One shared login is how settings get changed at midnight and nobody knows who did it. Kyasti splits people and permissions.
Invite people under Staff
Management → Staff lists everyone with access to this business. The owner is marked Protected. Managers can be assigned a role and removed. Use Add member to invite by phone — they sign in with OTP, same as you.
What each default role can do
Management → Roles shows Owner, Manager and Staff as cards with permission pills.
- Owner — full access, including future features. One member, protected.
- Manager — day-to-day: properties, leads, bookings, occupancy, tickets, vendors, announcements, and staff. Settings and payouts stay visible so they can operate, not reinvent the business.
- Staff — mostly view, plus tickets and announcements so the person at the desk can work without deleting a building.
You can tighten a role later. The point is the warden never needs your superuser session.
When this matters
- Night manager should mark a visit done, not edit pricing.
- Accountant should see tenant payments, not delete buildings.
- A second hostel in another city gets the same roles, different people.
Next step
On the demo we will add a dummy manager and show exactly which menu items they see versus Owner.

