Start with the work, not the person
Access is not a judgment about whether someone is trustworthy. It is a practical decision about what their role requires.
Begin with a few concrete questions:
- Which clients does this practitioner treat or support?
- Do they regularly cover for other practitioners?
- Are they part of a shared-care model?
- Do they need to review records before accepting a referral?
- Are they responsible for clinical oversight across the practice?
- Could the same task be completed by an owner, admin, or scheduler instead?
The answers should describe the work, not the person's seniority or how long you have known them. A highly trusted practitioner may still need only their own client records. A newer clinical lead may need broader access because reviewing care across the team is part of the role.
Write down the reason for broader access in one sentence. If the reason is vague, the access may be broader than the workflow needs.
Use own-client access as a clear starting point
For many practitioners, the simplest starting point is access to the clients connected to their own work. That keeps the client list relevant and reduces the chance of opening the wrong record when names are similar.
Own-client access tends to fit when a practitioner:
- manages an individual caseload;
- writes notes only for their own appointments;
- does not provide routine coverage for colleagues;
- is not responsible for practice-wide clinical review; or
- works in a contractor model with a distinct group of clients.
This approach should not create a daily permission chase. Make sure your system has a dependable way to recognize the relationship, such as an appointment with the practitioner or a clinical note they wrote. Test the common paths before you rely on the setting: opening the client chart, starting a note, checking an upcoming appointment, and finding a returning client.
If a practitioner cannot reach a client they genuinely work with, fix the care relationship or assignment. Do not quietly switch them to every client as a permanent workaround.
Give all-client access a specific purpose
Some practice models genuinely need broader access. The important part is to name the workflow it supports.
All-client access may be appropriate for a practitioner who provides regular clinical coverage, supervises care across a team, handles shared intake, or participates in a model where clients move between practitioners as part of normal treatment.
Before granting it, decide what the practitioner is expected to do with that access. For example:
- review a colleague's record when covering an absence;
- assess a new referral before assigning a practitioner;
- provide documented clinical supervision;
- coordinate care for clients who see several people in the practice; or
- respond to an urgent clinical concern when the usual practitioner is unavailable.
Broad access should solve a recurring need, not a hypothetical one. If coverage happens twice a year, a temporary or case-specific process may be clearer than keeping permanent access open.
Keep scheduling access separate from clinical access
Front desk work and clinical work overlap around the calendar, but they are not the same job.
A scheduler may need to find any client, book or move appointments, confirm contact details, and answer practical questions. That does not automatically mean they need to open clinical notes, intake answers, or treatment plans.
Map the workflow in layers:
- Who needs to find a client and manage an appointment?
- Who needs to open the general client record?
- Who needs to read or write clinical information?
- Who needs practice-wide oversight?
Keeping these decisions separate prevents two common mistakes. You do not have to block useful front desk work in order to protect clinical information, and you do not have to grant clinical access just to make scheduling possible.
Plan for the moments when access changes
Access decisions become unreliable when they are made once and never revisited. Build a small review into events that already get your attention.
Check client access when:
- a practitioner joins or changes roles;
- someone begins or stops covering another caseload;
- a supervisor takes on or hands off responsibility;
- a practitioner goes on leave;
- a contractor becomes an employee, or the reverse;
- a practitioner leaves the practice; or
- your team changes how clients are assigned.
The review can be short. Confirm the person's role, their client scope, and whether any temporary access should end. Then test the result with a normal task from their day.
When a person leaves, remove their current access without erasing the historical record of appointments and notes they were responsible for. Access and authorship are different things. Your records should preserve who did the work even after that person can no longer sign in.
Make the rule easy to explain
A good internal rule should fit in a few sentences. For example:
Practitioners begin with access to the clients they work with. Practice-wide access is used for regular coverage, supervision, or shared-care responsibilities. Owners and admins review access whenever a role or care relationship changes.
Adapt the wording to your profession, jurisdiction, contracts, and privacy obligations. Then use the same rule during onboarding, leave planning, and offboarding. A consistent explanation is easier to follow than a series of exceptions that live only in the owner's memory.
Stillpoint lets owners and admins choose Own clients or All clients for each practitioner. Own-client access follows clients who have booked with that practitioner or have a note they wrote, while team roles keep scheduling work separate from clinical-record access. Explore Stillpoint's security and access controls.



