Skip to content

The roles matrix

The role library holds 24 roles: 20 operational roles and 4 account roles. Every seat carries exactly one account role plus any number of operational roles, and holds the union of their permissions. What a seat sees follows mechanically from what it holds - see Roles and the shape of your sidebar.

Two floors sit underneath the tables below:

  • Universal: every role, without exception, can read its own notifications (the bell).
  • The member read floor: most operational seats also share a baseline of read-only screens. In the tables, “the shared screens” means exactly this set: Today, Inquiries, Bookings, Past Stays, Guest Screening, Guests, Reviews, Extensions, Lock Codes, Calendar, Daily Report.

Some screens are additionally plan-gated: Airbnb (channel manager) and Bookings to Review need the channel-sync feature; ROI, Monthly Break-even, P&L Report, the property Finance tab, Assets, and Period Close need the finance suite; the two external portals need the portals feature. A seat whose role reaches such a page on a plan without the feature sees it locked, pointing at Billing.

Role Who it’s for What it reaches and does
Admin The operator running the workspace Every screen in the app except the Housekeeping queue and the two external portals (Owner Portal, Investor Portal). Full org config: Settings, Team, Duty Roster, Billing, Audit, Fees & Taxes, Bank Accounts, properties and listings, guest app, booking website, channels, imports, message templates, Agent Hub (view and manage - including the door-code rule), tax rules, the full finance read suite, expense capture and categories. Deliberately not held: verifying payments, recording transactions, refunds, cancelling bookings, sending lock codes, and housekeeping work - those stay with the roles below.
Owner The person whose property you operate - external Owner Portal only (their own properties’ statements and bookings, scoped to themselves), plus the bell. Not an operator seat; no member floor.
Billing Manager Whoever manages your Stay N Host subscription The shared screens plus Billing (plan, seats, invoices, payment method) and the finance reports (P&L Report, ROI, Monthly Break-even).
Member The baseline everyone else builds on Exactly the shared screens - read-only operational awareness, no write powers beyond it.
Role Who it’s for Screens Beyond the shared screens, they can
Point of Contact Whoever answers guests day to day The shared screens + Inbox + Agent Hub (view) Create and drive inquiries (quote, request payment, reject/decline), create and update bookings, check guests in and out, request ID verification and record documents, view ID documents, attach payment proof, quote extensions, flag blacklist entries, manage guest profiles, message guests - and hand the door code to the guest (the only role that does, by hand or via the agent rule).
Booking Manager The reservations lead The shared screens + Approvals + Inbox + Agent Hub (view) Everything the funnel needs: all of the POC’s inquiry/booking powers plus direct and group bookings, historical imports, calendar blocks, verifying and revoking ID checks, approving extensions, deciding approval-queue tasks, requesting reviews. No payment verification and no door-code hand-off.
Guest Manager Guest relations and difficult calls The shared screens + Inbox The only role that cancels bookings and marks no-shows; requests refunds (Account Manager executes); verifies and revokes ID checks and views the documents; resolves blacklist entries; curates guest profiles; requests reviews; messages guests.
Airbnb Manager The channel-side operator The shared screens + Inbox Runs the funnel for channel guests (inquiries, direct bookings, updates), mirrors external calendar blocks, verifies ID checks, manages static lock codes, generates integrated smart-lock codes (the one role that can), relays codes to the POC, records and escalates damage, attaches payment proof.
Front Desk The desk downstairs The shared screens + Inbox Checks guests in and out, updates bookings, registers walk-ins and keeps guest contacts current, relays lock codes to the POC, messages guests.
Co-Host A trusted helper with light powers The shared screens + Inbox Creates inquiries, updates bookings, requests ID verification and reviews, flags blacklist entries, manages guest profiles, messages guests.
Conflict Resolution Manager Damage claims and disputes The shared screens + Housekeeping (the damage/claims tab is their surface) The only role that resolves damage claims; records inspections, creates and escalates damage evidence, resolves blacklist entries, requests reviews.
Role Who it’s for Screens Beyond the shared screens, they can
Account Manager Finance operations The shared screens + Approvals + Inbox + Agent Hub + the finance surfaces: Payments, Cash Report, Treasury, Expenses, Charges, Assets, Payables, Payees, Period Close, Operating Models, Owners, Owner Payouts, Investors, and the WS-8 capital suite (Investor Model, Track Record, Proposals, Launch, Deals, Deployment), plus Properties, Bank Accounts, property Finance tab, Occupancy Report The money role: the only seat that verifies or rejects payments, records transactions, and approves/executes refunds. Also records expenses, edits bank accounts, approves extensions, decides approval tasks, manages agent rules.
External Accountant Your bookkeeper - external, read-only The finance read surfaces (Payments, Cash Report, Treasury, Expenses, Charges, Assets, Payables, Payees, Period Close, Operating Models, Owners, Owner Payouts, Investors, the capital suite, property Finance tab, P&L, ROI, Monthly Break-even, Occupancy Report, Owner Portal, Tax rules) Reads transactions, statements, and the tax rule catalog. Cannot change a rate it audits, record anything, or see the operational screens - no member floor.
Auditor Compliance / an external reviewer Audit, Daily Report, Occupancy Report Reads the workspace activity feed and the two operational reports. Nothing else - no member floor.

These are portal-style seats: their screens are the Housekeeping queue (plus the bell), scoped to their work. All are designed for task-only seats - no member floor.

Role Who it’s for They can
Cleaner Cleaning staff See their own assigned tasks, start them, complete them.
Housekeeping Coordinator The dispatcher See the whole queue; assign, reassign, prioritize, and update task state. Does not clean and does not inspect.
Inspector Post-checkout quality control See the queue; record inspections, clear them, or record damage.
Maintenance Repairs See the queue; start and complete tasks; resolve maintenance items.
Property Manager The ops lead over all of it A bigger seat than the four above: the shared screens (minus Guests) + Approvals + Agent Hub + Housekeeping. Dispatches and works the whole cleaning queue, records/clears inspections and damage evidence, resolves maintenance, manages static lock codes, blocks units on the calendar, checks guests in and out, manages agent rules, decides approval tasks.

Four narrow seats so you can grant one channel power without the others. All ride the member floor (the shared screens); none can touch money or codes.

Role Screens The one power
Content Manager The shared screens + Properties Push listing content to channels (reads properties and units to do it).
Availability Manager The shared screens Set channel availability, from the calendar’s selection sheet.
Channel Pricing Manager The shared screens Set channel pricing, from the calendar’s selection sheet.
Channel Setup The shared screens + Airbnb (channel manager) + Bookings to Review Connect and configure a channel - the most trusted channel act, kept apart on purpose.
Role Who it’s for They see
Investor A capital partner - external Investor Portal only, scoped to their own position, plus the bell. No member floor; never money or lock-code powers.

You can compose custom roles from the same permission palette and page registry. Two hard ceilings apply, enforced at the write boundary, at rest in the database, and again at runtime: a custom role can never hold a role-pinned single-actor capability (the money and door-code verbs in The approval system), and it can never name a permission or page that doesn’t exist in the registry.