InnveraDocs
Getting Started

Roles and Permissions

The seven built-in roles, the full resource-by-action permission catalogue, what each permission unlocks, and how the sidebar follows from it.

Every member of a property holds one or more roles, and a role is a grid of permissions: for each resource (reservations, folios, rooms, housekeeping, accounting and so on) the set of actions the role may perform. A person's permissions are the union of all their roles. The property owner — the account that registered the property — is outside the grid: the owner can do everything and is the only person who can manage roles and members.

Access control lives under Settings → Users & Permission, with two tabs: Users and Roles. Anyone who is not the owner and opens it sees Access Control is owner-only — Only the hotel owner can manage roles and permissions. Contact your hotel owner if you need access.

Hidden is not the same as blocked

The PMS hides what you cannot do, but the server checks every request independently. Hiding a button is a convenience; the permission behind it is the real boundary.

Built-in roles

Innvera seeds seven system roles. They are the same at every property, they are read-only (a lock icon and a System badge mark them), and the owner can Clone to customize any of them.

RoleDescriptionWhat it grants
AdministratorFull access to every resource. Mirrors the hotel owner; assign to trusted staff.Every action on every resource. Cannot manage roles or members — that stays with the owner.
Front DeskDay-to-day reservations, guests, folio posting and messaging.Reservation read write cancel · Guest read write · Folio read post · Room, Room Type, Rate Plan, Inventory read · Housekeeping read read_team · Messaging read write · Reports read · Accounting read cashier
AttendantWorks on housekeeping tasks assigned to this user.Housekeeping read read_assigned work · Room, Reservation, Stores, Maintenance read · Lost & Found read write
SupervisorOversees the housekeeping team, assigns tasks and verifies completed work.Housekeeping read assign work verify configure read_team · Room, Reservation, Stores, Maintenance read · Lost & Found read write
StorekeeperManages physical stock: items, receipts, stock counts and adjustments.Stores read receive count manage · Housekeeping read read_team · Room read
AccountantAccounting, folio and tax management with reporting.Folio read post void · Tax read write · Reservation, Reports read · Accounting read close invoice configure export refund
Read-onlyRead access to every resource; no mutations.read on every resource, plus Housekeeping read_team.

Two of these are deliberately narrow:

  • The Front Desk role counts the drawer (accounting: cashier) but cannot close the day or decide what an account means. It has no accounting: close and no accounting: configure.
  • The Accountant role has every accounting action except cashier: the person who reconciles the drawer should not be the person who counts it. It does hold refund, because deciding a refund is a finance judgement — the desk requests one, an accountant or a manager approves it.

How the sidebar follows from this

Each sidebar entry names the permission it needs, so the menu is a direct readout of your roles. Nothing is configured separately: give someone maintenance: read and Maintenance appears; take it away and it goes.

Worked through for the seeded roles:

RoleSidebar
Front DeskDashboard, Arrivals & Departures, Calendar, Bookings, Groups, Companies & agents, Inventory, Guests · Rooms, Housekeeping, My tasks · Accounting
AccountantDashboard, Arrivals & Departures, Calendar, Bookings, Groups, Companies & agents · My tasks · Accounting · Settings
SupervisorRooms, Housekeeping, My tasks, Maintenance, Stores · Settings
AttendantMy tasks, Maintenance, Stores
StorekeeperRooms, My tasks, Stores

Accounting answers to two permissions

Accounting and Companies & agents appear with either accounting: read or folio: read. accounting: read is the catalogue entry; folio: read stays as the proxy for roles created before it existed, so an older custom role that only grants folio access still reaches the ledger.

Settings appears when any one of hotel: write, hotel_content: write, user: read, housekeeping: configure, channex: read, booking_engine: read, tax: read, rate_plan: read or room_type: read is granted — the question it asks is "is there a single settings section this person can use?". That is why a Supervisor, whose only configuration permission is housekeeping: configure, still sees it.

My tasks has no check at all and is listed for everyone, so a member with no permissions whatsoever still has one page to open. And a Attendant-shaped set of permissions (can work housekeeping, cannot assign it) shortens the whole sidebar to My tasks, Maintenance and Stores — see Navigating the PMS.

The permission grid

The Roles tab shows the grid for the selected role: one row per resource, one checkbox per action, and the granted actions listed as badges under the resource name (No access when nothing is ticked). Read is the base action on every resource — ticking any other action ticks read automatically and locks it, and unticking the last non-read action leaves just read.

Resource (as shown)ActionsWhat they unlock
Reservationread write cancel deleteSee bookings, the calendar and the arrivals list; create and edit reservations, move rooms and dates, check in and out; cancel or mark no-show; delete.
Folioread post voidSee folios; record charges and payments; void a posted line or payment. Also opens Accounting and Companies & agents.
Guestread write deleteSee guest profiles; create and edit them; delete a guest with no reservations.
Roomread writeSee rooms and their condition; create, edit, block (out of order) and change condition.
Room Typeread write deleteSee room types; create and edit them; delete.
Rate Planread write deleteSee rate plans and rates; create, edit and set restrictions; delete.
Inventoryread writeSee the availability grid; change available units and bulk-update.
Taxread write deleteSee taxes and tax sets; create and edit; delete.
Meal Planread write deleteSee meal plans; create and edit; delete.
Housekeepingread assign work verify configure read_assigned read_teamSee the board; assign rooms and publish the day; do the cleaning tasks; pass or fail inspections; edit housekeeping settings, sections, shifts, checklists and standards. The two scope bits narrow what a person sees: read_assigned is their own rooms, read_team is the whole team's.
Storesread receive count manageSee stock on hand; receive deliveries; run stock counts; manage the catalogue and adjustments.
Maintenanceread write assign close approveSee work orders; raise and edit them; assign to a person; close; approve a request someone else raised.
LostAndFoundread write release disposeSee lost items; log and edit; release to the owner; dispose.
Hotelread writeSee property settings; edit the property, its address and contacts.
Hotel Contentread writeSee and edit images, facilities, amenities, FAQs, the published policies and the Stay Rules.
Channexread manageSee channel connections and sync state; connect, map and resync channels.
Booking Engineread writeSee booking-engine settings; edit them.
Messagingread writeRead guest message threads; reply. Also decides the navbar Chat icon.
ReportsreadOpen the Dashboard and the other reports.
Accountingread close invoice cashier configure export refundSee the ledger; run the night audit (close — the one irreversible act); raise and send invoices; handle the cash drawer; edit accounting configuration, taxes and numbering; run exports; decide a refund request.
Userread write deleteSee other staff profiles; edit; delete. Managing roles and memberships is still owner-only.

Access control itself is not a resource: only the owner can invite members, assign roles or edit grants, whatever a role says.

Stay Rules and published policies are Hotel Content, not Hotel

The Stay Rules and OTA Policy tabs under Settings → Property read with hotel_content: read and save with hotel_content: write, while the General, Address and Contact Information tabs need hotel: write. A role meant to manage fee ladders needs the content permission, not just the property one.

Manage users

Open Settings → Users & Permission → Users. The list shows each member's name, email, an Owner badge with Full access for the owner, and their roles as removable badges.

Invite staff

Click Invite staff. Enter First name, Last name and Work email, pick one role under Access pass, then click Send invite. An account is created (or an existing Innvera account with that email is reused) and an invite email goes out; the link is valid for 7 days. The member appears in the list immediately with the chosen role, and an entry is written to the audit log.

Add or remove roles

Use the Add role… dropdown on a member's row to grant another role; a member can hold several, and their permissions are the union. Click the × on a role badge to remove it, confirming Remove this role?. The owner's row has no role controls; the owner does not need a role.

Remove a member

Click the remove icon at the end of the row and confirm Remove this member?. The person loses access to this property only; their account and any other memberships remain. The owner cannot be removed.

An invite to an email that is already a member fails with User is already a member of this hotel; remove the member first if you need to re-invite them.

Manage roles

Open Settings → Users & Permission → Roles. The left column lists the seven system roles and your property's own roles.

Create a role

Type a name in New role name and click +. The new role starts with no access. Alternatively select a system role and click Clone to customize to start from its grid.

Set its permissions

Tick or untick actions in the grid. Nothing is sent until you click Save changes; the button stays disabled while the grid matches what is saved. System roles show the grid greyed out with the note System roles are read-only templates. Clone this role to create an editable copy for your hotel.

Delete a role

Select a custom role and click Delete, then confirm Delete this role?. Staff who held the role lose the permissions it granted. System roles cannot be deleted or edited.

Permission changes take effect on the member's next request; they do not need to sign out.

Common mistakes

  • Giving an attendant the Supervisor role. Supervisor can assign, which turns the full sidebar back on and pushes My tasks below the board. Attendant is the role you want for someone who only cleans rooms.
  • Expecting Administrator to manage users. Only the owner can. An Administrator sees Access Control is owner-only.
  • Editing a system role. The grid is read-only; use Clone to customize and assign the clone.
  • Granting folio: read and expecting the night audit. Closing the day is accounting: close, which is a separate decision from reading the ledger.
  • Ticking write without read. You cannot — read is implied and the checkbox locks. This is by design.

On this page