Give people the right access
Invite test users, assign focused roles and department coverage, and plan company sign-in safely when it is available.
Updated September 26, 2026
In this article
Give each practice account only the access needed for the lesson. Access to an organization is separate from Avery Reed’s employee record. Do not change the populated demonstration’s memberships while using it for viewing.
Before you begin
You need Manage members, Manage access roles, and Assign access, with reviewed authority for the roles you will assign, separate practice accounts, and an agreed department coverage plan. For company sign-in, you also need Manage sign-in security and a supported, administrator-approved practice configuration.
If a limited access administrator has not been set up yet, have an organization administrator open that active person’s Edit user access page, select Access administrator, and use Set up assignment limits to approve the practice roles and department coverage before saving. Follow Allow another person to assign roles. Confirm the saved limits on the person’s Access roles tab before starting. An organization administrator already has assignment authority and can perform the practice directly.
Invite and verify access
- Open Settings, then Users and access. Review the starter roles before creating a custom role.
- Invite the requester using their verified practice email address. Assign the focused role needed to create or submit the practice request and give access to Outpatient Services.
- Invite a different reviewer. Give the reviewer access needed for Outpatient Services and the approval task, without granting employee-pay access unless the exercise needs it.
- Have each person accept their own invitation and check the organization name in the header.
- As the requester, open the intended position work and submit the practice request. As the reviewer, open the assigned approval step.
- Run Access Review and compare the two users’ roles and department coverage. Confirm that either person cannot see a financial area that their role does not include.
- When a practice user no longer needs access, review open work, then use Deactivate user access. Do not reuse their account for another person.
Review company sign-in without using credentials
If company sign-in is not enabled for the organization, read this section as a planning exercise only. Do not enter provider credentials, client secrets, or payment information.
- Open Configure company sign-in and identify which connection details the company sign-in administrator must supply.
- Decide who manages the sign-in provider, who can recover access, and which administrator will test the connection.
- Explain that a successful provider test comes before Require company sign-in. An authenticator app does not bypass required company sign-in.
- Use a prepared demonstration, if available, to identify the test result, the Company sign-in URL given to members, and the recovery action when the provider is unavailable.
Make an enforcement decision
Use this prepared example without changing any provider setting: Avery Reed, the requester, and the reviewer are all intended members. Avery and the reviewer can use the configured company provider, but the requester has not yet been given a provider account. The administrator has completed a successful test.
Do not choose Require company sign-in yet. The requester would lose access to the organization even though the requester’s FTE Tree role and Outpatient Services coverage are correct. First arrange the requester’s provider access, confirm that the requester can use the organization-specific Company sign-in URL, and keep an administrator recovery path available. Then the administrator can decide whether enforcement is appropriate.
Check your result
The requester and reviewer can do their intended work with different access. You should be able to explain that company sign-in confirms identity through the company service but does not assign FTE Tree roles or department access.
Ask: In the three-member example, why wait to require company sign-in? Every intended member needs provider access, at least one administrator needs a working recovery path, and an eligible administrator must complete a successful test. Avery and the reviewer being ready does not make it safe to lock out the requester.
Next task
Continue with Review billing, history, and retention.