Role-based access control

Role-Based Access Control for PG, Hostel and Co-Living Operations

Give owners, managers, wardens and tenants exactly the permissions they need while keeping sensitive data secure.

EasyAavaas supports role-based access control for owners, managers, wardens and tenants. No more sharing one admin password with your entire team. Every person gets access based on their role at each property — and owners can fine-tune permissions for individual staff members.

Practical guide · Live product workflow · Built for India

✓Role-based access controlA practical path
EasyAavaas complaints screen on iPhone
EasyAavaas guideWhat to do, when to do it, and why
01

Property-Scoped Roles — Not Global Access

In EasyAavaas, roles are assigned per property, not globally. This means:

Authentication is phone-first (OTP login). One phone number connects to all properties and roles assigned to that user.

When you select a property, the app determines your persona based on your highest role: Owner → Manager → Warden → Accountant → Staff → Support → Tenant.

  • A user can be Owner at PG A and Warden at PG B
  • Permissions at PG A do not grant access to PG B
  • Tenants only see their own complaints, payments, and requests — never other tenants' data
  • Staff permissions can be customized individually without changing the role defaults
02

Role Comparison — What Each Role Can Do

This table shows default permissions for each role at a property. Manager and Warden have identical default permissions — the distinction is organizational.

CapabilityOwnerManager / WardenTenantStaffAccountantSupport
View property details✓✓✓✓✓✓
Edit property setup (floors, rooms, beds)✓✓————
Delete property✓—————
List and manage staff members✓✓—View onlyView onlyView only
Assign staff roles✓✓————
Customize staff permissions✓✓————
Enroll tenants✓✓————
View tenant directory✓✓————
View tenant profile & documents✓✓————
Update tenant profile✓✓————
Remove / move-out tenant✓✓————
Assign beds and rooms✓✓————
Generate monthly rent✓✓————
View rent records✓✓————
Update rent records✓✓————
Submit payment proof——✓———
Record payments manually✓✓————
Verify / reject payments✓✓————
View announcements✓✓✓✓✓✓
Send announcements✓✓—✓✓✓
Manage inventory✓✓————
Issue / return inventory to tenants✓✓————
File complaint✓✓✓ (own)———
View all complaints✓✓————
View own complaints——✓———
Manage complaints (assign, resolve)✓✓————
Manage utility bills✓✓————
View visitors✓✓✓———
Manage visitors (approve, check-in/out)✓✓————
Create and manage approval requests✓✓✓ (own)———
View dashboard & analytics✓✓————
Export PDF / Excel reports✓✓————

Manager and Warden have identical default permissions in EasyAavaas. Both are designed for on-site operational control. The distinction is organizational — you assign the title that matches your team structure.

03

Owner — Full Control

The Owner role has complete access to the property. Owners can do everything: set up the property, manage all staff, enroll and remove tenants, handle all financial operations, configure permissions, and delete the property.

Owners are the only role with implicit full permissions (* — all permission keys). This includes capabilities not listed in the default manager/warden set, such as property deletion.

  • Ideal for: PG proprietors, hostel owners, co-living operators who need full visibility and control
  • Property creation and setup
  • Staff hiring and permission management
  • Financial oversight (rent, utilities, deposits)
  • Strategic decisions (rules, penalties, amenities)
  • Multi-property portfolio management
04

Manager & Warden — Day-to-Day Operations

Managers and Wardens are your on-site operational team. They share the same default permissions because both roles need to run the PG day to day — enrolling tenants, recording payments, verifying proof, handling complaints, managing visitors, and sending announcements.

What managers and wardens do daily

  • Enroll new tenants and assign beds/rooms
  • Generate and track monthly rent
  • Verify tenant payment proofs (UPI screenshots)
  • Record cash payments manually
  • Assign and resolve complaints
  • Approve or deny visitor entries
  • Check visitors in and out
  • Send announcements to tenants
  • Manage inventory (issue keys, furniture, etc.)
  • Create and manage utility bills
  • Assign additional staff (wardens can assign STAFF role; managers can assign warden and staff)
  • Customize permissions for staff they manage

What they cannot do by default

  • Delete the property
  • (Configurable) — owners can restrict any specific permission
05

Tenant — Self-Service Access

Tenants get a focused self-service experience. They can manage their stay without accessing staff tools or other tenants' data.

Ideal for: PG residents who need a simple app to see their dues, submit payment proof, and reach management — without WhatsApp group chaos.

What tenants can do

  • View property information and announcements
  • File complaints with photos and track resolution
  • Reply to complaint updates on their own complaints
  • Submit rent payment proofs for staff verification
  • Create approval requests (room change, move-out, etc.)
  • View their own visitor records
  • View their own request status

What tenants cannot do

  • View other tenants' information
  • Access staff or management tools
  • Verify payments or manage rent for others
  • Assign rooms or enroll tenants
06

Staff, Accountant & Support — Limited Default Access

These roles ship with minimal default permissions, designed for team members who need limited access.

Owners can expand any of these roles with custom permission overrides — for example, grant an accountant payment.view and rent.list without giving them tenant management access.

  • View property details
  • List staff members
  • View and send announcements
RoleCommon assignment
StaffHousekeeping supervisor, kitchen staff lead — can view property and send announcements
AccountantExternal accountant — view-only access, can receive announcements
SupportHelp desk or customer support — view property context
07

Customize Permissions Per Staff Member

Default role permissions are built into EasyAavaas and cover most PG operations out of the box. When you need finer control, owners and managers can override permissions for any staff member individually.

Editable roles (can receive overrides): Manager, Warden, Staff, Accountant, Support. Not editable via overrides: Owner (always full access), Tenant (fixed self-service set).

  • Staff member is assigned a role (e.g., Warden)
  • They inherit all default warden permissions
  • Owner adds an override: grant extra permission or revoke a specific one
  • Effective permissions = role defaults ± overrides

Example overrides

  • Grant a staff member payment.verify without full warden access
  • Revoke tenant.remove from a manager who should not move tenants out
  • Grant an accountant rent.list and payment.view for reconciliation

Permission groups available

GroupPermissions
Propertyview, edit, delete
Memberslist, assign, update, revoke, permissions
Tenantsenroll, list, view, update, remove
Roomsassign (bed/room occupancy)
Rentlist, view, generate, update
Paymentsview, submit, record, verify, reject
Announcementslist, send
Inventorylist, view, manage, issue, return, override
Complaintslist, view, create, manage
Utilitieslist, view, manage
Visitorslist, view, manage
Requestslist, view, create, manage
08

Security Built Into the Architecture

EasyAavaas enforces access control at the API level — not just in the UI.

This architecture matters for larger operators managing multiple PGs with different staff at each location.

  • Every protected API checks authentication, property membership, and permission before executing
  • Tenants cannot access other tenants' complaints, payments, or profiles
  • Staff at Property A cannot query Property B's data
  • Permissions use explicit keys (e.g., payment.verify, complaint.manage) — no hidden role checks in business logic
  • Phone-first identity — no shared passwords

Frequently asked questions

Common questions about role-based access control with EasyAavaas.

Can one person have different roles at different properties?

Yes. A user can be Owner at one PG and Warden at another. Permissions are always property-scoped.

Can I restrict what a warden can do?

Yes. Owners and managers can add permission overrides to grant or revoke specific capabilities for any staff member.

Do tenants see other tenants' data?

No. Tenants only see their own complaints, payments, and requests. Staff and owner roles see property-wide data based on their permissions.

How do I invite staff?

Assign staff by phone number. If they don't have an account, EasyAavaas creates a minimal user profile automatically. They log in with OTP — no password needed.

Watch the walkthroughs

Short videos from our YouTube channel showing these workflows in the live app.

EasyAavaas Hindi Demo — PG Management with the App & WhatsApp

A Hindi walkthrough of daily PG operations with EasyAavaas and WhatsApp: rent records, payment proof and reminders, tenant documents, utility bills, complaints, visitors, notices, team permissions and reports. Rent money goes directly to you; the app keeps the records.

Some screens and messages are reconstructed with example data. Notifications depend on the relevant settings and an available WhatsApp contact.

All tutorials on YouTube

Related solutions

Explore other operational modules — or combine them on one platform.

Bring the team together

Give Your Team the Right Access Today

Stop sharing one login across your warden, accountant, and owner. EasyAavaas gives every person exactly what they need — property by property, role by role. Set up roles in minutes. Invite staff by phone number.