Roles and Permissions
The seven built-in roles, the full resource-by-action permission catalogue, what each permission unlocks, and how the sidebar follows from it.
Every member of a property holds one or more roles, and a role is a grid of permissions: for each resource (reservations, folios, rooms, housekeeping, accounting and so on) the set of actions the role may perform. A person's permissions are the union of all their roles. The property owner — the account that registered the property — is outside the grid: the owner can do everything and is the only person who can manage roles and members.
Access control lives under Settings → Users & Permission, with two tabs: Users and Roles. Anyone who is not the owner and opens it sees Access Control is owner-only — Only the hotel owner can manage roles and permissions. Contact your hotel owner if you need access.
Hidden is not the same as blocked
The PMS hides what you cannot do, but the server checks every request independently. Hiding a button is a convenience; the permission behind it is the real boundary.
Built-in roles
Innvera seeds seven system roles. They are the same at every property, they are read-only (a lock icon and a System badge mark them), and the owner can Clone to customize any of them.
| Role | Description | What it grants |
|---|---|---|
| Administrator | Full access to every resource. Mirrors the hotel owner; assign to trusted staff. | Every action on every resource. Cannot manage roles or members — that stays with the owner. |
| Front Desk | Day-to-day reservations, guests, folio posting and messaging. | Reservation read write cancel · Guest read write · Folio read post · Room, Room Type, Rate Plan, Inventory read · Housekeeping read read_team · Messaging read write · Reports read · Accounting read cashier |
| Attendant | Works on housekeeping tasks assigned to this user. | Housekeeping read read_assigned work · Room, Reservation, Stores, Maintenance read · Lost & Found read write |
| Supervisor | Oversees the housekeeping team, assigns tasks and verifies completed work. | Housekeeping read assign work verify configure read_team · Room, Reservation, Stores, Maintenance read · Lost & Found read write |
| Storekeeper | Manages physical stock: items, receipts, stock counts and adjustments. | Stores read receive count manage · Housekeeping read read_team · Room read |
| Accountant | Accounting, folio and tax management with reporting. | Folio read post void · Tax read write · Reservation, Reports read · Accounting read close invoice configure export refund |
| Read-only | Read access to every resource; no mutations. | read on every resource, plus Housekeeping read_team. |
Two of these are deliberately narrow:
- The Front Desk role counts the drawer (
accounting: cashier) but cannot close the day or decide what an account means. It has noaccounting: closeand noaccounting: configure. - The Accountant role has every accounting action except
cashier: the person who reconciles the drawer should not be the person who counts it. It does holdrefund, because deciding a refund is a finance judgement — the desk requests one, an accountant or a manager approves it.
How the sidebar follows from this
Each sidebar entry names the permission it needs, so the menu is a direct readout of your roles. Nothing is configured separately: give someone maintenance: read and Maintenance appears; take it away and it goes.
Worked through for the seeded roles:
| Role | Sidebar |
|---|---|
| Front Desk | Dashboard, Arrivals & Departures, Calendar, Bookings, Groups, Companies & agents, Inventory, Guests · Rooms, Housekeeping, My tasks · Accounting |
| Accountant | Dashboard, Arrivals & Departures, Calendar, Bookings, Groups, Companies & agents · My tasks · Accounting · Settings |
| Supervisor | Rooms, Housekeeping, My tasks, Maintenance, Stores · Settings |
| Attendant | My tasks, Maintenance, Stores |
| Storekeeper | Rooms, My tasks, Stores |
Accounting answers to two permissions
Accounting and Companies & agents appear with either accounting: read or folio: read. accounting: read is the catalogue entry; folio: read stays as the proxy for roles created before it existed, so an older custom role that only grants folio access still reaches the ledger.
Settings appears when any one of hotel: write, hotel_content: write, user: read, housekeeping: configure, channex: read, booking_engine: read, tax: read, rate_plan: read or room_type: read is granted — the question it asks is "is there a single settings section this person can use?". That is why a Supervisor, whose only configuration permission is housekeeping: configure, still sees it.
My tasks has no check at all and is listed for everyone, so a member with no permissions whatsoever still has one page to open. And a Attendant-shaped set of permissions (can work housekeeping, cannot assign it) shortens the whole sidebar to My tasks, Maintenance and Stores — see Navigating the PMS.
The permission grid
The Roles tab shows the grid for the selected role: one row per resource, one checkbox per action, and the granted actions listed as badges under the resource name (No access when nothing is ticked). Read is the base action on every resource — ticking any other action ticks read automatically and locks it, and unticking the last non-read action leaves just read.
| Resource (as shown) | Actions | What they unlock |
|---|---|---|
| Reservation | read write cancel delete | See bookings, the calendar and the arrivals list; create and edit reservations, move rooms and dates, check in and out; cancel or mark no-show; delete. |
| Folio | read post void | See folios; record charges and payments; void a posted line or payment. Also opens Accounting and Companies & agents. |
| Guest | read write delete | See guest profiles; create and edit them; delete a guest with no reservations. |
| Room | read write | See rooms and their condition; create, edit, block (out of order) and change condition. |
| Room Type | read write delete | See room types; create and edit them; delete. |
| Rate Plan | read write delete | See rate plans and rates; create, edit and set restrictions; delete. |
| Inventory | read write | See the availability grid; change available units and bulk-update. |
| Tax | read write delete | See taxes and tax sets; create and edit; delete. |
| Meal Plan | read write delete | See meal plans; create and edit; delete. |
| Housekeeping | read assign work verify configure read_assigned read_team | See the board; assign rooms and publish the day; do the cleaning tasks; pass or fail inspections; edit housekeeping settings, sections, shifts, checklists and standards. The two scope bits narrow what a person sees: read_assigned is their own rooms, read_team is the whole team's. |
| Stores | read receive count manage | See stock on hand; receive deliveries; run stock counts; manage the catalogue and adjustments. |
| Maintenance | read write assign close approve | See work orders; raise and edit them; assign to a person; close; approve a request someone else raised. |
| LostAndFound | read write release dispose | See lost items; log and edit; release to the owner; dispose. |
| Hotel | read write | See property settings; edit the property, its address and contacts. |
| Hotel Content | read write | See and edit images, facilities, amenities, FAQs, the published policies and the Stay Rules. |
| Channex | read manage | See channel connections and sync state; connect, map and resync channels. |
| Booking Engine | read write | See booking-engine settings; edit them. |
| Messaging | read write | Read guest message threads; reply. Also decides the navbar Chat icon. |
| Reports | read | Open the Dashboard and the other reports. |
| Accounting | read close invoice cashier configure export refund | See the ledger; run the night audit (close — the one irreversible act); raise and send invoices; handle the cash drawer; edit accounting configuration, taxes and numbering; run exports; decide a refund request. |
| User | read write delete | See other staff profiles; edit; delete. Managing roles and memberships is still owner-only. |
Access control itself is not a resource: only the owner can invite members, assign roles or edit grants, whatever a role says.
Stay Rules and published policies are Hotel Content, not Hotel
The Stay Rules and OTA Policy tabs under Settings → Property read with hotel_content: read and save with hotel_content: write, while the General, Address and Contact Information tabs need hotel: write. A role meant to manage fee ladders needs the content permission, not just the property one.
Manage users
Open Settings → Users & Permission → Users. The list shows each member's name, email, an Owner badge with Full access for the owner, and their roles as removable badges.
Invite staff
Click Invite staff. Enter First name, Last name and Work email, pick one role under Access pass, then click Send invite. An account is created (or an existing Innvera account with that email is reused) and an invite email goes out; the link is valid for 7 days. The member appears in the list immediately with the chosen role, and an entry is written to the audit log.
Add or remove roles
Use the Add role… dropdown on a member's row to grant another role; a member can hold several, and their permissions are the union. Click the × on a role badge to remove it, confirming Remove this role?. The owner's row has no role controls; the owner does not need a role.
Remove a member
Click the remove icon at the end of the row and confirm Remove this member?. The person loses access to this property only; their account and any other memberships remain. The owner cannot be removed.
An invite to an email that is already a member fails with User is already a member of this hotel; remove the member first if you need to re-invite them.
Manage roles
Open Settings → Users & Permission → Roles. The left column lists the seven system roles and your property's own roles.
Create a role
Type a name in New role name and click +. The new role starts with no access. Alternatively select a system role and click Clone to customize to start from its grid.
Set its permissions
Tick or untick actions in the grid. Nothing is sent until you click Save changes; the button stays disabled while the grid matches what is saved. System roles show the grid greyed out with the note System roles are read-only templates. Clone this role to create an editable copy for your hotel.
Delete a role
Select a custom role and click Delete, then confirm Delete this role?. Staff who held the role lose the permissions it granted. System roles cannot be deleted or edited.
Permission changes take effect on the member's next request; they do not need to sign out.
Common mistakes
- Giving an attendant the Supervisor role. Supervisor can
assign, which turns the full sidebar back on and pushes My tasks below the board. Attendant is the role you want for someone who only cleans rooms. - Expecting Administrator to manage users. Only the owner can. An Administrator sees Access Control is owner-only.
- Editing a system role. The grid is read-only; use Clone to customize and assign the clone.
- Granting
folio: readand expecting the night audit. Closing the day isaccounting: close, which is a separate decision from reading the ledger. - Ticking
writewithoutread. You cannot — read is implied and the checkbox locks. This is by design.
Related
Navigating the PMS
The four sidebar groups and what each screen is for, how permissions decide what you see, what attendants and platform admins get instead, and global search.
Overview
The screens a front desk agent uses all day — dashboard, the arrivals and departures board, the calendar, bookings, availability and guest profiles.

