Roles, boundaries, and who can invite whom
The three provider-network account types, what each one can do, and the boundaries that catch people out.

A provider network has exactly three account types — Provider Network Admin, Provider, and Provider Delegate — and this guide says what each one can and cannot do before you send any invitations.
Questions people ask about this page
Which role should I give someone?
Pick by the work, not by seniority. Someone who signs off on care is a Provider. Someone who configures the network, invites people and handles clients is a Provider Network Admin. Someone who books, chases and follows up but never makes a clinical decision is a Provider Delegate.
Can a Provider Network Admin approve a chart if a provider is away?
An admin can open and edit any chart in the network, and can reassign work. What an admin should not do is record the clinical decision — approving, denying or deferring is a licensed act. Reassign the visit to another Provider instead. Admins are also never given live video-visit tools.
Why can my delegate open ScriptSure when I was told delegates cannot prescribe?
Both are true. A delegate can launch a ScriptSure patient chart, but GEN Health signs them in using the prescriber's ScriptSure identity, not their own. The prescription is written under the prescriber; GEN Health records the delegate separately in its own audit trail. A delegate does not need a ScriptSure enrolment of their own — the prescriber must be Verified.
Why does a Provider Network Admin have no Patients page?
Patients is deliberately absent from the Provider Network Admin menu and present for Provider and Provider Delegate. An admin reaches patient records through a visit, order, prescription or message row instead.
Who can invite whom?
In practice, only a Provider Network Admin. They can invite all three network roles. A Provider or Provider Delegate has no Providers page, no Settings and no Users table, so no invitation control appears anywhere in their menu. See Providers, admins, and delegates.
Can one person hold two roles?
Not on one account. A person with more than one GEN Health account switches between them with Switch in the sidebar account block, which opens Switch Account / Choose a linked or recently used account. Permissions come from the account that is signed in, never from the person's job title.
My provider says the app is stuck behind a dialog they cannot close.
Two blocking gates apply to Providers and Provider Delegates but never to admins. Required Knowledge Base Review (Review each required item before continuing in the portal.) cannot be dismissed — the X does nothing. They must open every item and finish it. The other is their own onboarding wizard. See What each provider must complete.
Where to find it
This guide is cross-page. You set someone's role when you invite them, at left menu → Providers (/providers) for clinicians, or left menu → Dashboard → the Users card → Add for the other two roles. You cannot change a role after the account exists — deactivate and re-invite.
The short version
| Role | Exists to | The boundary that bites |
|---|---|---|
| Provider Network Admin | Configure the network, invite people, run clients, route work. | No Patients menu item, and no live video-visit tools. |
| Provider | Claim work, chart it, decide it, prescribe it. | No Settings, no Billing, no Providers, no Clients. Blocked by their own 9-step wizard and by the knowledge-base gate. |
| Provider Delegate | Book, route, chase and follow up around a Provider. | Cannot claim a review or record a decision. Anything they do in ScriptSure happens under the prescriber's identity. |
What each role sees in the left menu
| Nav item | Route | Network Admin | Provider | Provider Delegate |
|---|---|---|---|---|
| Dashboard | /dashboard | Yes | Yes | Yes |
| Patients | /patients | No | Yes | Yes |
| Visits (ASYNC) | /async-visits | Yes | Yes | Yes |
| Visits (SYNC) | /sync-visits | Yes | Yes | Yes |
| Providers | /providers | Yes | No | No |
| Clients | /clients | Yes | No | Yes |
| Forms | /forms | Yes | No | No |
| Protocols | /protocols | Yes | Yes | Yes |
| Formulary | /formulary | Yes, only when an OnlyScripts pharmacy is connected | No | No |
| Labs, Orders, Prescriptions, Integrations, Messages, Reports, Knowledge base, Support | — | Yes | Yes | Yes |
| Notifications | /notifications | Yes | No | No |
| Billing | /billing | Yes | No | No |
| Settings | /settings | Yes | No | No |
| My schedule | query link, opens the profile on Scheduling | No | Yes | No |
A Provider or Provider Delegate who types /settings, /providers or /billing into the address bar does not get a permission error — they get Page not found, because the route is not registered for their role at all.
Capability table
| Capability | Provider Network Admin | Provider | Provider Delegate |
|---|---|---|---|
| Invite Network Admins, Providers, Delegates | Yes | No control in their menu | No control in their menu |
| Deactivate or reactivate an account | Yes | No | No |
| Verify or reject a licence, approve an NPI change | Yes | No — submits their own | No |
| Edit network settings, branding, operations, AI prompts | Yes | No | No |
| Set the patient payment processor | Yes (/billing) | No | No |
| Create and edit protocols, forms, labs, formulary | Yes | Read-only | Read-only |
| Assign providers to a client | Yes | No | No |
| Open a patient record from the menu | No Patients item | Yes | Yes |
| Claim an async chart review | No — assigns instead | Yes | No |
| Open and edit any chart in the network | Yes | Their own, plus covering | View only |
| Record the decision: Approve / Deny / Defer | Technically able; not the right actor | Yes | No |
| Use live video-visit tools (join, mute, end call) | No | Yes | No |
| Write and send a prescription | No | Yes | Only after a Provider approval, under the prescriber |
| Launch a ScriptSure patient chart | No | Yes | Yes — signed in as the prescriber |
| Use the standalone Open ScriptSure button | No | Yes | No |
| Send, resend or sync a ScriptSure invite | Yes | No | No |
| Set their own availability | No (sets network hours instead) | Yes, via My schedule | No — no Scheduling tab |
| Reassign or reschedule a visit | Yes | Their own | Yes |
| Message patients and staff | Yes | Yes | Yes |
| Manage knowledge-base content | Yes | Only if granted Provider can manage knowledge base content | No — cannot be granted |
| See the Notifications queues | Yes | No | No |
| Raise a support ticket | Yes | Yes | Yes |
The read-only messages a delegate sees, word for word
When a Provider Delegate opens a chart, the workspace tells them what they may do. These are the exact strings:
- Provider delegates can view this chart review. Approved reviews unlock prescribing only.
- Provider delegates can view this sync visit. Approved visits unlock prescribing only.
- Only prescribing is available for approved sync visits.
Providers get their own version when they open someone else's work: Only the provider who completed this review can edit it. and, when covering, The decision on this chart belongs to the provider who claimed it. You can still write a prescription.
How to choose a role and invite
Decide who signs off on care
Every person who will record a clinical decision needs a Provider account and an NPI. Everyone else does not.
Invite clinicians from Providers
Left menu → Providers → Add Provider. That button always creates a Provider; there is no role picker in it.
Invite admins and delegates from the dashboard
Left menu → Dashboard → the Users card → Add. The Add new user dialog offers three tiles: Provider Network Admin, Provider, Provider Delegate.
Tell each new person what blocks them
Providers face a 9-step wizard and the knowledge-base gate. Delegates face a 2-step wizard. Say so in the covering email or they will call you on day one.
Check the boundary once
Sign in as the new delegate with Log in as user from their row and confirm they can route work but cannot claim a review.
Log in as user is real impersonation. The confirm dialog says so: You will be entering the Provider's real account, and any actions you take after this point will be attributed to them, not to you. This login itself is logged for audit. Do not use it to record a clinical decision.
Statuses you will see here
| Status | What it means | What to do |
|---|---|---|
| Active | The account can sign in and work. | Nothing. |
| Pending | The invitation was sent and the account has never been claimed. | Use Send magic link on the row. Deactivate is hidden for pending accounts. |
| Onboarding | The account exists but the person has not finished their own setup wizard, so they cannot work. | See What each provider must complete. |
| Inactive | An admin switched the account off. | Row action Activate. Note the badge inside a profile reads Deactive for the same state. |
What can go wrong
| What you see | Why | Fix |
|---|---|---|
| You invited a delegate but they arrived as a Provider | Add Provider on /providers hard-codes the role. Its user-type list offers only Provider. | Delete the pending invite from the Users table and re-invite from Dashboard → Users → Add → Provider Delegate. |
| You want to change someone's role | There is no role-change control anywhere in the network app. | Deactivate the account and invite the person again at the correct role, using a different email if the first is still attached. |
| A delegate cannot see Manage schedule | Provider Delegates have no Scheduling tab and no My schedule link. | The Provider sets their own hours. An admin can open them from /providers → row action Manage Schedule. |
| A delegate cannot be made a knowledge-base manager | The Provider can manage knowledge base content control exists only on a Provider profile. | Nothing to fix. Grant it to a Provider instead. |
| A Provider says they cannot see a patient another Provider can see | Provider visibility depends on client assignment, account status, and state-licensure filtering. | Check /providers → the provider → Capabilities → Assigned clients, then /settings/operations → Require patient-state licensure. |
| A prescription is attributed to a provider who did not write it | A delegate launched ScriptSure. The vendor session runs under the prescriber's ScriptSure identity by design. | Nothing in the app. GEN Health's own audit records the real actor separately. |
Next
Was this helpful?
