26 August 2026
Staff Roles & Permissions: What Each Person Can Actually See
A hair salon in Ipoh with four stylists and one receptionist. The owner gives everyone a login to the same system so each stylist can check their own schedule. But the receptionist, two weeks into the job, can immediately see every long-time customer's phone number — including a VIP the owner personally handles. Nobody meant any harm; the system simply has no middle setting between "sees everything" and "sees nothing".
A car workshop in Klang hires a new manager to help run day-to-day operations when the owner can't be there. This manager needs to change operating hours, add new services, and manage other staff — access almost as wide as the owner's. But the owner does not want anyone, including that manager, to be able to create further managers without limit. If everyone can promote anyone, the owner can end up a minority voice in their own system within a year.
A small dental clinic in Seremban runs front desk in three shifts — morning, midday, evening. Every shift staff member needs to confirm and manage appointments during their own shift. But the owner does not want all three of them looking at the monthly sales report or the list of overdue invoices. It's not distrust — that information should stay between the owner and the accountant.
Why this keeps happening
Four reasons this recurs across small Malaysian businesses:
- Older systems only have one kind of login. When staff share the owner's account, or the system only offers two choices — "admin who sees everything" and "staff who can't do anything" — there's no room for what a specific business actually needs.
- Access gets handed out to whoever asks loudest, not according to what the job actually requires. A staff member who insists "just let me see everything, it's easier" ends up with more than the role calls for.
- Nobody wants to be the one walking access back. Once granted, few owners sit down and trim each staff member's access one by one — it feels like an accusation of distrust, even when it's really just scope creep.
- Management-level roles have no ceiling. If a system lets anyone promote anyone else to "admin", a business can end up with five people holding full access within a year — without the owner ever noticing when it happened.
What owners try instead
The most common: one account, shared password. Every staff member logs in with the owner's own credentials. Quick to set up, but there's no log of who did what, and everyone sees everything — including customer data and financial numbers they don't need.
Some rely on a spoken rule: "you can log in, just don't open the Reports page." This depends entirely on memory and goodwill. The conscientious staff follow it; the curious ones click anyway.
Others avoid giving direct access at all — staff message the owner on WhatsApp every time something needs confirming or changing. Safe for privacy, but the owner becomes the bottleneck. When the owner is unreachable, work stalls.
How staff roles and permissions should work
A few principles TempahKu holds to on the Staff page (under the dashboard, owner access only):
- Three tiers, not two. Owner (the account that registered — cannot be deactivated or have its role changed), Manager (full access — manage bookings, change settings, view financials, add staff), and Staff (specific permissions the owner sets individually).
- The Manager role has a ceiling. At most one Manager at a time — the number of full-access users (owner plus manager) is capped at two. This is enforced on the server, not just hidden in the interface: an attempt to add a second manager is rejected with an error message, not a silent failure.
- Six specific permissions for the Staff role: View Bookings, Manage Bookings, View Settings, Manage Settings, View Customer Phone, and View Financials. Each one can be switched on or off independently per staff member — not one switch for everyone.
- Ready-made permission sets for common situations — "Bookings only" (see and manage bookings, without customer phone numbers), "Bookings + Phone", "Bookings + View Settings", and "Full access" — or you can pick "Custom" and tick the six permissions yourself.
- Safe by default. The "Bookings only" preset deliberately withholds customer phone numbers — the owner has to explicitly grant that. The View Financials permission works the same way; that's covered in more depth in a separate article on the finance-view permission (Malay only for now).
- Whether customers can book a staff member is a separate switch, not part of the role. Whether a staff member's name appears for customers to pick during online booking is set independently — it has nothing to do with what that staff member can see on the dashboard.
- Permissions can be changed anytime, without a password reset or a new account. The owner opens the edit form for any staff member, changes the preset or an individual permission, and it takes effect immediately.
When it helps most
It matters most once a business has two or more staff logging into the same system for genuinely different jobs — a front-desk person who only needs to handle bookings, and a manager who needs wider access to help run operations. When the roles are clearly different, per-staff permissions avoid both bad outcomes: a staff member so restricted they become a bottleneck, or one who sees more than the job requires.
It's also useful the moment you start feeling uncomfortable about a particular staff member seeing something — old customers' phone numbers, monthly sales figures — without wanting to cut them off from their day-to-day work entirely.
If you run the business alone, or everyone involved is a partner who already shares every number, this probably isn't necessary yet — one shared full-access login is enough, and setting up a custom permission split for a single staff member just adds a step with no real benefit.
In short
The underlying problem was never about trusting staff — it's a system with no middle ground between "sees everything" and "sees nothing". When roles only offer two choices, an owner ends up either sharing more than they should, or restricting staff so much they can't actually do the job.
TempahKu splits this into three tiers — Owner, Manager (capped at one, full access) and Staff (six specific permissions to choose from) — so each person gets access that matches their actual job, without the owner having to share a password or become the bottleneck for every single booking.