Skip to main content

Users

Ask AI Chat “Where do I open Users to invite team members and manage role permissions?” — then open this Users tab (ai-chat-product-context-users-reply.png, ai-chat-product-context-users-flow.mp4). The assistant typically says Settings → Team (invite and manage users, assign roles, manage permissions) and may stop before naming the English Users tab — open Settings → Team → Users. Same grounding external MCP clients get from get-vivin-context-platform. Distinct from landlord records on Owners and from your own name fields on My Profile.

AI Assistant — where to open Users to invite team members and manage role permissions

Walkthrough: ask AI Assistant where to open Users to invite team members and manage role permissions, then open Settings → Team → Users (even if the reply only says Settings → Team).

Account Settings — Team sidebar with Users selected

The Users tab manages team members (your staff): who can access your Vivin account and what they are permitted to do through their role. Property owners are a separate concern — register and maintain them on the Owners tab (/settings/owners), not on this page.

First-time workspace setup

Complete Getting Started — Recommended Setup Sequence step 3 (this tab — team roles before greyed-out + Create New shortcuts) after steps 1–2 on General Information and Preferences — full tab map: Recommended setup order. Finish steps 13–15 in Listings, Bookings, and Tenants, then Onboarding a New Property — Step 7. Guided steps 4–12: Onboarding a New Property. Lockout catch-up: Getting Started. Workflow pairing after go-live: Account Settings — Setup sequence after go-live.

Finding your way in this guide

Start with Team Members invites, then audit Role Permissions before go-live. Property owners are on Owners — not this tab. Operational rules: Key Rules. Habit-specific shortcuts live under Related below.

Prerequisites​

  • An active Vivin account with Settings access that includes the Users tab (typically Super Admin or Admin; other roles may see this tab read-only or not at all depending on your permission matrix).
Direct access

Open this tab at platform.vivin.app/settings/users. It lives under Account Settings in the app shell (gear / account entry), in the Team section of the settings sidebar. See Deep Links for neighbouring routes such as Owners (/settings/owners).

Pair with other Account Settings tabs

Register landlords on Owners before Listings property setup, and point each teammate to Personal Settings (/settings/personal) for interface language and per-user notification opt-outs. Grant account_settings.module (see Role Permissions) before scripting AI usage API polls — integration Bearer keys return 401. Hub: Recommended setup order.

Team Members​

Pair with other Users sections

New invites should complete Getting Started — Accessing the Platform — pair role changes with Role Permissions before finance or settings access goes live.

Team members are the people in your organization who use Vivin. Each member has a role that determines their permissions across all modules.

Adding a Team Member​

To add a team member, click Add Member (the primary button with a plus icon in the Team Members header). The dialog title is Add Team Member. Fill in:

  • First Name, Last Name, and Email — the member will receive an email invitation to create their account
  • Role — select from your available roles (see Role Permissions below)

The Add Team Member dialog does not include a phone field. After the invite is created, open the member’s card and set Phone Number under Editing a Team Member to link WhatsApp Genius.

Account Settings — Add Team Member modal with name, email, and role fields

The Invitation Flow​

When you add a team member:

  1. The system sends an invitation email to the address you provided.
  2. The new member clicks the link in the email to set their password and activate their account — or, when the hub shows Sign in with Google, they can open platform.vivin.app and use the Google account that matches this invite email (even before they set a password).
  3. Once signed in, the member sees only the modules and actions allowed by their role.

Use the same email you expect them to use with Google if your team relies on Sign in with Google. Changing the Users email later means they must sign in with the new address (Google or password).

tip

If a team member says they did not receive the invitation email, check the spelling of the email address in the team member list. You can resend the invitation from the member's detail view.

Available Roles​

RoleTypical Access Level
Super AdminFull access to all modules and settings, including the ability to add/remove team members and change financial settings.
AdminFull operational access to bookings, listings, finance (see note), sales, and operations. Cannot modify account-level settings.
FinanceStrong access to Finance (Overview, Income, Contract Values) and limited Bookings/Listings. Transactions / Payouts / Deposits require Approve payments unless your role matrix grants it.
SalesAccess to Sales (pricing, channels), Listings, and Bookings. No Finance or account settings.
Operations AdminAccess to Operations (tickets, check-ins/check-outs) and limited Bookings. Sees all maintenances.
OperationsAccess to Operations with own maintenances only. No Bookings sidebar or Finance.
Finance “Approve payments”

Default presets for Admin and Finance roles do not include Approve payments. Users with those roles still see Finance Overview, Income, and Contract Values, but not the Transactions, Payouts, or Deposits tabs until Approve payments is turned on for their role (or a custom permission profile) in Role Permissions. Super Admin always has full Finance access. On Transactions, Reject selected and Revert payment show accounting follow-up copy when charges may already be invoiced — see Glossary — Credit note (payment reject/revert). Rent edits on bookings respect the invoiced floor once months are exported — see FAQ — Lower rent below invoiced.

Editing a Team Member​

Click Edit on a team member card to open that member’s inline detail state. From here you can:

  • Change their role — the new permissions take effect immediately the next time the member navigates to a page or refreshes. There is no need for them to log out and back in.
  • Update their first name, last name, email, or Phone Number — if their email address changes, update it here so they continue receiving system notifications. See WhatsApp Genius phone linking below for the optional Phone Number field.
  • Resend password reset email — if a team member is locked out, click the envelope icon on their card (tooltip Resend password) to send a new recovery link to their email. This is the admin-assisted path when self-service reset at platform.vivin.app/reset-password is not enough — see Resetting a Management User Password.

Account Settings — team member card in inline edit mode with role selector and Save / Cancel

Account Settings — Team member card with Resend password (envelope), Edit, and Deactivate actions

WhatsApp Genius phone linking​

Pair with Automation & AI

Landlord-side Genius is separate from the tenant ChatBot. Concept overview: Automation & AI — WhatsApp Genius. Troubleshooting: FAQ — Genius does not recognize my number.

After the teammate exists, open Edit on their card and set Phone Number (optional):

  1. Enter digits in international format (country code + number, no spaces required — the UI formats the badge).
  2. Read the helper under the field: it explains that the number links to the WhatsApp AI assistant (Genius) so the member can message Genius and act with their own role permissions.
  3. Click Save. Each phone can link to one user per account while set — saving a number already linked to another teammate returns an error.
  4. In view mode, the card shows a teal Phone Number badge with the formatted international number. Hover the badge for the tooltip Linked to the WhatsApp AI assistant (Genius). Clearing the field and saving unlinks Genius for that user.

Account Settings — team member inline edit with Phone Number field and WhatsApp Genius helper text

Account Settings — team member card with Phone Number badge linked to WhatsApp Genius

Walkthrough: open Users, Edit a teammate, enter Phone Number with the Genius helper visible, then Cancel without saving.

Deactivating or Removing a Team Member​

When a team member leaves your organization:

  1. Open their detail view and remove or deactivate them.
  2. Their account is immediately locked — they can no longer log in.

The product asks you to confirm before deactivation so you do not lock out the wrong person. The dialog names the member and explains that they will lose access immediately; choose Deactivate to proceed or Cancel to keep the account active.

Account Settings — deactivate team member confirmation dialog with member name and Deactivate / Cancel actions

Business Rule

Removing a team member does not delete their historical activity. Bookings they created, payments they recorded, and tickets they resolved remain in the system with their name attached for audit purposes. However, any tickets currently assigned to them will need to be reassigned manually — check the Operations > Tickets tab for open tickets under their name.

Owners​

Pair with other Users sections

Landlord records live on the dedicated Owners tab — register payees there before assigning properties in Listings.

Separate tab in the app

Owner records are edited under Account Settings > Team > Owners (/settings/owners), not inside the Users tab. The guidance below matches that screen.

Property owners are the individuals or companies that own the properties you manage. Adding owners there allows you to:

  • Associate properties with their correct owner
  • Generate owner statements and payout records
  • Display owner details on contracts and legal documents

Adding an Owner​

When adding an owner, fill in:

FieldDescription
NameThe owner's display name.
Legal Name(Optional) The owner's full legal name as it should appear on documents.
EmailThe owner's email address for correspondence.
Phone(Optional) Contact number.
Fiscal ID / NIFThe owner's tax identification number (VAT), required for invoicing and legal documents.
Address(Optional) The owner's registered address, used on contracts and payment statements.
IBAN(Optional) The owner's bank account for payout transfers.
Business Rule

An owner record must exist before you can create a property assigned to that owner. If an owner is not in this list, the Owner dropdown in the property creation wizard will not show them.

Same email → owner-linked login

When an Owners email matches a Users invite (either order), that teammate’s login becomes owner-linked: portfolio modules and Inbox only show that landlord’s properties. Use distinct emails when a staff user should keep full-account access.

Editing an Owner​

Click on any owner row to update their details. Common reasons to edit an owner record:

  • IBAN change — the owner has a new bank account for payout transfers
  • Fiscal ID update — the owner's tax information has changed
  • Address change — update for accurate contracts and invoices
Important

Changes to an owner's details (name, fiscal ID, address) affect future documents only. Contracts and invoices that have already been generated retain the values they were created with.

Owner Visibility on Documents​

Owner information is used in several places:

  • Contract templates — Single-brace tokens such as {OwnerName}, {OwnerFiscalId}, {OwnerFiscalAddress}, {OwnerEmail}, {OwnerPhone}, and {OwnerIdDocumentType} pull from the owner record on the booking’s property. There are no {{OwnerFullName}} / {{OwnerAddress}} double-brace aliases — use the catalogue names above (see FAQ — Owner contract tokens).
  • Finance > Payouts — Payout records display the owner name and property.
  • Property detail view — The owner is displayed in the property's General Information tab.

Role Permissions​

Pair with other Users sections

Approve payments and communication.send_now gates control Finance — Transactions and Emails — Send now — audit the matrix before month-end collections. Deposit bookings.refund / bookings.dispute permissions pair with Glossary — Deposit lifecycle status on Finance → Deposits and booking Deposit tab.

Click the Role Permissions button to open a full permissions matrix. This table shows, for every role, exactly which actions are allowed or blocked across each module. Common permission categories include:

  • Listings: View, Create, Edit, Delete properties and units. Shared property/unit pickers used from Operations, Bookings, Sales, Utilities, and Finance are not gated by Listings module access — they use dedicated picker allowlists so an Operations (or Finance) teammate can name a building or unit on a ticket, filter, or bill without receiving the whole Listings module.
  • Bookings: View, Create, Edit, Cancel bookings; bookings.edit_items (edit or delete scheduled charge lines on Contract Values); bookings.change_payment_due_date; bookings.bulk_rent_increase (Bulk Rent Increase — Rent adjustment on Payments; default Admin on, default Finance off); bookings.add_discounts (per-line and booking-scoped discounts); bookings.add_return_of_value (return-of-value adjustments on Contract Values — not-invoiced cash only; see Manage return of value); bookings.refund (record deposit refunds and transfers on the booking Deposit tab and from Finance → Deposits); bookings.dispute (mark or resolve deposit disputes when Enable deposit disputes is on)
  • Sales: Pricing and channel integrations
  • Finance: Module access, payment actions, Approve payments (ledger tabs: Transactions, Payouts, Deposits; see Finance module), and Assign payments to other bookings (move an in-payment to another booking in the same account — including a booking that belongs to a different tenant — from Finance Transactions or a booking Transactions tab — see Finance > Assign a payment)
  • Operations: operations.module — open Operations; operations.see_checkin_checkout — Check-in & Check-out tab and /operations/check-in-out (without it, the tab is hidden and that URL redirects to Overview); operations.planning — Planning day dispatch board and /operations/planning (Planning (schedule board) — off by default for every role; grant it for supervisors who assign work on the board — see Operations — Planning); operations.see_all_maintenances vs operations.see_own_maintenances — whether Tickets lists every maintenance or only rows assigned to the signed-in user; create/resolve ticket actions follow the broader Operations rows in the matrix. Ticket Category options and the resolution-proof rule load from a maintenance-settings endpoint that Operations roles can call without Account Settings access.
  • Utilities: utilities.module — open the Utilities module; utilities.edit_connections — edit contract IDs on Utilities → Connections (without it, the matrix is read-only with an amber banner)
  • Settings: View and Edit account-level settings — including granular tabs such as account_settings.personal (Personal Settings: interface language, your email preferences, tab order, Operations ticket columns) and account_settings.fees (Fees: fee visibility and custom invoice labels on Global Settings — not a Billing sidebar tab). Preferences (account_settings.preferences) remains separate for workspace defaults (notifications, auto-cancel, contract signing, and similar).
  • Communications: communication.send_now — use the Now filter and create or run immediate-send communication rules (Emails > Communication Rules). After a blast, the rule is Inactive on Now while queued messages still send — Send now is fire-once.
  • Chatbot: account_settings.chatbot — view and edit Account Settings → System → Chatbot (tenant-facing WhatsApp/email automation; see Automation & AI). On by default only for Super Admin; a Super Admin can switch it on or off for any other role. It works on its own: a role does not also need Account Settings → Module to open ChatBot and FAQs.
  • AI / MCP: account_settings.mcp — the role may open Account Settings → System → AI / MCP, use Tools → AI Assistant and connect an external AI client (AI / MCP settings); without it the assistant gets no tools at all. On by default for Super Admin and Admin, off for the other roles. Editing the account-wide Landlord MCP tool permissions, API keys, and per-user AI overrides additionally requires the Admin or Super Admin role: every other role with this flag opens the tab read-only — My permissions for its own effective access plus the connection card — and the API refuses the management calls.
  • Support: support.module — open Help & Support (floating control on desktop), the Support entry in Account Settings, and /settings/support routes. In the matrix this row is under the Support group. Only Administrator and Super administrator roles can be assigned Support; other presets cannot enable it even if toggles appear during editing. A user may have Support without any Account Settings tab permissions — they then see the support-only browse layout at /settings instead of editable tabs.

Use this matrix to verify that each team member's role matches what they need access to — and nothing more.

tip

Follow the principle of least privilege: assign each team member the most restrictive role that still allows them to do their job. For example, a cleaning coordinator only needs the Operations role — they do not need access to Finance or Settings.

Blocked actions in the app​

Vivin enforces role permissions on the server for every mutating API call. When a signed-in user tries an action their role cannot perform — saving a booking change, approving a payment, editing Settings, and so on — the management app shows a red error toast:

You do not have permission to perform this action.

The message is localized with your interface language (English default). It replaces the generic API Forbidden resource text so operators get a clear explanation instead of engineering jargon.

OutcomeWhat you see
Generic RBAC denialThe localized toast above
Specific business ruleThe API’s own message (for example validation when a booking cannot be cancelled)

Role Permissions hides or disables many controls up front (+ Create New greys out rows you cannot use; Finance Transactions tabs stay hidden without Approve payments). Other surfaces still render buttons that look available until you click them — a 403 at save time means the signed-in role lacks the granular key for that API route. Ask an administrator to adjust the matrix in Role Permissions; changes take effect on the user’s next page load — no logout required.

See FAQ — Permission denied toast.

Interface overview​

The section header uses the product title Team Members with a count of members next to it. The main surface is a responsive card grid (one card per person). Each card shows avatar initials, name, email, role, and status, with Edit for inline changes, invitation resend, or deactivation. The Search… field beside the title filters cards by name or email.

Account Settings — Users tab showing Team Members cards, search, and Role Permissions

Toolbar (right side of the Team Members header)

  • Role Permissions — outline pill; opens the full permissions matrix modal (grouped rows by module, columns per role) so you can review or adjust what each role may do, within what your own role is allowed to change.
  • Add Member — filled primary action; opens the invite form (first name, last name, email, role) titled Add Team Member.

For the property-owner list and forms, use the Owners tab; see the Owners section above for field meanings and business rules.

Screenshots​

Team Members (/settings/users) — card grid with search, Role Permissions, and Add Member in the section header (full app shell):

Users settings — Team Members grid with Role Permissions and Add Member

Role Permissions — matrix of modules and actions by role (Super Admin, Admin, Finance, Sales, Operations Admin, Operations); use toggles to adjust what each role may do within what your own role is allowed to change:

Users settings — Role Permissions matrix modal

Walkthrough: open Role Permissions, scroll the permissions matrix by module, then close and return to the team member cards.

Key Rules​

Pair with other Users sections

Deactivating a teammate preserves audit history but leaves Operations — Tickets assigned rows orphaned — reassign open tickets before removal.

Summary
  1. Roles take effect immediately. When you change a team member's role, the new permissions apply on their next page load — no logout required.

  2. Owners must exist before properties. You cannot assign an owner to a property unless they are registered here first. Plan your owner setup before onboarding properties.

  3. Removal does not erase history. Deactivating or removing a team member preserves all their past activity for audit purposes. Only their future access is blocked.

  4. Reassign open tickets after removal. When removing a team member, manually reassign any tickets still assigned to them to prevent tasks from being forgotten.

  5. Owner details feed into contracts and payouts. Keep owner records up to date — especially fiscal IDs and IBANs — to ensure accurate document generation and payment processing.

  6. Blocked saves show a permission toast. When the API denies an action for RBAC reasons, operators see You do not have permission to perform this action. — adjust Role Permissions rather than retrying the same click. See Blocked actions in the app.

Users section cross-reference​

Use the sections above for this settings area. Related setup pages are linked from Related below when present, or from Account Settings.

Pair with other Users guide sections

Related below links this Account Settings tab to modules, workflows, concepts, and escalation paths.

Documentation map & escalation​

Upstream & downstream workflows​

Deeper workflow reads​

See Upstream & downstream workflows above for the same guides.

Operator modules​

  • Finance module — Approve payments, Reject selected, and deposit disputes gated by role permissions
  • Bookings module — Reservation workflows gated by Bookings module and sub-permissions
  • Operations — Tickets — Ticket assignments reference team members
  • Analytics module — analytics.module permission in the role matrix
  • Audit module — Cross-portfolio block review when audit.module is restricted
  • Inbox module — Portfolio WhatsApp triage permission paired with Bookings module access
  • AI Chat module — assistant gated by the AI / MCP role permission rather than by a module permission

Deeper concept reads​

Companion API guides​

Module documentation hubs​

Operator habit hubs​

Day-to-day operator habits (lockout catch-up, pending receipts, payment triage, handoffs, and related playbooks) live on the Common Workflows habit hub.

Deep-link anchors for habit hubs

Lockout catch-up after password recovery​

Pending manual receipt approval​

Reject/revert mistaken receipts​

Notification row-click navigation​

Payment alert to receivables triage​

Confirmation alert triage​

Finance debt receivables triage​

Handling a Late Payment collections​

Finance Income status drill-down​

Cash flow forecast drill-down​

Key glossary terms​