Team Overview
Xeni supports multi-user agency accounts so your entire team can access the platform with appropriate permissions. Each team member gets their own login and can be assigned a role that controls what they can see and do.
User Roles
Xeni has four built-in roles:
Owner
- Full access to everything
- Can manage billing and subscription
- Can delete the agency account
- Only one owner per account
- Can transfer ownership to another user
Admin
- Full access to bookings, reports, and settings
- Can invite and remove team members
- Can manage API keys and white label settings
- Cannot manage billing or delete the account
Agent
- Can search and book hotels, flights, and activities
- Can view and manage their own bookings
- Can create and share Deal Links
- Cannot access settings, reports, or team management
Viewer
- Read-only access to bookings and reports
- Cannot make bookings or changes
- Useful for accountants or external auditors
Tip
Start by adding your booking staff as Agents — they get everything they need to sell without access to sensitive account settings.
Inviting Team Members
- Go to Settings → Team Management
- Click Invite Member
- Enter their email address
- Select a role (Admin, Agent, or Viewer)
- Click Send Invitation
Info
You can resend or revoke pending invitations from the Team Management page. Revoked invitations immediately invalidate the invite link.
Managing Existing Members
From the team member list, you can:
- Change role — Promote or demote a team member (e.g., Agent → Admin)
- Deactivate — Temporarily disable access without deleting the user
- Remove — Permanently remove the member and revoke all access
- View activity log — See recent actions performed by the member
Warning
Removing a team member is irreversible. Their booking history is preserved, but they lose all access immediately. Consider deactivating instead if the absence is temporary.
Permissions Summary
| Permission | Owner | Admin | Agent | Viewer |
|---|---|---|---|---|
| Search & book | Yes | Yes | Yes | No |
| View own bookings | Yes | Yes | Yes | Yes |
| View all bookings | Yes | Yes | No | Yes |
| Manage Deal Links | Yes | Yes | Yes | No |
| View reports | Yes | Yes | No | Yes |
| Manage team | Yes | Yes | No | No |
| API keys | Yes | Yes | No | No |
| White label settings | Yes | Yes | No | No |
| Billing & subscription | Yes | No | No | No |
Security Best Practices
- Use the principle of least privilege — Give each member only the access they need
- Review team access quarterly — Remove inactive users promptly
- Enable two-factor authentication — Recommended for Owners and Admins
- Monitor the activity log — Watch for unusual booking patterns or unauthorized access