Roles and Access
Access controls decide which product areas, pages, and actions a staff member can use. For HOME, the key value is the staff member's typeOfUser, which HOME maps to manager access, staff access, or no HOME access.
Quick Reference
| Access Check | Why It Matters | What To Do |
|---|---|---|
| Property | Staff may belong to more than one property. | Confirm the staff member is working in the expected property. |
| Module | HOME, Facility Booking, and Catalogue V3 can be enabled separately. | Confirm the product area is enabled before troubleshooting page access. |
| HOME role code | HOME access depends on the exact typeOfUser value. | Compare the staff member's role code with the tables on this page. |
| Access bucket | HOME pages are grouped as manager-facing or staff-facing. | Confirm whether the page expects manager or staff access. |
| HOME AI access | Supported HOME manager roles can use HOME AI when the property rollout is enabled. | Check the role and rollout availability when HOME AI is missing. |
| Assignment | Some workflows depend on team, department, or staff assignment. | Check assignment setup when the page opens but records are missing. |
How HOME Role Access Works
- HOME reads the staff member's
typeOfUser. - HOME maps that role code to
manager,staff, or no HOME access. - Manager-facing HOME pages require
manageraccess. - Staff-facing HOME pages require
staffaccess. - HOME AI is available to supported HOME manager roles when the HOME AI rollout is enabled for the property.
- MCP Setup remains available only to
EmployeeAdmin. - Unmapped role codes do not receive HOME page access.
Manager Access Roles
These roles are treated as HOME manager access.
| Friendly Role | Role Code | Typical Access |
|---|---|---|
| Employee Admin | EmployeeAdmin | HOME AI, setup, staff management, settings, reports, and manager dashboards. |
| HOME administrator | Home_Admin | HOME operational pages, employee access, and manager workflows; HOME AI when the rollout is enabled; not Feature Configuration or MCP Setup. |
| Super Admin | SuperAdmin | Broad manager access for setup, configuration, and operational review. |
| Operation Manager | OperationManager | Daily operations, assignments, reports, and manager workflows. |
| Housekeeping Supervisor | HousekeepingSupervisor | Housekeeping operations, room assignment, reports, and staff follow-up. |
| Client Admin | ClientAdmin | Property-level administration and manager workflows. |
| Duty Manager | Home_DutyManager | Duty manager workflows, operational review, and manager pages. |
| Maintenance Manager | Home_MaintenanceManager | Maintenance oversight, preventive maintenance, and manager pages. |
The other manager roles in this table can also receive HOME AI access when the rollout is enabled: Super Admin, Operations manager, Housekeeping supervisor, Client administrator, Duty manager, and Maintenance manager.
HOME administrator staff scope
HOME administrators can add, update, and delete staff whose role is a HOME employee type, including operational HOME roles and other HOME administrators. They cannot manage non-HOME employee roles from HOME. Feature Configuration and MCP Setup remain unavailable to this role; HOME AI can be available when the rollout is enabled.
Staff-Facing Roles
These roles are treated as HOME staff access for staff-facing pages.
| Friendly Role | Role Code | Default HOME Page | Notes |
|---|---|---|---|
| Room Attendant | housekeeping_staff | /room-attendant | Opens the room attendant workflow. |
| Engineer | Home_Engineers | /room-attendant/task | Opens the task attendant workflow. |
| Bellman | Home_Bellman | /room-attendant/task | Opens the task attendant workflow. |
| Operator | Home_Operator | /room-attendant/task | Opens the task attendant workflow. |
| F&B Staff | Home_FB | /room-attendant/task | Opens the task attendant workflow. |
| Concierge | Home_Concierge | /room-attendant/task | Opens the task attendant workflow. |
| Maintenance Staff | Home_Maintenance | /room-attendant/task | Opens the task attendant workflow. |
Home_DutyManager and Home_MaintenanceManager are also used in operational staff groupings, but HOME currently resolves them as manager access because manager roles are checked before staff roles.
Before You Start
- Confirm the staff member is using the correct property.
- Confirm the exact
typeOfUservalue on the staff account. - Confirm the module is enabled for the property.
- Confirm whether the blocked page is manager-facing or staff-facing.
- Confirm the staff member is assigned to the correct department or team when required.
How Access Behaves
- Staff who are not logged in are sent back to the login flow.
EmployeeAdminopens HOME at/home-aiby default; other recognized manager roles open HOME at/dashboard.- Room attendants with
housekeeping_staffopen HOME at/room-attendantby default. - Task attendant roles open HOME at
/room-attendant/taskby default. - Staff who open a page that requires a different access bucket see a not-authorized message and are returned to a safer page.
- A denied action during an active session shows the access reason without signing the staff member out.
- Staff with an unmapped role code do not receive HOME page access.
Security Page Access
The Security page is available from both manager and staff HOME shells.
| Staff Context | What They Can Use It For | What To Check |
|---|---|---|
| Manager HOME | Update password, review email update preferences, and manage passkeys where available. | Confirm the account has manager access if the page is missing. |
| Staff HOME | Update password and account security from the room attendant or task attendant flow. | Confirm the account has staff access if the staff Security page is missing. |
Security actions can be unavailable when the browser is offline or when the browser/device does not support the selected sign-in method.
HOME password requirements
When staff create or change a HOME password, the password must:
- Contain at least 12 characters.
- Include at least 3 of these 4 types: uppercase letters, lowercase letters, numbers, and supported symbols.
- Be different from the staff member's username.
- Not be a common password.
The password form shows which requirements are met while the password is entered. Supported symbols are ! @ # $ % ^ & * ( ) , . ? " : { } | < >.
Troubleshooting
Staff cannot see a module
What you see: The staff member logs in but does not see HOME, Facility Booking, or Catalogue V3.
Do this:
- Confirm the staff member is in the correct property.
- Check whether the module is enabled for that property.
- For HOME, confirm the staff member's exact
typeOfUser. - Compare the role code with the manager and staff role tables on this page.
- Ask the staff member to log out and log in again.
Staff sees a not-authorized message
What you see: The page does not open, or staff are sent back after trying to open it.
Do this:
- Confirm the page is manager-facing or staff-facing.
- Confirm the staff member's role code maps to the required access bucket.
- If the role is
Home_DutyManagerorHome_MaintenanceManager, treat it as manager access. - Ask a manager to open the same page.
- Update the staff role or assignment if the access is expected.
Staff lands on the wrong HOME page
What you see: The staff member logs in but lands on a page that does not match their expected workflow.
Do this:
- Confirm the staff member's exact
typeOfUser. - Check the default HOME page listed for that role.
- Confirm whether the staff member should be a manager, room attendant, or task attendant.
- Update the role code if the landing page does not match the staff member's job.
Staff can view a page but cannot update records
What you see: The page opens, but update actions are hidden or blocked.
Do this:
- Confirm the staff member should have edit access.
- Check whether the record is already closed or completed.
- Check whether the workflow also requires assignment to a team, department, room, or task.
- Ask a manager to try the same action.
- Contact support if managers are also blocked.
HOME AI or MCP Setup is missing
What you see: The manager signs in but cannot see HOME AI or MCP Setup in the HOME navigation.
Do this:
- Confirm whether the missing entry is HOME AI or MCP Setup.
- For HOME AI, confirm the account uses a supported manager role and the property rollout is enabled.
- For MCP Setup, confirm the account is
EmployeeAdmin. - Confirm the manager is using the expected property.
- Ask the manager to sign out and sign in again.
- Contact support if the eligible account still cannot access the expected entry.