—
Team Members
—
Owners
—
Editors
—
Viewers
Team Members
Permission levels are real and enforced by the backend on every write action — see STAGE_5_IMPLEMENTATION_REPORT.md. "Add Team Member" creates a real account with a temporary password shown once; there is no email-invite step yet (needs the email/SMS integration — see EXTERNAL_INTEGRATION_MAP.md).
What Each Permission Level Can Do
Owner
Full access — can update the account profile/branding, add associate partners, and add, edit or remove any team member. There must always be at least one Owner.
Editor
Can register patient cases and use the day-to-day workflow, but cannot change account profile/branding, add associates, or manage the team.
Viewer
Read-only — can see patient cases, rewards and revenue-share data, but cannot create or edit anything.