# Flow: Admin Monitoring (Super Admin & Clinic Admin)

**Actors**: Super Admin (platform-wide), Clinic Admin (own branch only, via branch scoping)
**Phase**: 1 for the base screens, 4 for full Reports/Offers (`05-roadmap.md`)

## Super Admin — platform-wide, unrestricted (`admins.branch_id IS NULL`)

1. **Clinics**: `Admin\Clinic\ClinicController::index()` — every branch with a `ClinicProfile`,
   create/edit/disable/delete, assign/reassign a Clinic Admin.
2. **Users**: existing `Admin\Users\UsersController` — activate/disable any account, reset
   passwords; already generic, no Clinic-specific change needed beyond the new `Clinic Admin`/
   `Receptionist` roles being selectable there.
3. **Monitoring**: `Admin\Clinic\Reports\ClinicReportController` (or a dedicated cross-branch
   dashboard) — live KPIs (today's/month's bookings, revenue, active clinics), filterable by
   branch/date/status, read-only (no booking edits from here — that's `Admin\Clinic\BookingController`).
4. **Reports**: bookings, `clinic_payments` revenue, doctor/clinic performance, ratings — filterable
   and comparable across branches, following the shape of existing Finance/HR report controllers
   (e.g. `app/Http/Controllers/Admin/Finance/Reports/*`).
5. **Reviews**: `Admin\Clinic\...` review moderation list (read; the brief doesn't call for
   Super Admin to edit/delete reviews, only view them).
6. **Policies**: `Admin\Clinic\Setup\PolicyController` — default cancellation/reschedule windows,
   default commission %, active payment gateways (reuses `PaymentGatewayController`).
7. **Offers**: `Admin\Clinic\OfferController` — platform-wide offers (`branch_id = null`).

## Clinic Admin — branch-scoped (`admins.branch_id` set, enforced per `03-permissions-and-roles.md`)

Same controllers as above where permitted (`Bookings`, `Patients`, `Reports`, local `Offers`,
`Doctors`, `Schedules`), automatically filtered to their own `branch_id` by the
`BelongsToClinicBranch` scope / policy checks — **no separate controller code path**, the
restriction is data-layer, not a different screen.

## Receptionist — branch-scoped, narrower permission set

Only `clinic.bookings.*` and `clinic.patients.view` (see `03-permissions-and-roles.md` roles) —
same `Admin\Clinic\BookingController`/`PatientController`, just fewer granted permissions, so
create/edit/schedule/reports/offers routes 403 for this role even though the controllers are shared.

## What none of these three ever see

Precise medical detail (`clinic_medical_records`, `clinic_patient_profiles` medical fields) —
enforced by never loading those relations/columns in any `Admin\Clinic\*` code path, regardless
of role or branch scope (see `03-permissions-and-roles.md` §4).
