All documentationAdministration

Admin portal

The Admin section is where administrators manage people, clients, website analytics, the audit trail and system health. Only accounts with the Administrator role see it.

Opening the Admin section#

Select Admin in the console sidebar. A second sidebar lists the admin sections: Overview, Users, Clients, Website analytics, Audit log and System health. On a phone, use the Switch admin section menu instead. The top bar title reads "Admin / {section}".

Ops accounts do not see Admin. They work in the rest of the console; see Console.

Overview#

Overview answers: what needs an admin now, what changed lately, and is the service answering.

  • Quick actions: New user and New client.
  • Needs attention: a list of items, each with a severity chip, a count, up to five examples and a Review link.
  • Recent activity: the latest changes, with View audit log.
  • A system strip showing whether the database is responding. It links to System health.
SeverityItemWhat to do
Act nowOnly one active adminMake a second person an internal admin.
Act nowAccounts with repeated failed sign-ins (5 or more in 24 hours)Check the attempts and contact the account holder.
AccessActive clients nobody can sign in toCreate or grant a client login.
AccessEnded contracts with live loginsRemove their access.
AccessClient accounts with no dashboardShow one of their clients on their dashboard.
HousekeepingAccounts that never signed inResend the sign-in details, or suspend the account.
HousekeepingAccounts idle for a long timeConfirm the account is still needed, or suspend it.

When nothing is listed, the card says All clear.

Users#

Users lists everyone with a Medical3 sign-in. Search by name or email, and filter by Role, Status (Active, Suspended or Inactive), Activity (never signed in, or dormant) and Access (No dashboard). Select a row to open that person's details. Roles are Client, Internal ops and Internal admin.

Creating a user

  1. Select New user.
  2. Enter the Email and Name, and choose the Role.
  3. For a client, choose the Client. It is required, and their dashboard opens on it.
  4. Leave Email the invite to them on to send the link by email. Turn it off if you will share the link yourself.
  5. Select Create user. The button changes to Confirm create; select it.
  6. The Setup link appears with a Copy button, its expiry time and whether the email went out. If it was not emailed, send the link yourself.
  7. Select Done, or Create another.

Important: Anyone with the link can set the password. Share it only with its owner. An invite link is valid for 72 hours and works once.

Managing a user's access

The user drawer shows their email, role, status, last sign-in, sign-in count and workspaces. Under Manage access you can:

ActionEffect
Change roleChanges what they see and do, immediately.
Suspend accountAsks for a reason. They lose access on their next request and cannot sign in until you choose Reactivate account.
Send a new setup link or Send password reset linkSigns them out everywhere, stops their current password and cancels earlier links. A reset link lasts 24 hours.
Sign out everywhereEnds every session on every device.

Edit profile changes their name or email. Changing the email signs them out everywhere. Recent activity lists admin changes to this account.

Under Client access, Show on dashboard switches which client their dashboard shows; the client it shows now carries the On dashboard chip. Remove access ends access to a client. It also removes their access to that client's workspace and disconnects any mailbox they connected there. It is refused if the person is the only Admin of that client's workspace. If you remove the client their dashboard shows, they are left with no dashboard.

You cannot change your own role, name, email, suspension or setup link in Users; use Settings for your own profile. The last active internal admin cannot be demoted or suspended.

Clients#

Clients holds client records. Search by client name, and filter by Category, Type (Clients or In negotiation), Login (No login or Has login) and Contract (Active or Ended). The list also shows logins, contract end date and whether a workspace exists.

To add a client, select New client. Enter the Client name, Category, Gross margin assumption (%), Annual overseas revenue, the contract dates, and tick Prospect (not yet signed) if it applies. Then select Create client.

Select a row to open the provisioning drawer:

  • Edit client: name, category, margin, revenue, contract dates and prospect status.
  • Service engagement: the service period, target countries, target products and period goals. Saving replaces the whole record.
  • Fee agreement: monthly fee, project fee, success fee percentage, tail fee and milestone fees. Blank fields stay unchanged; submitted milestone fees replace the existing list.
  • Members: everyone with access to this client.
  • Account access: type a user's email, choose whether to Show this client on their dashboard, and select Grant access. The account must already exist; create it under Users first.

Website analytics#

Website analytics shows visits, traffic sources, clicks and conversions on the Medical3 website. It counts only visitors who accepted analytics cookies, and it excludes browsers that have signed in to Medical3, whether staff or client. Real traffic is therefore higher than shown.

Choose Last 7 days, Last 30 days, Last 90 days, or a custom From and To range in UTC of up to 400 days, then select Apply. Download CSV exports the data.

The headline figures are Sessions, Visitors, Pageviews, Pages / session, Median session, Bounce rate, Contact requests, Newsletter sign-ups and Conversion rate. Cards below cover Daily trend, Channels, Contact funnel, Referrers, Campaigns, Top pages, Landing pages, Clicks, Countries and Technology.

Audit log#

The Audit log lists changes to accounts, access and billing, newest first. Filter by Action, Record type, Record ID, Changed by, From and To (UTC), or use the quick ranges Today, Last 7 days and Last 30 days.

Failed sign-ins appear only when you set Action to Sign-in failed.

Select an entry to see its Changes (the old and new values), its Details, and a link to Only this person's changes. Export CSV exports every entry that matches your filters, not just the current page.

System health#

System health is read-only. It shows whether the database is reachable, its ping latency and the latest applied migration. It also shows the running service revision and uptime. Under Integrations, the system email, Microsoft 365 connection and website analytics collection each show Configured or Not configured.

If an integration shows Not configured, or the database is unreachable, contact Medical3 support. This page only reports status.

Arm then confirm#

Changes to people and access use two clicks: creating a user, changing a role, suspending an account, sending setup links, signing people out, editing a profile, and granting, switching or removing client access. The first click arms the action: the button turns amber, changes its label to a confirmation such as Confirm create, and a sentence explains the consequence. The second click performs it. Press Esc or click elsewhere to disarm without changing anything.

Saving client records, service engagement and fee agreements, and Reactivate account, take one click. Invoice steps have their own safeguard: Void arms in red, and invoice buttons do not disarm on Esc. See Money.

Read the consequence sentence each time. Some actions, like signing someone out or voiding an invoice, take effect immediately. See Safety rules.