Invite your team and set their roles
Two independent axes govern a teammate's access — what they may do, and which properties they may do it on. The invitation form sets both, and the link is handed over only once.
A YStay account can be shared. The Team page, in the Account group of the navigation, welcomes a concierge, a housekeeping crew, an accountant or a co-investor, and sets two independent things for each of them: their permissions (what they may do) and their property scope (where they may do it). Forgetting the second one hands the whole portfolio to someone who only services one studio.
Opening this page with controls does not come from the role but from a permission: the Gestion box on the perm.module.coreTeam row — the technical identifier of the Team module in a member's matrix, see “What the matrix displays” below. A Manager gets it by default, Staff does not; tick it for a Staff member and they will manage the team just as you do, take it away from a Manager — or apply an access preset to them, see below — and they lose it. The owner always has it and is never editable: that role cannot be assigned, and no scope ever applies to them. Inviting new members also requires a plan that includes teamwork — without it the page replaces the form with See plans, while still letting you manage the members already there.
Inviting, screen by screen
Fill in the invitation form
The Invite a teammate card asks for four things: Email address, Role, Access preset and Accessible properties.
Role is one of Manager, Staff and Read only: the owner role cannot be assigned. Access preset offers Default (based on role) and then five ready-made presets.
Screenshot to be produced
captures/inviter-equipe-regler-roles/01-inviter-membre.png
Choose the property scope
Under Accessible properties, tick the properties this member should see. Ticking nothing is not an oversight, it is a decision — and the screen spells it out: “No selection: access to all properties.” A property that does not belong to your account is dropped silently: the saved scope only ever contains your own.
Hand the link to the person you invited
Invite confirms with “Invitation sent. Share the link below to finalize access.”, shows the Invitation link, and the person appears in the list with the Invited badge.
That link opens a page asking them to sign in — or create an account — with the invited email address, then validates the access. That page is shown in French; its English version comes from adding “?locale=en” at the end of the link.
Screenshot to be produced
captures/inviter-equipe-regler-roles/02-lien-invitation.png
Fine-tune the access afterwards
On a member's row, Manage access opens their panel: Access template (preset), Permissions by module — one box per module and per action — and Accessible properties. Save access closes the matter.
Read the team matrix back
Each row recalls the role, the preset if any, and the scope: All properties, or the number of properties selected. The owner never shows a scope at all.
Screenshot to be produced
captures/inviter-equipe-regler-roles/03-roles-et-perimetre.png
The three roles, and the five presets
The The roles card at the bottom of the page sums up the base:
- Owner & Manager — full access: operations, sales & marketing, team and billing.
- Staff — field operations (reservations, stays, housekeeping, incidents). No team or billing management.
- Read only — view only, no changes.
Five presets are on offer — Concierge, Ménage, Compta, Co-investisseur, Manager — plus a fully manual mode: Custom (manual), in a member's panel. A preset does not refine that base, it replaces it: as soon as a preset sits on a member, their permissions come from that preset alone and the role's base is never consulted again. A Manager you apply a preset to therefore loses team and billing management — not one of the five carries them, not even Manager. A Read only role, for its part, stays read-only whatever you tick: the server refuses every write coming from that role.
What a Read only role sees
The Team page opens, but without a single control: no invitation form, no role selector, no Manage access. The banner names the role — “Your role (Read only) does not allow managing the team.” — but what is missing is the permission: a Staff member sees exactly the same screen, and that same Staff member gets the controls back the moment Gestion is ticked on perm.module.coreTeam. The navigation narrows at the same time: Subscription, Payments and API & integrations disappear, for want of the right to manage billing; Earnings and Insights remain reachable, for viewing — as long as no access preset has been applied to that member, since a preset recomputes what they see too.
Requiring two-step verification from the team
At the very bottom of the page, Team security carries a switch: Require two-step verification for the team. The confirmation is blunt — “EVERY team member, including you, stays locked out until they turn on two-step verification.” Hence the guard: if your own second factor is not on, YStay refuses — “Turn on your own two-step verification before requiring it from the team.” — and offers Go to my security settings. Lifting the requirement, by contrast, has no condition at all.
Next
- Turn on two-step verification — do it for yourself first.
- Set up your account and integrations — profile, company, connections.
- Create your account and your first listing — opening the account.
- Team & account — the other guides in this section.
Updated on