Team management
Invite teammates, assign roles, enforce two-factor authentication, and deactivate staff who leave.
Where to find it
Open Settings → Team from the sidebar. You'll see a table of every person on your practice with their name, email, role, last sign-in, and status (Active, Pending invite, or Deactivated).
Inviting a teammate
Vantrexia emails the new teammate a secure invitation link. The link expires after 7 days. Until they accept, their row shows as Pending invite. You can resend or revoke the invite from the row's action menu.
Invitations are tied to the email address you enter. If a teammate changes employers, do not transfer the account. Deactivate the old user and invite them fresh under the new email.
Roles
Roles control what each user can see and do. Vantrexia ships with the following standard roles:
| Role | What they can do |
|---|---|
| Owner | Everything, including billing, branding, and team management. Usually the practice owner. |
| Admin | Manage staff, devices, settings, and billing. Cannot delete the tenant. |
| Clinician | Enroll patients, review readings, respond to alerts, document care time. |
| Care Coordinator | Same as Clinician, plus run outreach lists and reminders. |
| Read-only | View patients and readings but make no changes. Useful for auditors and observers. |
Assign the most restrictive role that lets the person do their job. You can change a role at any time from the row's action menu. The change takes effect on the user's next page load.
Enforcing two-factor authentication
Two-factor authentication (2FA) adds a one-time code from an authenticator app on top of the password. Vantrexia strongly recommends requiring 2FA for all staff who handle PHI.
To enforce 2FA practice-wide:
Once enforced, any user without 2FA is prompted to enroll on their next sign-in and cannot reach patient data until they finish. They scan a QR code with an app like Google Authenticator, 1Password, or Authy, then enter a 6-digit code to confirm.
Before enforcing 2FA, give your team a heads-up so they install an authenticator app first. Otherwise you'll get a flurry of "I'm locked out" messages.
If a teammate loses their phone, an Owner or Admin can reset their 2FA from the row's action menu. They'll be prompted to re-enroll on next sign-in.
Deactivating staff
When someone leaves your practice, deactivate their account immediately. Deactivation is reversible and preserves their audit trail.
A deactivated user:
- Cannot sign in
- Disappears from assignment dropdowns (so you can't accidentally route work to them)
- Remains in audit logs and historical records. Their past actions stay attributed to them
- Can be reactivated later from the same action menu
Never delete a user. Deactivation is the right action. It preserves the audit trail while immediately revoking access.
Auditing access
Open Settings → Audit log to see every sign-in, role change, and deactivation. Use the filters to scope to a specific user or date range. This is also where compliance officers download access reports for HIPAA reviews.