Skip to content

Docs / Guides / Staff

Inviting staff and passkey sign-in

How to invite someone to your practice, what changes between an owner and an assistant, how to register a passkey to sign in, and why the last owner of a practice can never be removed.

Inviting someone

An owner invites a new staff member with their email address and a role, owner or assistant. That sends a single-use invitation which expires after three days, so an old, unused invite can't be accepted months later. The invited person accepts it while signed in with a matching, verified email address — a mismatched or unverified email is rejected before anything is granted.

If email isn't set up

If the invitation email does not arrive, the invitation itself still exists — the owner gets the accept link back directly and can pass it on however is convenient, so a new receptionist is never blocked on an email. Either way the link expires after three days and can only be used once.

Owner vs assistant

Every staff member is an owner or an assistant. Owners can manage staff, change roles, and reach administrative surfaces like reports and the audit log. Assistants get the everyday tools — patients, calendar, billing, forms — without those administrative ones. An owner can change anyone's role at any time, with one exception below.

The last-owner rule

A practice can never be left without an owner. Trying to remove or demote the only remaining owner is rejected outright — there's no confirmation step to click through by mistake, it simply isn't allowed. If you need to hand ownership to someone else, promote them to owner first, and only then adjust your own role.

Setting up passkey sign-in

Staff sign in with a passkey (the WebAuthn standard) instead of a shared password. Registering one is a short prompt from your device — a fingerprint, face unlock, or security key, depending on what your device supports — and the credential is bound to that specific device and to the environment it was registered in. That means a passkey registered against a local/test environment won't work against the live one; register one separately wherever you actually sign in. A practice can also require this step for every sign-in, not just offer it. See the team feature page for the marketing-facing summary, or the guides hub for the rest of the documentation. Anything unclear about roles or invitations is worth asking us directly.

Related reading

Team feature

The marketing overview of roles, invitations and passkey sign-in.

Security

How passkeys, roles and the audit log protect a practice's whole account.

Reporting

The audit log records every staff and role change alongside everything else.

Common questions

Patient records are encrypted in transit and at rest, files are stored privately and served through short-lived signed links, and every change is written to an audit log. Staff accounts sign in with passkeys rather than shared passwords.

HyperCRM is paid software. Every practice starts with a 30-day free trial of the full Complete plan, with no card required. After that, plans start at €19 and €29 a month excluding VAT, banded by how many practitioners you have. Every price is printed on the pricing page rather than quoted on a call.

It simply stops working — the invited person sees an expired-invitation message instead of being added to the practice. An owner can send a fresh invitation to the same email address at any time; there's no waiting period or manual cleanup needed on the expired one first.

No. Removing or demoting the last remaining owner is rejected outright, so a practice can never end up without anyone able to manage staff and settings. To hand off ownership, first promote another member to owner, and only then change or remove your own owner role.