Skip to content
For practices · The organisation console

One practice.
Clear boundaries.

See who is set up, manage your practice's defaults and check the evidence behind its privacy promises. Run the practice without reading your colleagues' consults.

Getting people started

An invitation is a credential, and it behaves like one.

Bound to one person

Give an address and the invite is bound to it — nobody else can redeem it, even holding the link. Leave it blank to hand a code over in person instead.

Shown once

The code is displayed when it is generated and only its hash is stored. Losing it means issuing another — it can never be read back out of the system, by anyone.

Revocable, and on the record

Revoking stops the link immediately. The invite is kept rather than deleted, so who issued it, who revoked it and why all stay legible afterwards.

The line

You can administer a practice without reading its consults.

Administration and clinical content are different permissions, and the console keeps them apart. Where an administrator genuinely needs to open content, the act is recorded and the clinician can see it — so the boundary is observable by the person it protects, not just asserted to them.

Sessions, as metadata

Who recorded, when, how long, which mode, whether a note was confirmed and whether audio is still retained. Not a word of the consult itself.

Opening content is an event

Reading clinical content writes an audit entry naming who read it. The clinician sees that entry. There is no quiet look.

Billing is its own key

Commercial access is granted separately from day-to-day administration, so running the roster does not hand someone the invoices.

Practice defaults

Decide once, for everyone, and say what is locked.

Processing modes, consent, retention, shared templates and your letterhead are set for the practice rather than negotiated per clinician. Where the platform holds a setting above you, the console marks it as locked instead of pretending it is yours to change.

Retention

Audio is deleted by default — Free deletes it when the first draft arrives; paid retains it encrypted for review and deletes it on confirmation by default; a practice can instead set immediate deletion or a short fixed retention window, and every mode sits under a hard 7-day ceiling. On AU Sovereign, Small Mercy stores the clinical record in Sydney and runs transcription and note drafting on vetted Australian services over private links — disclosed on every note under your organisation’s processing consent. The optional Global note fallback is currently disabled; if enabled, after an in-cell note-drafting failure a clinician may accept a single-use offer to send only that consult’s transcript for its note and later redrafts, never audio or other outputs. Global processing may occur outside Australia; the organisation and session stay AU Sovereign, with no automatic switch. Consent to record is separate for each consultation. Speaker identity is matched only on Small Mercy’s infrastructure. A Small Mercy-managed route outside Australia needs separate, explicit acceptance for that session and purpose. Sending a confirmed note or letter to connected practice software is a separate clinician action into the vendor account; Nookal’s Australian API service alone does not establish where that account stores data. Clinical data is never used to train models.

Templates and letterhead

Share note and letter templates across the practice and set the default one. Your address, letterhead and logo live with your letters, so what a patient receives looks like it came from you.

Evidence

Compliance you can read, rather than assurances you're given.

Every row on the compliance page is a live read of the running system — encryption at rest, consent captured before recording, the append-only guard on the audit trail, retention and deletion evidence. Not a checklist someone ticked. Where a check cannot be answered right now, it says so instead of passing.

An append-only audit log

Filter by the question you're actually asking — who read clinical content, who changed our policy, who signed in, what was exported — rather than by an action name you'd have to know. Export it as CSV; the export is itself recorded.

Usage per clinician

One month at a time: recorded consults, recorded minutes, consent capture and confirmed notes, per clinician and in total. Counts only — every number traces back to the sessions list. Exports as CSV.

Practice software

From today’s booking to a draft in Cliniko or Nookal.

We say “integrated” only when it actually is.

Cliniko and Nookal connect on paid plans for Australian and New Zealand practices. Today’s appointments come into Small Mercy, and once you have confirmed which patient a booking is, you start the consult from it. Once you confirm the note and check the patient a second time, Small Mercy files it into Cliniko or Nookal as a draft treatment note for you to finalise there — and reads it back before it says it was sent. A confirmed letter can be filed as a PDF copy on the patient’s record; you still send the letter itself. Nothing is written until you confirm and send. Everything else still exports as clean text and PDF you paste or attach: Best Practice, MedicalDirector, HealthLink, Medical Objects and My Health Record are on the roadmap, and we’ll say “integrated” only when it actually is.

Each system is set up the way it handles access. Cliniko is connected by each clinician with their own API key, so there is no practice-wide Cliniko credential to hold. Nookal is connected once for the practice by an organisation owner or integration administrator, who then maps each clinician to one Nookal practitioner and one location.

Per seat, one billing cycle for the practice.

Seats are a purchased quantity, not a headcount that creeps — the console shows how many are occupied against how many you bought. Pricing, tax treatment and annual terms are on the pricing page.

See practice pricingTalk to us about a practice