Understanding staff roles (staff, manager, admin)
In short: Every person you invite to Keyhive gets one of three roles. Staff covers the everyday work: handing keys out, taking them back, and keeping your records up to date. Manager adds the jobs that undo things or change how Keyhive is set up: deleting records, managing your people, and your settings. Admin is the same as a manager, but across every branch in your business.
When it matters: When you’re inviting someone and have to pick a role, or when someone can’t find an option you can see.
Staff
The everyday role, and the right one for most of your team. Someone with Staff access can do all the work that keys actually generate:
- Check keys out and take them back: on the Hive, on the mobile app, or in the portal. That includes handing keys straight on to the next person, changing a return date, and closing a checkout for a key that won’t be coming back.
- Keep the records right: create and edit assets, key sets, contacts and key / hook numbers, attach and remove fobs, and add photos.
- Move keys between key stores, if you use them.
- See what’s going on: what’s out right now, what’s overdue, what a colleague is holding, and the full history of any key set or contact.
- Bring records in and take them out: importing from a spreadsheet and exporting to one.
What they can’t do is take anything away or change how Keyhive is set up. There’s no archiving, no deleting, no inviting or editing colleagues, and no settings. Those options simply aren’t there for them. They can still open the Staff list and see who’s on the team.
Manager
Everything above, plus the jobs that change or remove things. Give Manager access to whoever runs the branch day to day.
- Archive and restore assets. See How to archive and restore an asset.
- Delete records for good: contacts, key sets, key / hook numbers and individual checkouts. Merging two key sets counts here too, because one of the two is removed in the process.
- Manage your people: invite someone, change their details or role, and disable or restore them.
- Change your settings: the default checkout lengths, the Hive password, your asset types, your key stores, which notifications go out, and the activity log. These sit in their own section of the sidebar, under your branch’s name, which nobody below Manager sees at all.
A manager’s reach stops at the branch they’re working in.
Admin
Everything a manager can do, across every branch in your business.
- Move between branches. An admin can switch to any branch and work in it, including ones nobody has explicitly given them. Managers and staff only see the branches they’ve been added to.
- Decide who works where. When an admin invites or edits someone, they get a Branch Access list of every branch to tick. Nobody below Admin sees it, so when a manager invites someone, that person joins the branch the manager is in. See Giving a staff member access to more than one branch.
Rules that apply whatever the role
One person, one role, everywhere. A role isn’t set per branch. It follows someone into every branch they can reach, and into the mobile app as well as the portal. You can’t make someone an admin in one branch and an everyday user in another.
Nobody can change their own role. Editing your own record shows only the role you already hold. Promoting or demoting yourself isn’t possible; someone else with Manager or Admin access has to do it.
You can’t act on someone above you. A manager can edit, disable or delete staff and other managers, but not an admin. On an admin’s page, those options aren’t there. The same applies to giving out roles: you can only give someone a role up to your own, so a manager can create managers but not admins.
Nobody can delete their own account. Ask a colleague with the access to do it, or in most cases disable the account instead.
Options you can’t use aren’t shown. If a colleague is describing a button you can’t find, the usual reason is that your role doesn’t include it. Check with whoever manages your account.
Good to know
- The apps don’t work by role. Everything the Hive and the mobile app do, including checking out, returning, passing keys on and transferring between stores, is open to everyone, so an everyday staff member can use them exactly as a manager would. The jobs that need Manager or Admin access are all in the portal. The Hive doesn’t know who’s standing at it either: it signs in with a shared Hive username and password, not a personal login.
- A new role takes effect straight away. There’s nothing to accept and no need to sign out and back in.
- Changing someone’s role isn’t how you stop them using Keyhive. If they’ve left, disable them instead.
- Roles are about your own team. Contacts, the people outside your business you hand keys to, don’t have a login at all, so they never have a role.
- You may see a role we haven’t listed. If a System Admin ever shows up on your Staff list, that’s a Keyhive account and shouldn’t be there. Get in touch and we’ll sort it.