Version 1.1

Effective date:

Aug 11, 2026

Administrator workflows

User Creation and Management User Guide

Overview 

This guide provides a comprehensive framework for user management within the Workflow and Reporting platform, including user creation, configuration, and ongoing administration. It covers the three core user levels, roles and permission models, step-by-step setup for radiologist and non-radiologist users, bulk upload functionality via Excel, and account maintenance best practices. 


IMPORTANT: The platform uses role-based access control (RBAC) aligned with HIPAA minimum-necessary principles. Always assign the least permissive role that meets the user's job function. 


Contents: 

  • Module 1 — Understanding User Levels 

  • Module 2 — Roles and Permissions 

  • Module 3 — Adding Non-Radiologist Users 

  • Module 4 — Adding Radiologist Users 

  • Module 5 — Ongoing User Management 


Module 1: Understanding User Levels 

There are three user levels. Each level determines how broadly a user can access data across the platform. Selecting the correct user level is an important first step — it directly affects HIPAA compliance and data visibility. 


Level 

Typical Use 

Global 

Platform employees only 

Group (Facility Group) 

Radiologists, group admins 

Local (Facility) 

Technologists, site-specific staff 


Global Users 

  • Data is accessible across all facility groups and customers. 

  • Only platform employees are assigned global-level access. 

  • Do not assign product environment access to global users unless absolutely necessary. 


IMPORTANT: Overuse of global-level access can compromise HIPAA compliance. Limit global users to internal staff only. 


Group Users 

  • Access is limited to a specific customer's facility group. 

  • This is the recommended level for radiologists and administrative staff.

  • Limits exposure of PHI to within the group boundary. 


Local Users 

  • Access is scoped to a single facility only. 

  • Useful for site-specific roles such as technologists. 

  • Users cannot see data from other facilities in the same group. 


Module 2: Roles and Permissions 

Roles define the access a user has to specific features in the platform. They are made up of Access Control Lists (ACLs) — individual permission flags that grant access to specific modules, tabs, and actions. 


Default Roles 

The platform ships with predefined roles suitable for the most common use cases: 

Role 

Level 

Administrator 

Global 

Radiologist 

Global 

Guest 

Global 

Patient 

Global 

Facility Group Admin 

Local 

Facility Admin 

Local 

Technologist 

Local 

Client 

Local 

CSR 

Local 

Mobile Technologist 

Local 


TIP: Default roles are a good starting point. Review their ACLs before assigning to ensure they match the user's actual job function. 


ACL Editing Permissions 

Who can edit a role's ACLs depends on whether the role is a default role or a custom role: 

  • Default roles — ACLs are editable only by Global Admin users. Any other user who opens a default role in Admin > Roles sees its ACLs in view-only mode. 

  • Custom roles — ACLs remain editable, scoped to the editor's own level: 

  • Global users can edit permissions for all custom roles. 

  • Group users can edit permissions for custom roles associated with their own facility group. 

  • Local users can edit permissions for custom roles associated with their own facility. 


Custom Roles 

Custom roles can be created to meet specific workflow or compliance needs. 

  • Example: an "Admin Technologist" role that includes standard technologist permissions plus access to additional admin tabs in the exams list. 

  • Custom roles are visible only within the facility group they were created in. 


Creating a New Role 

  1. Navigate to Admin → Users and Roles. 

  2. Select the Roles tab. 

  3. Click Create New Role. 

  4. Enter a name and description for the role. 

  5. Assign ACLs by checking the relevant permission flags. There are over 200 ACLs — only check what is necessary for the role. 

  6. Save the role. 


IMPORTANT: ACL configuration errors are a common cause of users not seeing the correct tabs or exams. Always test a new role by logging in as a test user before rolling out to the team. 


ACLs and HIPAA Alignment 

  • ACLs control access at the module and feature level. 

  • Assign the minimum set of ACLs required for the user's job function. 

  • Avoid granting access to sensitive modules (e.g. QA, Peer Review) unless there is a documented clinical need. 

  • Review ACL assignments quarterly as part of your HIPAA access review process. 


New: the "Sign exams" ACL 

Field 

Value 

ACL name 

Sign exams 

Category 

Orders 

Action 

Read 

Description 

Allow users to perform sign actions on exams assigned to them 


This ACL controls whether the Sign & Close and Sign & Next buttons appear for a user, for both final reports and addendums: 

  • If enabled (Read checked), the user sees the Sign & Close and Sign & Next buttons. 

  • If disabled, those buttons are hidden and the user cannot sign. 


Default state: 

  • ON for the default Radiologist role, at both the Global and Local levels. 

  • ON for custom roles created with the Radiologist alias (these inherit permissions from the default Radiologist role). 

  • OFF for all other roles, including Facility Group Admin and Site Admin. 


Note: Having Read access to "Sign exams" is necessary but not sufficient to sign — the user's role must also carry the Radiologist alias, at minimum. So even if a Facility Group Admin or Site Admin role has this ACL turned on, users with that role still will not see the sign buttons. 


Module 3: Adding Non-Radiologist Users 

Non-physician (radiologist) users include facility administrators, technologists, or other support roles. They should be assigned to a Group or Local user level — never Global. 


Step-by-Step: Adding a Non-Physician User 

  1. Navigate to Admin → Users. 

  2. Click Add User. 

  3. Select the appropriate User Level: Group (recommended for most admin/support roles) or Local (for site-specific staff). 

  4. Complete the user's profile fields: name, email, phone number, time zone, and address. 

  5. Assign a Role from the dropdown. If the correct role does not appear, it may need to be created first (see Module 2). 

  6. Review the ACLs inherited from the role and confirm they match the user's job function. 

  7. Save the user. They will receive an email invitation to set their password. 


TIPS 

  • Do not give non-physician users access to QA or Peer Review modules unless there is a specific documented requirement. 

  • If the Radiologist role does not appear in the role dropdown when adding a user via Admin > Users, this is expected — radiologists are added through a separate flow (see Module 4). 

  • For bulk uploads of non-radiologist users, use the Upload Users option and provide a correctly formatted Excel file (see Module 5 for bulk upload tips). 


Module 4: Adding Radiologist Users 

When creating a physician user (current default: Radiologist), additional configuration is required, including assigning the appropriate licenses and privileges to enable access to view and interpret exams on the worklist. 

UPDATED — The radiologist creation dialog has been redesigned and renamed "New Reader" (previously "Add Radiologist"). See Step 1 below.

  • Radiologists who read for a single facility group only should be created at the Facility Group Level. 

  • Radiologists who read for multiple facility groups should be created at the Global Level. Note: Global level users can be created by platform administrators only. 


Step 1 — Create the Radiologist Account 

  1. Navigate to the Radiologists section. 

  2. Click Add Radiologist or Upload Radiologists (for bulk). Clicking Add Radiologist now opens the "New Reader" dialog. 

  3. Complete the "General Details" section (renamed from "Radiologist Details"): name, email, NPI, date of birth, phone number, time zone, and address. 

  4. Select a Role (new, mandatory field). The dropdown lists the default Radiologist role at the top, followed by custom radiologist roles in alphabetical order. 

  5. Optionally enter Specialty and Subspecialty (new, free-text fields). 

  6. Optionally enter a Title — this is now a free-text field instead of a dropdown. 

  7. Set the Primary Group — this determines which group admins will manage the radiologist's settings. 

  8. Optionally add "Additional facility group(s)" (renamed from "Secondary Facility Group") for shared coverage arrangements (applicable to global role). 

  9. Save the account. 


What's new in the New Reader dialog 

NEW — Role field — mandatory dropdown. 

  • Shows the default Radiologist role first, then custom radiologist roles in alphabetical order. 

  • For a global radiologist, global custom radiologist roles are shown. For a group or local radiologist, the custom roles scoped to that group/facility are shown. 

  • For Group or Local radiologists, the Role field is disabled until you select a Primary facility group. 


NEW — Specialty and Subspecialty fields — optional free text. 

  • Alphanumeric, up to 50 characters. 

  • Allowed characters: letters, numbers, spaces, hyphen (-), slash (/), parentheses (), period (.), comma (,), apostrophe ('), and accented characters (á, é, ñ, etc.). 

  • Not allowed: & (ampersand), ~ (tilde), | (pipe), ^ (caret), \ (backslash), and any other character outside the allowed list. 


UPDATED — Title field — now free text instead of a dropdown. 

  • Optional, up to 50 characters, with the same allowed/disallowed characters as Specialty and Subspecialty. 


UPDATED — Field labeling — mandatory fields no longer show a red asterisk. Optional fields are labeled "optional" instead.  

Title, Specialty, and Subspecialty also appear on the radiologist's existing profile (in the General Details block), with the same validation rules. 


Step 2 — Add State Licenses 

In the US, radiologists are licensed by state. A license must be added for every state in which the radiologist will be reporting. 

  1. Open the radiologist's profile and go to the Licenses tab. 

  2. Click Add License.

  3. Enter the license number. 

  4. Select the State — this is the most important field. It must match the state where the facility is located.

  5. Set an end date. 

  6. Save. 

TIP: The radiologist does not need to be physically located in the licensed state. The license state must match the state of the facility they are reporting for. 


Step 3 — Add Privileges 

Privileges grant the radiologist the ability to read exams at specific facilities for specific modalities. 

  1. Go to the Privileges tab on the radiologist's profile. 

  2. Click Add Privileges. 

  3. Select the Facility. 

  4. Select the Modalities. Add all relevant modalities. 

  5. Set the HL7 report type: Final, Preliminary, or both — based on the radiologist's signing authority at that facility. 

  6. Set an end date. 

  7. Save. 


Step 4 — Configure Order Visibility 

Order visibility controls whether assigned or unassigned exams will be visible to the radiologist on their worklists. 


Setting 

Behavior 

View only exams assigned to user 

Enabled by default when a radiologist account is created. With it turned on, the radiologist will see only the exams assigned to them. 

View only exams completed by user 

Disabled by default. When enabled, users can view only the exams they have completed. 

IMPORTANT: The "View only exams assigned to user" checkbox is frequently missed during setup. If a radiologist cannot see exams on their worklist, check this setting first. 


Step 5 — Exam Exclusions (Optional) 

  • Exam exclusions prevent specific exam types from being reported by a radiologist. 

  • The radiologist can still see the excluded exams but cannot dictate or sign them. 


Mapping Specialty and Subspecialty to PDF reports 

NEW — This capability is new. 

The Specialty and Subspecialty fields can now be mapped into PDF reports, the same way the Title field already can be. 

  • Go to the Accounts page → PDF Report Setup, at either the group level or the facility level. 

  • Open the Instructions file for the report template — it has been updated to document the new Specialty and Subspecialty placeholders alongside the existing Title placeholder. 

  • Add the placeholders to your report template as needed. 


Bulk Upload: Radiologists via Excel 

When onboarding many radiologists at once, the bulk upload feature allows you to efficiently upload multiple users at a time. 

  1. Navigate to the Radiologists section. 

  2. Click Upload Radiologists, select Global or Group in the dropdown to determine the user's access, and download the sample Excel template. 

  3. Fill in the required columns: Primary facility group, name, email, NPI, date of birth, time zone, address, phone number. 

  4. For address, format as: City, State, Country (e.g. New York, New York, USA). 

  5. For phone numbers, format as plain text (e.g. 201 5555555) to prevent Excel from stripping leading digits or adding decimal points. 

  6. Set time zone consistently — use the same time zone value for all rows if possible. 

  7. Save the file and upload it via the Upload Radiologists button. 

  8. If the upload fails, click the Open Excel file link shown in the error message — it explains exactly which rows failed and why. 

TIP: If your network environment blocks the error log file from opening, send the Excel file to your implementation contact for upload. Licenses and privileges still need to be added per radiologist after upload. 


Module 5: Ongoing User Management 

Unlocking Users 

User accounts can become locked after three failed login attempts or extended inactivity. 

  1. Navigate to Admin → Users. 

  2. Select the Locked Users filter or tab. 

  3. Find the affected user. 

  4. Click Unlock Account. 

  5. Notify the user that their account has been restored. 


Access Audits and Role Reviews 

  • Review user access and role assignments on a regular schedule. 

  • Disable or remove accounts for staff who have left the organization or changed roles. 

  • Conduct a formal role-based access review at least quarterly. 

  • Pay particular attention to: global-level users, custom roles with broad ACLs, and radiologists with access to multiple facility groups. 


TIP: A quarterly ACL review is a HIPAA best practice. Ensure inactive accounts are disabled promptly — departed staff should not retain system access. 


Troubleshooting 

Symptom 

First thing to check 

Radiologist cannot see any exams on the worklist 

Check "View only exams assigned to user" — it may be checked. Also verify privileges are saved correctly. 

User cannot see a tab or module after login 

Review the role's ACL configuration. The relevant ACL for that module may not be enabled. 

Radiologist cannot view a specific exam type 

Check privileges — the modality may not be included. Also check exam exclusions. 

Bulk upload fails 

Open the error log Excel file linked in the upload error message. Common causes: address format, phone number format, duplicate emails, or time zone field. 

User account is locked 

Navigate to Admin > Users > Locked Users and unlock the account. 

Custom radiologist role not visible in Add User dropdown 

Radiologists are added via the Radiologists section, not via Admin > Users. The radiologist role will not appear in the standard user role dropdown. 

Radiologist cannot see the Sign & Close / Sign & Next buttons 

NEW — Check the "Sign exams" ACL for the user's role (Module 2). Also confirm the role carries the Radiologist alias — the sign buttons require both. 

Role field is disabled in the New Reader dialog 

NEW — For Group or Local radiologists, select a Primary facility group first — the Role dropdown enables afterward. 

Cannot edit ACLs for a default role 

NEW — This is expected for non-Global Admin users. Only Global Admins can edit default role ACLs; others have view-only access (Module 2).