Permissions are a compliance control, not just convenience
In a regulated workflow, who can do what is a safeguard. A clear separation between staff who prepare orders and prescribers who sign them, plus admin control over who is added and removed, reduces both errors and audit risk. A flat model where everyone can do everything is a liability as a clinic grows.
Because Refill does not document its roles model, ask precisely: what roles exist, can permissions be scoped per role, how are users invited and deactivated, and how does access work if you run more than one location? For multi-site clinics especially, confirm whether one account spans locations or each site is separate.