Hotel Staff Roles and Permissions
Most small hotels run on one shared login. It works until something goes wrong — a rate changed, a charge voided, a folio written off — and nobody can say who did it.
Why the Shared Login Eventually Costs You
A shared front desk login is the most common access arrangement in small hotels and the most expensive habit in the building. It is not primarily a security problem — it is an accountability one. Every discount, voided charge, rate override and written-off balance is recorded against the same account, so when a pattern appears in the numbers there is no way to trace it to a person, a shift or a mistake.
The losses that follow are rarely dramatic theft. They are ordinary: a rate overridden downward repeatedly by someone who does not understand the rate plan, a folio charge deleted rather than corrected, a cash payment recorded against the wrong reservation. Each is fixable if you can see who did it and retrain them. None is fixable if the audit trail says "frontdesk".
The second cost is offboarding. When a staff member leaves, a shared password means changing it for everyone — so most properties do not, and the departed employee retains access for months.
The Roles a Hotel Actually Needs
Seven cover almost every property. More than that is usually over-engineering.
The principle behind the table is least privilege: each role gets what the job needs and nothing beyond. The test is not "could they be trusted with it" but "does the job require it" — because access you never granted cannot be misused, leaked or accidentally changed.
The Access Decisions Worth Thinking About
- Who can change a rate. This is the highest-value permission in the building and the one most often given to everyone. A front desk agent needs to apply an existing rate; they rarely need to create or edit rate plans.
- Who can void or delete a charge. Corrections should usually be adjustments that leave a trail, not deletions that remove the evidence. If deletion exists at all, restrict it tightly.
- Who sees guest contact details. Housekeeping needs a room number and a task, not a phone number and an email address. Reducing who can see guest personal data is both a privacy obligation and a smaller breach surface.
- Who can see revenue reporting. Occupancy is operational; profit is not. Many properties are comfortable showing staff occupancy and arrivals while keeping ADR, RevPAR and revenue to managers.
- Who can add users. This is the permission that undoes all the others, and it belongs with one or two people.
For multi-property operators, add a scoping question on top: which properties each account can see. A receptionist at one property should not be able to open another property’s arrivals, and a group manager should not have to hold five separate logins.
Getting There Without Disrupting the Desk
- Create individual accounts for everyone who touches the system, including part-time and night staff. This alone captures most of the benefit, before you tune a single permission.
- Start permissive and tighten. Set roles roughly right, then narrow based on what people actually use over a month. Locking down hard on day one produces workarounds — usually the shared manager password you were trying to eliminate.
- Make the audit trail visible to managers. A permission model nobody reviews is just configuration; the value comes from occasionally looking at who changed what.
- Remove access the day someone leaves, and put it on the offboarding checklist next to returning the keys. Individual accounts make this a thirty-second job instead of a password change that disrupts everyone.
Frontdesko provides per-user staff accounts across administrator, manager, finance manager, front desk agent, housekeeper, maintenance and sales roles, scoped per property, with an audit trail recording status changes, room moves, rate adjustments and folio actions against the individual who made them.
Frequently Asked Questions
Why should hotel staff have individual logins?
Because a shared login destroys accountability. Every discount, voided charge, rate override and write-off is recorded against the same account, so when a pattern appears in the numbers there is no way to trace it to a person or a shift. Individual accounts also make offboarding a thirty-second job rather than a password change that disrupts everyone.
What staff roles does a hotel PMS need?
Seven cover almost every property: administrator, manager, finance manager, front desk agent, housekeeper, maintenance and sales. More than that is usually over-engineering. Each should get what the job requires and nothing beyond — the test is not whether the person can be trusted but whether the role needs the access.
What should a front desk agent be able to do?
Handle today’s arrivals, departures and in-house guests, take payments, post charges and manage folios. They generally should not configure rate plans, view profit-level reporting or administer users. Applying an existing rate is part of the job; creating and editing rate plans rarely is, and that is the highest-value permission in the building.
Should housekeepers see guest information?
Only what the task needs — a room number, the status and any relevant note. Guest phone numbers, email addresses and folio details are not required to clean a room, and restricting them reduces both your privacy exposure and the size of any breach. Housekeeping access should be scoped to room status and assigned tasks.
What is an audit trail in a hotel PMS?
A record of who changed what and when — status changes, room moves, rate adjustments, folio actions and write-offs, each tied to the individual staff account that performed it. It only works if staff have individual logins; with a shared account every entry reads the same and the trail proves nothing. Managers should review it occasionally rather than only after a problem.
How do permissions work across multiple properties?
Access should be scoped per property on top of the role. A receptionist at one property should not be able to open another property’s arrivals, while a group manager should see several properties without holding separate logins for each. Without scoping, multi-property operators end up either over-sharing access or juggling one account per property.
Know Who Changed What
Individual staff accounts across seven roles, scoped per property, with an audit trail covering status changes, room moves, rate adjustments and folio actions — free with the PMS.
Related Guides
Control and accountability
Security at Frontdesko
Encryption, per-property isolation and audit trails across the platform.
Learn More →GDPR Compliance for Hotels
Why limiting who sees guest data is an obligation, not just good practice.
Learn More →Housekeeping Management
Task assignment and room status for scoped housekeeping access.
Learn More →