> ## Documentation Index
> Fetch the complete documentation index at: https://handbook.helendelovely.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Access and What Your Access Covers

> How accounts are set up, what you can see, and why it's limited.

## Before access

Two things happen before you get access to any system with client information:

1. You sign the practice's HIPAA and confidentiality agreement.
2. You complete privacy and security training, and the completion is recorded.

No exceptions, including for people who've worked in healthcare before.

## What you get

Zack sets up your accounts, usually before your first day:

* A practice email address on Google Workspace, with two-factor authentication required
* A PracticeOS user account with a clinician role
* Care portal access scoped to your clients
* Telehealth platform access
* Gusto access for your own payroll information
* Enrollment of any personal device you'll use in the practice's mobile management

Login details come through a secure channel, never in a plain email. You'll be required to change any temporary password at first login.

## What your access covers

Access is scoped to your role, following the minimum-necessary principle.

**Clinicians see:**

* Your own caseload's records, conversations, and notes
* Your own calendar and availability
* Shared clinical resources and the SOP library

**Clinicians don't see:**

* Other clinicians' caseloads, beyond what supervision requires
* Billing and financial settings
* Admin and system configuration
* The practice's legal, HR, and financial files

This isn't about trust. It's about limiting exposure so that a compromised account, or an honest mistake, can only reach so far.

## Requesting more

If you need access you don't have, ask Zack. Say what you need it for. Most requests are quick. Some, like access to another clinician's records, need Helen's approval.

## Role changes

If your role changes, your access changes with it. Access you no longer need is removed.

## When you leave

All access is revoked on your last day. See [Offboarding and access revocation](/leaving/offboarding-and-access-revocation).

## The related SOPs

SOP 01 (CRM onboarding) and SOP 20 (device security) cover the step-by-step. See the [SOP library](/operations/sop-library).
