Sign in
This panel creates practices and decides whether they may operate. It holds no patient records.
Set a new password
There is no reset email. This account can suspend every practice on the
platform, and a mailbox is not a strong enough key for that. Someone with
access to the server runs scripts/resetAdmin.js and gives you
the token.
Practices
Audit
Every action taken in this panel, newest first — including the ones that only looked.
| When | Who | Action | Change | Reason |
|---|
Account
- Signed in as
- —
- Name
- —
- Last sign-in
- —
Two-factor
—
An authenticator app on your phone — Google Authenticator, Aegis, 1Password, any of them. Nothing is sent by SMS.
In your authenticator app choose enter a setup key, then type this. It is shown once.
The app will start showing a six-digit code. Type the current one to finish — until it is verified, two-factor stays off, so a mistyped key cannot lock you out.
Turning it off needs a current code as well as this session — otherwise a stolen token could remove the factor protecting the account, which is the same as not having one.
This session
Held in memory only. Closing the tab signs you out, there is no “remember me”, and the server expires it after two hours regardless. That is deliberate for an account that can suspend every practice, and it means signing in again after a refresh.