TG Guest Talk
Guide

Staff permissions audit for hotel groups.

Talk with Guest ships with seven default roles and a permission model that scales from a nine-key guesthouse to a fifteen-property group. This guide covers the audit template, the twelve most abused permissions and the quarterly review routine that keeps the model tight.

Why this matters

The permission drift problem

Every hotel group we work with arrives with the same problem: permissions have drifted. A receptionist who covered a night audit two summers ago still has access to the daily revenue report. A former head of housekeeping still has an active login because HR left the account open when she moved to a competitor. A group finance director has direct access to the WhatsApp inbox for reasons nobody can now remember.

Permission drift is not a security issue in the dramatic sense. It is a compliance and audit-trail issue. When the CNPD asks who could access guest data on a specific date, the answer must be short, specific and defensible. Talkguest gives you the tooling to keep that answer short, but you still have to run the audit.

The default roles

Seven roles that cover most properties

  1. Owner. Full access. One person per property, usually the actual owner or the general manager. Every action logged.
  2. General manager. Full operational access, no billing modifications, no user creation. This is the day-to-day driving seat.
  3. Revenue manager. Full access to rate plans, analytics, channels, forecasts. No access to guest CRM beyond aggregated views.
  4. Receptionist. Reservation view, check-in/check-out actions, WhatsApp inbox, guest CRM for current-day guests. No rate changes. No user management.
  5. Head of housekeeping. Housekeeping board, staff assignments, maintenance queue. No financial data.
  6. Housekeeper. Assigned room list only. Cannot see other housekeepers' assignments or historic guest data.
  7. Accountant. Read-only access to invoicing, VAT summaries, SAF-T exports and reconciliation reports. No operational data.

Every user is assigned exactly one role. Custom permissions on top of a role are possible but discouraged — every custom permission is a compliance debt to be paid at the next audit.

Frequent mistakes

The twelve most abused permissions

  • Receptionists granted rate-change permission for "flexibility on walk-ins". Wrong — walk-ins use published rates with a manager approval flow.
  • Head of housekeeping granted financial access to see room revenue. Wrong — financial access is finance, housekeeping is operations.
  • Owner-level access on a former GM's account, never revoked. Wrong — HR offboarding must remove access within two hours.
  • Shared login for the reception night shift. Wrong — every person has their own login, the audit trail depends on it.
  • Revenue manager granted full guest CRM. Wrong — revenue works from aggregated data, not from individual guest records.
  • Accountant granted operational access to see the tape chart. Wrong — the accountant does not need to see who is in room 204 tonight.
  • External web agency granted owner-level access to test the widget. Wrong — external users get a scoped role with a two-week automatic expiry.
  • Group finance granted full property access across every property. Wrong — group finance sees the finance layer, not the individual property operations.
  • Former marketing intern still active because the account is still receiving campaign reports by email. Wrong — the campaign report is a separate resource.
  • Two-factor authentication turned off for owner accounts because the token was inconvenient during a busy weekend. Wrong — always on, never off.
  • Housekeepers granted the ability to mark rooms sellable without inspection. Wrong — a Ready-to-sell status requires an inspector's touch.
  • Reception granted the ability to delete conversation history in the WhatsApp inbox. Wrong — nobody deletes history.
Permissions are the plumbing. Nobody notices them when they work. When they leak, the leak is discovered by the auditor, not by the operator, and that is always the wrong order.
The routine

The quarterly permissions review

Every quarter, the general manager and the DPO (or the accountant, in properties without a DPO) run a permissions review. The review is a one-hour meeting driven by the Talkguest permissions dashboard, which produces a report of every user, their role, their last login and every permission deviation from the default role.

  1. Confirm every active user still works at the property.
  2. Confirm every custom permission is still justified in writing.
  3. Revoke any user who has not logged in for 90 days.
  4. Rotate any shared credentials — API keys, PSP webhook secrets — that have not been rotated in six months.
  5. Sign off the review in the compliance dashboard. The signed record supports future audits.

Multi-property groups

Groups add a layer of complexity because a user may need access to multiple properties. Talkguest models this with a scoped role: a group revenue manager has "revenue manager" role scoped to the specific properties they cover. When a property is added to the group, existing group-level users do not automatically inherit access to it — the addition is deliberate.

The group audit view shows every user across every property in a single table with heat-mapping for permission depth. A group DPO can spot outliers instantly, which is what makes this scalable across ten, fifteen, twenty properties.

Onboarding and offboarding routines

Every new hire needs a clean provisioning flow. On the Talkguest platform this is a three-step wizard: identify the person, assign the role, confirm the property scope. Two-factor authentication is enforced on first login and cannot be disabled at the property level. The provisioning wizard is available to the general manager and the owner role only.

Offboarding is more sensitive because it often happens under pressure. When a receptionist leaves the property — for any reason, at any notice — the general manager triggers the offboarding flow, which immediately revokes access, invalidates active sessions, transfers ownership of open conversations to a nominated replacement and produces an audit-trail entry. The whole process takes under a minute. Nobody has to remember to change a shared password because there is no shared password.

For groups with high receptionist turnover — hostels routinely rotate seasonal staff — a bulk provisioning tool imports and offboards up to fifty users at a time from a CSV. The CSV format is documented in the platform help and matches the standard export from Portuguese HR systems used across the hospitality sector.

What to read next

Permissions sit alongside compliance. The natural companion is the GDPR piece, which covers the CNPD's expectations on data access. If you have not yet run the first-week onboarding, start with the first-week guide, and if you operate multiple properties see the customer stories for group examples.

Keep the audit trail tight