Giving staff access to your booking system — without opening up your whole administration
Your housekeeper needs to know which rooms are leaving, your holiday stand-in needs to enter a booking, your bookkeeper only wants the figures. None of them needs your full guest list or revenue. Here is how to divide access without sharing your password.
Share on LinkedIn
As long as you do everything yourself, access is not a topic. You log in, you see everything, done. It only becomes a question the moment a second person joins: a housekeeper who wants to see for herself which rooms are leaving tomorrow, a family member taking over for two weeks while you are away, or a bookkeeper asking whether he can "look in somewhere".
And then the same thing happens at a great many properties: the password gets passed around. One login, three people. It works — until it does not.
Why one shared login eventually goes wrong
Three problems, and all three do happen.
You no longer know who did what. A booking is on the wrong room, a price has been changed, a guest was accidentally marked as departed. With one shared login there is nobody to ask — not because people lie, but because nobody remembers. With separate accounts, the log shows who made the change and when.
Everyone sees everything. Your cleaner has no reason at all to be able to open your monthly revenue, your Booking.com commissions, or the phone number and address of every guest from the past two years. That is not about trust: it is simply an unnecessary risk. If her phone is stolen, or she logs in on a shared computer, your entire guest database is exposed. Under the GDPR you are the one accountable for that, not her — more on this in storing guest data and the GDPR.
You cannot close it off cleanly. A seasonal helper stops in October. With a shared password you have to change that password and hand the new one to everybody else. In practice that does not happen, and a former helper still has access months later. With separate accounts you switch one off and you are done.
Who actually needs what?
It helps to make this concrete per role rather than talking about "permissions" in the abstract.
Housekeeping. Needs: which rooms are leaving today, which are arriving, which are staying on, and whether there is anything special (extra bed, late check-out, allergy). Does not need: prices, revenue, guest addresses, invoices. A cleaning list is really a daily overview with the money taken out. How to build that schedule is covered in housekeeping between check-out and check-in.
Holiday stand-in or front desk help. Needs: see the calendar, enter a booking, check a guest in, move a booking, send the guest an email. Does not need: to change your rates structurally, disconnect channels, or edit your invoicing settings. That is the most dangerous part to open up: one wrong click in your rate rules or channel settings carries through to every platform, and you only notice days later.
Bookkeeper. Needs: revenue, VAT split, invoices, tourist tax. Does not need: the calendar or the guest messages. Usually a bookkeeper does not want a login at all but an export or a connection — see automating your bookkeeping.
Co-owner or partner. They do need everything. That is the one role where full access makes sense.
Put those four lists side by side and it is striking how small the overlap is. Which is exactly why one shared login is such a blunt instrument.
In practice: how to set it up
In BedFlow PMS you work with separate users per person, each with their own role. You invite someone on their own email address, they choose their own password, and you decide what that role may see. A housekeeping role gets the daily overview and room statuses; a front desk user gets the calendar and the bookings; only an owner gets the financial and technical settings.
If you manage several properties, another dimension is added: access per property. The helper at your coastal holiday home does not need to see the bookings of your city property. How that split works is in managing multiple properties.
Four rules of thumb that keep it simple:
- One person, one account. Never an account named after a function ("cleaning") that three people log in to.
- Grant as little as works. Start tight. Someone who is missing something will say so within the week; someone who can do too much says nothing.
- Switch accounts off on departure, not "later". Put it on your end-of-season checklist, next to the keys.
- Turn on two-factor authentication on your own account. You are the only one with full access; that account is worth protecting properly.
The objection you usually hear
"There are only two of us, this is overkill." Maybe. But the reason to do it anyway is not distrust — it is peace of mind. If in September you want to know why that three-night booking is suddenly two nights, you want to find the answer in the log and not in a conversation. And if in July you want to be away for two weeks without checking your email every evening, you want to be able to let someone help without feeling that you are handing over your entire business.
That is ultimately what roles and permissions are for: not to keep people out, but to be able to let them in.
Want to see what that looks like in practice? BedFlow PMS is free to try for 30 days at bedflow.eu — separate users with their own roles, a log of every change, and access per property. How to add users and set roles is covered step by step in the manual; what it costs after that is on our pricing page. No credit card required.
30-day free trial, no credit card. We migrate your MyTourist or other PMS data with you.