The problem is uncertainty about who can do what
Shared access often begins as a practical response. Staff need to work now, the owner is available now and setting up another account feels like a task for a quieter day.
The difficulty grows as the team changes. A password shared with a trusted colleague may also be saved on a device someone else uses. A former employee may still know it. A manager investigating a changed setting may see the shared account rather than a clear individual identity.
This is an operating problem as well as a security problem. Staff may be unsure which actions they are allowed to take. They may interrupt the owner for routine work because they lack the right access, or perform a sensitive action through an account that exposes much more than they need.
The goal is not to make employees feel distrusted. It is to make responsibility clear and give people a working setup they can use confidently.
A receptionist should be able to handle the agreed reception tasks without borrowing another person's account. The owner should be able to explain why that person has access to particular areas. When someone leaves, the hotel should know which accounts need attention.
Start with the person's work, not the role name
Job titles vary between properties. At one small hotel, the receptionist also handles reservations. At another, a manager controls prices while reception deals with arrivals. A room coordinator may need some booking information but no financial controls.
Write down the tasks the person must perform. Which property do they work in? What information do they need? Which changes are they expected to make? Which decisions still require a manager?
Then compare those needs with the permissions the system actually offers. A role called staff, manager or reception may cover more or less than you expect. Do not grant it on the strength of the name alone.
Kiyo's roles and security controls connect property membership with built-in and custom roles and access to supported workspace areas. The useful question is whether the selected role lets this colleague do the required work without opening unrelated sensitive areas.
This approach also helps with training. Instead of handing over a login and saying “use the system,” the manager can explain which parts of the job belong to the person and where to ask for help. Access becomes part of a clear working arrangement.
Give three common roles different starting points
The following is a fictional property policy example, not a preset Kiyo role or a promise that each individual task has a separate permission switch.
An owner or authorized general manager may need broad oversight, property settings and the ability to make team-access decisions. That does not remove the need to consider sensitive financial permissions deliberately. Broad responsibility and a specific financial action are still different questions.
A receptionist may need reservations, arrivals and the guest communication areas used by the property. Start there. Do not assume that working at the front desk automatically requires access to billing or payout settings.
A room coordinator may need the information required to help prepare rooms and communicate readiness. Choose only the supported areas needed for that assigned work. In this example, sensitive financial access is not part of the job.
These starting points are meant to prompt a conversation, not replace it. A real role may need more or less. If the available permission is broader than the manager intended, resolve that difference before granting it.
Equally, avoid giving so little access that staff cannot complete their responsibilities. If the only way to do the job is to borrow the owner's login, the setup has not solved the problem. Clear access should support useful delegation, as discussed in our guide to reducing hotel owner dependency.
When a colleague joins, make the first account useful
Set up an individual account for the correct property and confirm the agreed role. Explain how the person signs in through the normal process and which areas they should use for the work they have been given.
Do not ask a colleague to share their password or an authenticator code so a manager can act as them. An individual account has value when the person's identity remains individual.
Check the practical work together. Can the receptionist find an arrival and the information they are expected to use? Can they reach the relevant workspace? Are unrelated areas absent or restricted as intended? Use a suitable demonstration or authorized process without exposing unnecessary guest information.
This is also the moment to explain the boundary of the role. Who approves a price exception? Who handles an unclear payment? Who can change another person's access? Staff should know where a routine action ends and a management decision begins.
A short, useful introduction is better than a large permissions list nobody understands. Show the person how their account supports their first working day, then record who approved the setup and when it should be reviewed.
Keep financial access a separate conversation
Seeing the payment information on a reservation and controlling sensitive billing or payout settings are not the same responsibility. A receptionist may need to understand whether the guest's payment is recorded without needing every financial control in the system.
Kiyo's public security guidance describes separate financial permissions and requires enabled, verified two-factor authentication before that access can be granted. The manager still needs to decide whether the person's work requires it.
Two-factor authentication adds a check to account access. It does not make every action appropriate merely because the account can sign in. Keep the business decision about permission with the person responsible for it.
The hotel payments overview explains the payment information staff may encounter. Use that context to distinguish the work of checking a booking from the separate authority to manage sensitive financial settings.
This distinction helps employees as well. They can handle the part of the job they were assigned without being left with unclear responsibility for controls they were never trained or authorized to use.
When the job changes, review what should be removed too
Access tends to grow because adding a new permission is easier to remember than removing an old one. A colleague changes duties, receives another area and keeps everything they had before.
Over time, the account describes the history of the person's jobs rather than the work they do now. That may expose information they no longer need or make responsibility less clear during an investigation.
When someone changes roles, ask two questions together: what do they need to begin doing, and what are they no longer responsible for? Review both the new and old areas before treating the change as complete.
Also check property membership if the person moves between locations. Access that was appropriate at one property may not be needed at another. A group role should not be assumed simply because the person helped another location once.
Record the date, changed responsibilities and approver. That short note gives a future manager a reason for the access rather than a list of unexplained switches. It also helps the next review distinguish a deliberate decision from an old setting nobody remembers.
Keep an access record people can actually maintain
You do not need a complicated register to begin. For each person, record the property, role, required work areas, start date, any change date, known end date, approver, financial-access decision and the person who checked the result.
The record should answer a practical question: if this person's duties change today, where do we look and who owns the update?
For the fictional receptionist, an entry might say that the person works at the main property, needs the agreed booking and guest areas, and does not require sensitive financial settings. The manager approves the setup and records the review after checking it.
For the room coordinator, the entry can describe the narrower information needed for the assigned work. If the system cannot provide exactly the boundary the manager expected, record the issue and agree the appropriate arrangement rather than pretending the requested restriction exists.
Keep this record private. It does not need guest details or copies of passwords. Its purpose is to explain decisions about access, not to become another place where sensitive information is collected.
The front-desk handover guide handles a different but related job. A handover explains unfinished work; an access record explains who can enter the systems needed to perform it.
When someone leaves, check every system they used
A departure can be friendly and still require a complete access review. The question is not whether the person is trusted. It is whether their account should continue to have a business role after that role has ended.
Agree who handles the review and when access should end. Check the Kiyo property membership, then separately review the OTA accounts, business email, messaging tools and other services the person used.
Removing access from one product is not proof that another product has changed. A former colleague may also know a shared password or have access through a business account that was never tied to their individual PMS login.
Where shared credentials were used, review who knows them and change them through the appropriate authorized process. Preserve business records and transfer unfinished work as required. Do not delete reservation history or guest correspondence simply because the colleague who handled it has left.
Kiyo's public guidance describes deactivating property access while retaining team history. That helps the hotel separate the end of a person's access from the continued need for an operating record. The manager still checks external systems and any remaining account-specific questions separately.
Use activity history for a specific question
If a setting or team membership changed unexpectedly, a record of who changed it and when can help the manager understand what happened. It is especially useful when staff use their own accounts rather than one shared identity.
Kiyo records selected team and settings events in the property's activity history, with the available details for those events. Use that information for its stated scope. It is not a promise that every action in every connected system appears in a complete investigation log.
Start with a concrete question: which recorded team change affected this account, or who changed the setting that is now different? Read the available event in context and speak with the responsible person when needed.
Avoid treating the presence or absence of one event as a conclusion about every possible action. The usefulness of the history depends on what the system records and what information is available.
For the hotel, the practical gain is a clearer explanation of selected changes. Combined with individual accounts and an access record, it can reduce the uncertainty that comes from several people working under one identity.
Make access part of a calm management routine
Review access when someone joins, changes responsibilities or leaves. Add a periodic review suited to the property, but do not wait for that date when a person's job has already changed.
The owner should not need to remember every account from memory. The manager should know where the record is, what each role is meant to do and which systems need separate attention. Staff should have the access required to work without borrowing someone else's identity.
Kiyo is worth considering when the team needs property-specific membership, roles and workspace permissions that can be reviewed alongside the work. Its separate financial-access controls and selected activity history support that arrangement without replacing management judgment.
Bring your actual team roles to a product discussion. Describe the receptionist's day, the manager's responsibilities and the work another colleague needs to perform. Ask to see how the available controls fit those tasks, rather than starting with the broadest role and hoping it will be fine.
A good access setup makes ordinary work easier and changes easier to handle. When the next employee joins or leaves, the hotel can follow a clear record instead of asking who might still know the owner's password.