirm invoices or record payments.

Finance

Can record and reconcile payments, view revenue reports, and work aged-debt lists. Has read-only access to invoices and claims for reconciliation purposes. Cannot modify billing or claims records.

Reception

Can register patients and create draft invoices. Cannot confirm invoices, access claims, or view any payment or financial data.

Clinician

Can view patient encounters and attach service items to a visit record. Has no access to billing, claims, or financial data of any kind.

Inviting Team Members

Invite staff as soon as your clinic details and locations are configured so that they are ready to work on the day you go live.
1

Open the Team settings

Navigate to Settings → Team. You will see a list of all active and pending users in your workspace.
2

Start an invitation

Click Invite Member to open the invitation form.
3

Enter the staff member's work email

Use their official work email address. Invitations sent to personal addresses create account ownership complications later.
4

Select their role

Choose the role that matches their job function from the dropdown. See the role descriptions above if you are unsure.
5

Send the invitation

Click Send Invite. The staff member receives an email prompting them to set a password and activate their account. The invitation link expires after 48 hours — resend from the Team page if needed.

Managing Access

Your active user list should reflect your current team at all times. Regular access reviews reduce the risk of former staff retaining access to sensitive billing and financial data.
  • Change a role — Select any active user in Settings → Team and choose a new role from the dropdown. The change takes effect immediately on their next action.
  • Deactivate an account — When a staff member leaves, deactivate their account immediately. Deactivated accounts cannot log in, but their activity history is retained for auditing purposes.
  • Review active users — Run a quarterly check of your active user list. Remove or downgrade anyone whose role has changed or who is no longer with the clinic.
Each staff member must use their own individual account. Shared credentials make it impossible to audit who created or modified a billing or claims record. In the event of a dispute or a payer audit, traceability to a named user is essential.
Follow the principle of least privilege — assign the narrowest role that allows a staff member to complete their job. Promote to broader roles only when there is a clear operational need. It is easier to grant additional access than to explain why a restricted record was accessed.

Workspace Setup

Configure clinic details, locations, and operational preferences before inviting your team.

Subscription

Understand your plan, manage billing cycles, and handle cancellations.