Skip to content

From a spreadsheet to a roster that warns you

Every credentialing product claims it will warn you before things expire. The specifics are the only part that matters, so this page gives you the actual rules rather than the promise.

Rules last reviewed

Stage one

Getting your roster in

The cold start is where most credentialing tools lose people. There is no CAQH participation gate here and no eligibility check to clear first.

  1. Sign up and finish the wizard

    Three steps: create a client practice, add a provider, and add that provider's first credential with its alert. It deliberately uses the same credential dialog you will use forever after, so you finish onboarding holding a real tracked deadline rather than a sample row you have to delete later.

  2. Import the rest by CSV

    Upload a spreadsheet export and map your columns to RosterSafe fields. Valid rows insert and invalid rows come back with their reasons, so one bad date does not reject the file. Re-importing a corrected or updated list adds affiliations rather than creating duplicate providers.

  3. Fill the gaps from NPPES

    Look providers up by NPI against the free official CMS registry to populate names, taxonomy and specialty, either one at a time from the provider form or in bulk across an imported roster. Enrichment only writes to empty fields, so nothing you typed is ever overwritten.

Stage two

The deadline engine, precisely

This is the product. Everything else is somewhere to put the data it watches. These are the real rules, not a simplified version of them.

When do credential expiration alerts fire?

  • You set the windows. Default 90, 60, 30 and 7 days before expiry. One to ten windows, each between 1 and 365 days.
  • Each window fires once per expiry date, so entering the 60-day window does not re-send the 90-day warning. Reconfiguring your windows does not re-fire ones that already went.
  • Inside the final window it repeats daily, deduplicated per calendar day. Acknowledging silences the daily repeat for that window without silencing the next one.
  • A lapse alerts every day until it is fixed, and overrides both snooze and acknowledgment. There is no way to accidentally make a lapsed credential go quiet.
  • Unacknowledged alerts escalate to the owner after a number of days you choose, once per expiry date.
  • Renewing resets everything and fires a completion event, so a renewed credential starts its next cycle clean.

Days are counted on your calendar, not UTC

Your firm sets its time zone and every day boundary follows it: days-until, the alert windows, the digests, and the daily export limit. Counted in UTC instead, an overnight sweep calls a license lapsed while it is still hours valid on the West Coast, and the export allowance resets mid-afternoon. This sounds like a detail and is not: the number is the entire product, so the clock it is counted on has to be a decision rather than an accident.

Stage three

The week after that

Credentialing deadlines are a steady weekly drip, not an annual event. At 50 providers something is expiring nearly every week, so the daily surfaces matter more than the reports.

Today

The work queue. What needs doing now, grouped by status, scoped to what is assigned to you. This is the screen a credentialing coordinator lives in.

Roster board

Traffic-light health across the whole book, with a horizon band showing how close each provider is to trouble. Proximity is encoded by length and position, not by colour alone, so it survives grayscale.

Dashboard

Deadlines across the next 90 days as the dominant element, above a reading line of six figures: active providers, at-risk providers, lapsed credentials, exclusion flags, client practices, and revenue exposure per day.

Alerts

Everything the engine has fired, with snooze and acknowledge. Each notification carries its own per-channel delivery record, so whether a given alert actually went out by email is answerable rather than assumed.

Throughout

All of it, across every client practice

This is the part built for a billing firm rather than a single practice, and it is the thing competitors are not shaped for.

How does RosterSafe handle multiple client practices?

  • Client practices are a core object, not a tag. Every provider, credential, document and enrollment belongs to one.
  • The rollup across all of them is the default view, and filtering down to one practice is the exception rather than the other way round.
  • A client can have a read-only login pinned to their own practice, showing their roster and nobody else's. The pin is enforced by the database and derived from the role on the server, never passed through from the browser.
  • Per-client credentialing health reports for the conversation where a client asks how their roster is doing.

Also included

The rest of the job

Payer enrollments

Status per payer, per practice, per provider, with application tracking and the CAQH 120-day re-attestation clock as a first-class date rather than a note in a cell.

Document vault

License copies and certificates with their own expiry alerts, plus request links so a provider can upload a document without needing an account.

Exclusion screening

The roster screened on a schedule against OIG-LEIE and SAM.gov, so you never bill a claim for an excluded provider. For a billing firm that is False Claims Act protection.

Reporting and exports

Filterable exports built to be sent to a client or a payer, an audit trail of who changed what, and scheduled reports that arrive without anyone remembering to run them.

Questions about getting started

How long until I see something real?
One session. The first-run wizard takes you through creating a client practice, a provider, and its first tracked credential, so you finish setup with a real deadline rather than a demo row. If you have a CSV, the import route gets a whole roster in faster than that.
What if my spreadsheet columns are named differently?
That is expected, and the import has a column mapping step for exactly that reason. No two firms name their columns the same way. Rows that fail validation come back with the reason rather than failing the whole file, so a messy export still gets you most of the way in one go.
Do I have to enter every provider detail by hand?
No. Look a provider up by NPI and RosterSafe pulls their details from the free NPPES registry. Enrichment only fills fields that are empty, so registry data never overwrites something you typed. You can also enrich a whole imported roster in bulk.
What happens if I import the same file twice?
You get affiliations added, not duplicate providers. Re-importing is a normal thing to do when a client sends an updated list, so it is designed to be safe rather than destructive.
Can I change when the alerts fire?
Yes. The default is 90, 60, 30 and 7 days before expiry, and you can set anywhere from one to ten windows, each between 1 and 365 days. If you reconfigure them, windows that already fired do not fire again, so changing your mind does not produce a burst of duplicate alerts.
What happens if something lapses anyway?
It keeps alerting daily until it is resolved, and a lapse overrides both snooze and acknowledgment. This is deliberate: the moment a deadline passes is the moment the alerts matter most, and going quiet there is the single failure this product exists to prevent.

Put one real provider in

Free forever for one provider, no card. Pick the most complicated one you have and see whether the deadline picture is clearer than what you get today.

Get Started Free