★ Backed by Y Combinator · HIPAA-compliant, BAA included · Built for California workers'-comp & med-legal billing
MindBill Book a Demo
Settings3 min readUpdated 2026-05-28

Managing users, roles, and MFA

A billing system holds protected health information and the keys to a practice's cash, so who can do what matters. Mindbill's team controls are role-based, MFA-enforced, and fully audit-logged. This walkthrough covers the team page and seats, the four roles, inviting a teammate, and enforcing security.

Step 1 — Open team management

Open Settings → Team (/settings/team). The header shows seats used against your plan limit (e.g. 5 / 25 on Self-Serve; unlimited on MindCollect and Enterprise) and how many users have MFA enabled. The roster below lists every teammate with their email, role, MFA status, and last-active time — your at-a-glance view of who has access and whether they've secured it.

Step 1 — Open team management

Step 2 — Understand the four roles

Mindbill has four roles, each scoped to least privilege. Owner: full access including billing, team, and account deletion — exactly one per account. Admin: full access except billing and account deletion, and can manage the team. Biller: can create, send, and appeal bills, but cannot touch team or billing. Read-only: view-only, for physicians and auditors who need visibility without edit rights. Assign the narrowest role that lets each person do their job.

Step 2 — Understand the four roles

Step 3 — Invite a teammate

Click Invite teammate, enter their email, and assign a role. The invite consumes a seat against your plan limit, so the seat counter updates immediately. The new user sets their own password and is required to enroll in two-factor authentication at first sign-in — you never handle their credentials, and the account is secured before it can touch a bill.

Step 3 — Invite a teammate

Step 4 — Enforce MFA, SSO, and the audit trail

New accounts require MFA at first sign-in, and admins can enforce MFA across the entire team so no seat goes unprotected. On Enterprise, SSO (Okta, Azure AD, Google Workspace) centralizes sign-in and offboarding. Every user action — sending a bill, filing an appeal, changing a setting — is captured in the account-wide audit log with the actor and timestamp, so access control and accountability are two sides of the same record.

Step 4 — Enforce MFA, SSO, and the audit trail

See it on your own bills.

A 15-minute demo on your workflow — bill entry, second review, and reporting. No slides.