Security
Roles, Permissions & Security
Role-based permissions, per-role status visibility, organization-level data separation, two-factor authentication and API token management.
Patient data is not an ordinary customer list, and deciding how much of it each person sees is a responsibility in itself. Teams running several brands or branches also need that data kept apart. MoonCRM defines permissions at the role level, separates records by organization, and adds a setting for which statuses each role is allowed to see. On the account side there is two-factor authentication and personal access token management.
What you can do
- Role definitions with a permission list
- User-to-role assignment
- Per-role status visibility settings
- Organization-level data separation
- QR-based two-factor authentication setup
- Recovery code generation
- Create, list and revoke personal access tokens
- Profile, password and appearance settings
Highlights
Role-based permissions
Permissions attach to roles rather than individuals, so onboarding a new consultant means assigning the right role and nothing else.
Per-role status visibility
Which statuses a role may see is configured separately, keeping sensitive stages of the pipeline visible only to the teams that need them.
Organization separation
If you run several brands or branches, records are separated by organization so teams never work in each other’s data.
Two-factor authentication
QR-based setup and recovery codes stop a compromised password from turning into access to patient data.
Getting started
Setup takes three steps
An implementation specialist works with you at every step. No technical team required.
- 1
Map out your roles
Define roles such as consultant, operations and manager, and decide which permissions each one carries.
- 2
Set status visibility
Choose which statuses each role can see and switch off visibility nobody needs.
- 3
Protect the accounts
Require two-factor authentication on administrator accounts and store the recovery codes somewhere safe.
Frequently asked questions
Our team knows medical tourism operations inside out. Let’s review your process together in a 15-minute call.
All questions Can I limit a consultant to their own patients?
Permissions are role-based, so access can be restricted, and per-role status visibility lets you hide records in certain stages entirely.
Can I run several branches or brands in one installation?
Yes. The organization structure separates the data, and each team works only within its own organization.
Can we connect MoonCRM to our own systems?
You can create, list and revoke personal access tokens, and your integrations authenticate through them.
Other modules
WhatsApp Integration
Bring multiple WhatsApp lines into one inbox and message patients, contracted hotels and transfer companies from the same screen.
Patient & Lead Management
Every lead lives on one record — status, category, consultant, services, tags, call notes and reminders in one place.
Operations: Hotel, Transfer, Flight
Appointment, doctor, hotel, transfer, room type and flight details live inside the patient record — with every visit stored separately.
See Roles, Permissions & Security in action
In the demo we walk through this module against your own process. Thirty minutes, no sales pressure.