Managing your team and user roles

Last updated: 2026-02-07

Team Overview

Xeni supports multi-user agency accounts so your entire team can access the platform with appropriate permissions. Each team member gets their own login and can be assigned a role that controls what they can see and do.

User Roles

Xeni has four built-in roles:

Owner

  • Full access to everything
  • Can manage billing and subscription
  • Can delete the agency account
  • Only one owner per account
  • Can transfer ownership to another user

Admin

  • Full access to bookings, reports, and settings
  • Can invite and remove team members
  • Can manage API keys and white label settings
  • Cannot manage billing or delete the account

Agent

  • Can search and book hotels, flights, and activities
  • Can view and manage their own bookings
  • Can create and share Deal Links
  • Cannot access settings, reports, or team management

Viewer

  • Read-only access to bookings and reports
  • Cannot make bookings or changes
  • Useful for accountants or external auditors

Tip

Start by adding your booking staff as Agents — they get everything they need to sell without access to sensitive account settings.

Inviting Team Members

  1. Go to Settings → Team Management
  2. Click Invite Member
  3. Enter their email address
  4. Select a role (Admin, Agent, or Viewer)
  5. Click Send Invitation
The invitee receives an email with a link to create their account and set a password. Invitations expire after 7 days.

Info

You can resend or revoke pending invitations from the Team Management page. Revoked invitations immediately invalidate the invite link.

Managing Existing Members

From the team member list, you can:

  • Change role — Promote or demote a team member (e.g., Agent → Admin)
  • Deactivate — Temporarily disable access without deleting the user
  • Remove — Permanently remove the member and revoke all access
  • View activity log — See recent actions performed by the member

Warning

Removing a team member is irreversible. Their booking history is preserved, but they lose all access immediately. Consider deactivating instead if the absence is temporary.

Permissions Summary

PermissionOwnerAdminAgentViewer
Search & bookYesYesYesNo
View own bookingsYesYesYesYes
View all bookingsYesYesNoYes
Manage Deal LinksYesYesYesNo
View reportsYesYesNoYes
Manage teamYesYesNoNo
API keysYesYesNoNo
White label settingsYesYesNoNo
Billing & subscriptionYesNoNoNo

Security Best Practices

  • Use the principle of least privilege — Give each member only the access they need
  • Review team access quarterly — Remove inactive users promptly
  • Enable two-factor authentication — Recommended for Owners and Admins
  • Monitor the activity log — Watch for unusual booking patterns or unauthorized access

Was this article helpful?