Organization Feature
What a clinic workspace is, who it is for, and how roles and permissions work.
What the organization feature is
By default Medisa is a single-person tool: one doctor, one subscription, one quota, and records only their creator can open. An organization — called a clinic in the app — turns that into a shared workspace.
A clinic brings together three things that were previously per-doctor:
| Without a clinic | With a clinic | |
|---|---|---|
| Subscription | Each doctor subscribes separately | One subscription for the whole team |
| Billing | A separate invoice per doctor | One invoice to the clinic's billing email |
| Management | None — every account stands alone | Invite members, set roles, monitor usage |
What does not change is ownership of clinical data. Records stay with the doctor who created them; a clinic does not open their contents to other members automatically. The full rules are further down this page.
Who it is for
The feature is built for practices that pay for and manage several doctors at once.
| A good fit for | Why |
|---|---|
| Clinics with several practising doctors | One invoice, one place to set who may do what |
| Hospitals or units where doctors rotate | Seats can be revoked and reassigned without new accounts |
| Practices with a non-clinical admin handling billing | The Admin role separates team matters from clinical ones |
You do not need it if you practise alone, or if several doctors happen to share premises but subscribe and bill separately. In both cases the personal workspace is enough and simpler.
One account can hold both
Creating or joining a clinic does not remove your personal workspace. The two live side by side, and you pick the working context when you sign in. Your personal subscription is only paused while you hold an active clinic seat — its remaining days are kept intact.
Roles and permissions
A clinic has three roles: Owner, Admin, and Member.
| Action | Owner | Admin | Member |
|---|---|---|---|
| Use the product (record → EMR) | ✅ | ✅ | ✅ |
| Invite and remove members | ✅ | ✅ | ❌ |
| Buy and manage seats and billing | ✅ | ✅ | ❌ |
| Set member roles | ✅ | ❌ | ❌ |
| Transfer ownership and delete the clinic | ✅ | ❌ | ❌ |
| See the whole team's quota usage | ✅ | ✅ | ❌ |
In short: Admins run the team day to day, while the Owner holds the decisions that cannot be undone — changing roles, transferring ownership, dissolving the clinic.
Every member occupies one seat
Owner and Admins included. A role decides permissions, not cost — a clinic with 1 Owner, 1 Admin, and 4 doctors needs 6 seats. See Adding Organization Seats.
Who sees whose data
This is the part that matters most: joining a clinic does not open your records to anyone.
| Data | Who can see it |
|---|---|
| Records and patients | Only the doctor who created them — unless explicitly shared |
| Records shared with the clinic | Every member of that clinic |
| Each doctor's quota usage | Owner and Admins only |
| Transcripts, SOAP notes, patient data | Never shown on the usage dashboard |
The default is private. Sharing a record with the clinic is a deliberate act you take per patient.
Every cross-doctor access is logged
When a doctor opens another doctor's record through shared data, that access goes into the audit log. This is not surveillance of your team; it is a compliance requirement — a medical record must carry a trail of who opened what, and when.
The usage dashboard shows numbers only — hours used, quota left, when someone was last active. A clinic admin can see that a doctor used 32 of 75 hours, but cannot open a single patient from there.
Changing roles
Only the Owner can change roles, on the Members tab. Changes take effect immediately: Medisa checks the role on every request rather than storing it in the login session. A member who has just been demoted loses access there and then, with no need to sign out and back in.
Removing a member
Owners and Admins can remove members from the Members tab. What follows:
- Their seat is freed immediately and can go to another doctor.
- Their access to clinic data ends at once.
- Their personal subscription resumes with its stored remaining days.
- The records they created stay — removing a member deletes no data.
A removed member can be invited back at any time.
The danger zone
Two irreversible actions live on the clinic's Settings tab, in a Danger zone box, and both are Owner-only.

Transfer ownership makes another member the Owner; you drop to Admin automatically and stay in the clinic.
Delete clinic permanently removes the clinic, its memberships, and all related data.
Transfer ownership before you leave
A clinic must always have an owner. A sole Owner can neither leave nor be removed. If you are leaving for good, transfer ownership first — otherwise the clinic can be stranded with nobody authorised to handle its billing.
If something goes wrong
| Symptom | Most common cause |
|---|---|
| Cannot change a member's role | You are an Admin, not the Owner — only the Owner may |
| Cannot leave the clinic | You are the sole Owner; transfer ownership first |
| Cannot see teammates' usage | You are an ordinary member — usage is Owner and Admin only |
| Cannot see a teammate's records | By design — records are private unless shared |
| A removed member still appears to have access | Reload; revocation takes effect immediately server-side |
Next steps
- Creating an Organization — create a clinic and invite doctors
- Adding Organization Seats — activate and manage seats
- Subscription — what happens to your personal subscription