ST Stay Tantra
Core module

Administration & Security

The platform security module — multi-tenant isolation, roles, and authentication.

Platform module Multi-tenant RBAC Master admin Property scope Secure auth

Multi

Tenant isolation

RBAC

Custom roles

4+

Portal auth flows

Scope

Per-property access

Overview

What Administration & Security covers

Administration & Security is the foundation of Stay Tantra. Each client operates in an isolated tenant environment while master administrators oversee the platform. Custom roles, property-scoped permissions, and separate authentication flows protect every portal.

Master admins provision clients, properties, and subscriptions from a central console. Tenant administrators define custom roles that scope staff to specific properties and modules. Guests and staff each authenticate through dedicated flows — master admin, tenant staff, and guest portals remain securely separated.

Ideal for

Platform operators · Multi-property groups · Enterprise hospitality clients

Role and permission management for tenant staff Multi-tenant client isolation and property scoping

Benefits

Key benefits

1

Enterprise-ready isolation

Run many hospitality clients on one platform without data bleeding between tenants.

2

Least-privilege staff access

Housekeeping, kitchen, and front desk see only the screens their role requires.

3

Central operator oversight

Master admins manage the full client footprint — provisioning, plans, and support context.

4

Confidence at scale

Property-scoped RBAC and separate guest auth support multi-site and multi-brand deployments.

Workflow

How Administration & Security works

From client provisioning to daily access — how security fits your platform operations.

1 01 Provision

Create clients & properties

Master admins set up tenant environments, properties, and initial subscriptions.

  • Client records
  • Property setup
  • Database isolation mode
2 02 Configure

Define roles & permissions

Tenant admins create roles that map to hotel, restaurant, and settings access.

  • Custom role builder
  • Module permissions
  • Property assignments
3 03 Assign

Onboard staff accounts

Invite users, assign roles, and scope them to the correct properties.

  • Staff user creation
  • Role assignment
  • Property scoping
4 04 Operate

Secure daily access

Staff, guests, and operators each authenticate through the appropriate portal flow.

  • Tenant staff sign-in
  • Guest token sessions
  • Master admin oversight

Capabilities

Everything included

Isolation, roles, authentication, and settings — grouped by security layer.

Platform & tenant isolation

How client data stays separated on the platform.

  • Master admin layer

    Operator console above all client tenants.

  • Per-client tenants

    Isolated environments for each hospitality client.

  • Property records

    Hotel and restaurant sites scoped under each client.

  • Database modes

    Shared or dedicated storage options per deployment needs.

Roles & permissions

Fine-grained control over who accesses what.

  • Custom tenant roles

    Build roles for front desk, kitchen, housekeeping, and managers.

  • Module permissions

    Toggle access to reservations, floor, kitchen, settings, and billing.

  • Property scoping

    Limit users to specific hotels or restaurants.

  • Rate & billing visibility

    Restrict sensitive financial screens by role.

Authentication & branding

Secure entry points and platform identity.

  • Tenant staff login

    Client code plus individual credentials for staff portals.

  • Guest token access

    Stay and QR sessions without staff credentials.

  • Master admin auth

    Separate operator authentication for platform management.

  • Application settings

    Central branding, contact, and configuration controls.

Portals

By portal

How each portal type uses administration and security controls.

Portal

Hotel Staff Portal

Tenant staff authenticate with role-scoped hotel module access.

  • Client code and staff credentials
  • Property-scoped reservations and rooms
  • Role-limited settings and billing views
  • Multi-property switch when permitted

Portal

Restaurant Floor Portal

Floor and kitchen staff access dining modules by assigned role.

  • Separate permissions for floor vs kitchen
  • Menu admin vs service-only roles
  • Property-scoped floor visibility
  • Secure staff sign-in per client

Portal

Guest Stay Portal

Guests access stay hubs via secure tokens — not staff accounts.

  • Reservation-scoped secure links
  • No shared staff credentials
  • Time-bound guest sessions
  • Isolated from tenant admin settings

FAQ

Common questions

Is each client's data isolated?

Yes. Stay Tantra uses multi-tenant architecture with per-client isolation so operational data does not mix between properties under different clients.

Can we create custom staff roles?

Yes. Tenant administrators define custom roles with module and property permissions — for example, housekeeping without billing access.

Do guests use staff login credentials?

No. Guests access stay and QR portals through secure token-based sessions separate from staff authentication.

Who manages clients and subscriptions?

Master administrators provision clients, assign properties, and manage subscriptions from the operator layer above tenant environments.