Hospitality and food service: managing IT access for seasonal staff

IT Operations · 3 min

Industry: Hospitality and food service

Articles by Bruno Roque

Rotating teams and shared accounts at tills and booking systems create risks that often go unnoticed. Here's how to organize onboarding, role changes and departures without slowing down service.

Hospitality and food service: managing IT access for seasonal staff

TL;DR

Staff turnover is part of the operating model

In hospitality and food service, in Portugal and other European tourist destinations, hiring tracks demand: reinforcements during peak season, extra staff for events, interns and temporary workers come and go throughout the year. Each person needs, from their very first shift, access to the hotel management system (PMS, Property Management System), the point-of-sale (POS) terminal, the shift schedule, email and, at times, booking portals. The operational question is easy to state and hard to fulfil: how to grant the right access on day one and remove it on the last day, without depending on the memory of whoever is on duty.

Shared accounts hide who did what

Under service pressure, shortcuts are common: a generic user for the front desk, a till code shared across the floor, a password taped next to the terminal. These shortcuts solve the immediate problem but create two lasting risks. The first is the loss of traceability, since an improper discount, a refund or access to guest data can no longer be attributed to a specific person. The second is access remaining active after an employee leaves, which is particularly sensitive for internet-accessible portals such as channel managers or online travel agency extranets.

PCI DSS provides an objective reference for those accepting cards

PCI DSS is a payment industry standard, enforced contractually rather than by law, that covers entities processing card data. According to the PCI Security Standards Council, the use of shared, group or generic credentials should be avoided except in exceptional circumstances, and requirement 8.2.2 applies to all such credentials, not just administrative ones. The stated goal is that every action be attributable to an individual identifier. The exact scope depends on the payment architecture, for example the type of terminals used, and should be confirmed with the acquirer or a qualified assessor. In parallel, guest data is personal data covered by GDPR, and access control is one of the organizational measures typically considered, in proportion to risk.

The access lifecycle starts in HR

An approach that tends to work is treating the hiring record as the origin of access. Predefined role-based profiles, such as receptionist, waiter, floor supervisor or housekeeper, prevent improvised decisions and permissions inherited from colleagues. Each account is created with the contract end date and is automatically deactivated on that day, while role changes require a review of the profile instead of simply adding permissions. At the POS, personal cards or individual codes allow fast identification without sacrificing service speed, and single sign-on can simplify the rest when vendors support it. An account review at the end of each season helps catch anything that slipped through the process. For unforeseen situations, such as a breakdown during the night shift, it's worth defining controlled emergency access in advance, rather than reactivating old accounts.

Exceptions and limits require explicit decisions

Not everything fits the ideal model. Shared kitchen terminals, service accounts linking the PMS to the POS, and remote vendor access need their own rules, with an identified owner and periodic review. Many SaaS-based PMS and POS platforms offer limited integration with identity directories, which requires combining automation with manual checklists. In a small restaurant, a departure checklist followed with discipline may be enough, while a hotel group with multiple properties benefits from centralization and identity risk detection. Where the internal team is small, continuous technical support can ensure account creation and deactivation at night and on weekends, periods when hotel operations continue running.

Simple discipline sustains operations

Managing access for seasonal staff is primarily a process problem, not a technology one. Individual identification, role-based profiles and deactivation tied to contract end dates can help reduce risks of fraud, guest data exposure and audit difficulties. The right design depends on business size, payment architecture and vendor capabilities, and specific obligations should be confirmed for each case.

Related

References

  1. PCI Security Standards Council — FAQ: Does PCI DSS Requirement 8.2.2 allow users to share authentication credentials?