In a clinic running on CuraVerto, a role decides which screens a staff member can open, branch scoping decides which location's records they can see, and the audit log records who opened or changed what, when, and from where. CuraVerto's roles, admin, doctor, staff, receptionist and lab, are scoped to a branch on every plan, including Essential. The audit log itself is a Plus-plan feature, included at โน49,999 per year.
| Role | What the job needs | What it should not reach |
|---|---|---|
| Admin | Full clinic settings, staff accounts, billing configuration, and every branch the account is scoped to | Nothing within the clinic's own scoped branches is hidden from admin, which is exactly why an admin login needs the most careful handling of any role |
| Doctor | Their own patients' clinical notes, prescriptions and appointment schedule | Other doctors' consultation notes and clinic-wide financial reports |
| Receptionist / front desk | Appointment booking, patient contact details and billing at their own branch | Clinical notes, prescriptions and any other branch's records |
| Staff | The appointment queue and assigned tasks at their own branch | Full consultation notes, prescriptions and billing configuration |
| Lab | Test orders and result entry at their own branch | Consultation notes and billing |
Role answers what a person can open. Branch answers at which location. A receptionist at one branch has no business browsing another branch's billing, and a system with roles but no branch scoping cannot draw that line: access becomes all or nothing, and there is no way to say which location a change belongs to. CuraVerto scopes every role to a branch, so a front-desk login at branch A stays inside branch A's patients and billing, and opening a second branch does not mean rebuilding access from scratch.
A log that only says something changed does not help in a dispute. To be useful, an audit trail has to answer six questions every time: who made the change, what they changed, when, what the value was before, what it became after, and at which branch it happened. That is the standard CuraVerto's audit log is built to meet.
CuraVerto's audit log is a Plus-plan feature, included at โน49,999 per year. Essential and Pro do not lose access control by not having it, every plan gets role-scoped access to begin with. The audit log is the additional layer that keeps a history of who did what, and it sits on Plus.
Two ideas from India's Digital Personal Data Protection Act 2023 map onto access control directly: purpose limitation, meaning staff should only see the data their role actually needs, and a record of who accessed what, which is what an audit log provides. Neither idea is unique to the Act, both describe what a working access-control system looks like in practice.
Software supports these practices, it does not confer compliance on its own. CuraVerto does not claim to make a clinic DPDP compliant on the strength of roles and an audit log alone, the Act's obligations, notice, consent and breach reporting among them, extend well beyond access control. Our DPDPA compliance guide for Indian clinics covers the full obligation list.
Roles are scoped to a branch on every CuraVerto plan, and the audit log is included on Plus at โน49,999 per year with no per-doctor fee at any headcount.