Team roles and permissions
Keep your team moving while you stay in control. Start with a premade role or build a custom role for one job.
Choose a premade role
Open Settings, then find Team access. Select a role beside a team member. The change takes effect when the member loads the next page.
Owner: Full access, including custom roles and ownership changes.Administrator: Full day-to-day access and team role assignment. Webhook endpoints and custom agent skills stay owner-managed unless delegated through a custom role.Operations manager: Runs properties, reservations, rates, messages, tasks, and automations.Front desk: Handles reservations, availability, guest messages, and tasks.Team member: Handles guest messages and assigned tasks.Viewer: Can inspect workspace data but cannot change it.
Supahost always keeps at least one active owner. You cannot disable or change the role of the last owner.
Each person can have 1 active membership. Deactivate it before you activate a membership in a different workspace.
Create a custom role
An owner can select New custom role in Team access. Name the role, explain its purpose, and select only the permissions that the job needs.
You can change a custom role later. The new permission set applies to every member who has that role. You must move all members to another role before you delete it.
Permission catalog
Supahost has 15 permissions. A custom role is any combination of them. They appear in 6 groups on the Team access screen, in this order:
Workspace
Organization settings: Change the organization name and shared settings.Team access: Assign roles to team members. Only owners can create custom roles.API keys: Create, change, and revoke API keys.Webhooks: Create, edit, disable, and remove outbound webhook endpoints. Owner-only by default; delegable through a custom role.Connections: Connect and disconnect external services.
Properties
Properties and listings: Change property details, rooms, content, and photos.
Operations
Availability: Open, close, block, and change sellable inventory.Rates and restrictions: Change rates, stay limits, and booking restrictions.Reservations: Create, move, and cancel reservations.
Financials
Owners and statements: Manage owners, commission agreements, financial entries, and statements.Direct booking site: Customize, publish, and connect the workspace direct booking site.
Guest service
Guest messages: Send replies and retry failed messages.Tasks: Create tasks and change their status.
Automation
Automations: Create, run, and stop automation rules.Agent skills: Write, edit, and delete custom agent skills. Owner-only by default; delegable through a custom role.
Delegate safely
A member with the Team access permission can assign premade and custom roles. That member can grant only permissions that are already in their own role.
A manager can change a member only when the manager has all of that member’s current permissions.
Delegated team managers cannot grant ownership. Only an owner can grant or remove ownership.
Use a custom role when a person needs one sensitive control, such as rates and restrictions or API keys, but does not need broad administrator access.
Agent access follows the member
The operations agent uses the signed-in member’s permissions. It does not offer a change tool that the member cannot use. Supahost checks the permission again before it makes a change.