HavenSuiteRoles & permissions

Roles and Permissions

Roles should match real hotel duties. Permissions are enforced on the server, so removing a menu link is never treated as access control.

Security center and access controls

Recommended role map

RoleTypical workKeep restricted
OwnerHotel setup, staff, policies, approvals, financial oversight.Use sparingly; this role has the broadest authority.
ManagerShift supervision, exceptions, floor handovers, operational approvals.Platform billing and owner-only security settings.
ReceptionistBookings, check-in/out, room moves, folios, guest communication.Accounting configuration, role management, system settings.
HousekeepingAssigned rooms, cleaning tasks, minibar and inspections.Guest financials, staff management, rate changes.
MaintenanceTickets, room blocks, evidence, repair completion.Reservations, payments, owner settings.
AccountantInvoices, payments, journals, tax, dues, reconciliation.Room operations and staff access unless explicitly required.

Create a safe role

  1. Start from the closest operational role rather than an all-access role.
  2. Add only the permissions needed for the person’s normal shift.
  3. Separate high-risk actions such as refunds, overrides, exports, token management, and dispute resolution.
  4. Test with a temporary user assigned only to that role.
  5. Record who approved the change and review privileged roles regularly.

Practical examples

Night receptionist

Allow front desk, reservations, room rack, check-in/out, folio viewing, and approved payment actions. Do not grant staff management, API tokens, backup restore, or accounting configuration.

Floor manager

Allow assigned-floor room operations, condition inspection, handover signing, housekeeping review, and permitted overrides. Owner-only controls remain protected.

Quarterly access review

  • Disable dormant and departed users.
  • Confirm every privileged user still needs their role.
  • Review refund, override, export, API, and security-center activity.
  • Check floor-manager assignments and remove obsolete coverage.
  • Re-test critical roles after upgrades or permission-registry changes.
Principle of least privilege: if a task can be completed without a permission, leave that permission off. Owners can add access later without exposing historical guest or revenue data today.