Hospitality and food service: managing IT access for seasonal staff
IT Operations · 3 min
Industry: Hospitality and food service
Articles by Bruno Roque
Rotating teams and shared accounts at tills and booking systems create risks that often go unnoticed. Here's how to organize onboarding, role changes and departures without slowing down service.

TL;DR
- In hospitality and food service, staff turnover is structural and should be reflected in how access is granted and removed.
- Generic accounts on point-of-sale terminals or hotel management systems make it hard to attribute actions and investigate incidents.
- For businesses that accept cards, PCI DSS requires individual identification and only allows shared credentials in exceptional, controlled circumstances.
- Role-based profiles, contract end dates and deactivation tied to HR records reduce reliance on whoever happens to be on shift remembering to act.
- The level of automation possible depends on software vendors and business size, and should be assessed case by case.
Staff turnover is part of the operating model
In hospitality and food service, in Portugal and other European tourist destinations, hiring tracks demand: reinforcements during peak season, extra staff for events, interns and temporary workers come and go throughout the year. Each person needs, from their very first shift, access to the hotel management system (PMS, Property Management System), the point-of-sale (POS) terminal, the shift schedule, email and, at times, booking portals. The operational question is easy to state and hard to fulfil: how to grant the right access on day one and remove it on the last day, without depending on the memory of whoever is on duty.
Shared accounts hide who did what
Under service pressure, shortcuts are common: a generic user for the front desk, a till code shared across the floor, a password taped next to the terminal. These shortcuts solve the immediate problem but create two lasting risks. The first is the loss of traceability, since an improper discount, a refund or access to guest data can no longer be attributed to a specific person. The second is access remaining active after an employee leaves, which is particularly sensitive for internet-accessible portals such as channel managers or online travel agency extranets.
PCI DSS provides an objective reference for those accepting cards
PCI DSS is a payment industry standard, enforced contractually rather than by law, that covers entities processing card data. According to the PCI Security Standards Council, the use of shared, group or generic credentials should be avoided except in exceptional circumstances, and requirement 8.2.2 applies to all such credentials, not just administrative ones. The stated goal is that every action be attributable to an individual identifier. The exact scope depends on the payment architecture, for example the type of terminals used, and should be confirmed with the acquirer or a qualified assessor. In parallel, guest data is personal data covered by GDPR, and access control is one of the organizational measures typically considered, in proportion to risk.
The access lifecycle starts in HR
An approach that tends to work is treating the hiring record as the origin of access. Predefined role-based profiles, such as receptionist, waiter, floor supervisor or housekeeper, prevent improvised decisions and permissions inherited from colleagues. Each account is created with the contract end date and is automatically deactivated on that day, while role changes require a review of the profile instead of simply adding permissions. At the POS, personal cards or individual codes allow fast identification without sacrificing service speed, and single sign-on can simplify the rest when vendors support it. An account review at the end of each season helps catch anything that slipped through the process. For unforeseen situations, such as a breakdown during the night shift, it's worth defining controlled emergency access in advance, rather than reactivating old accounts.
Exceptions and limits require explicit decisions
Not everything fits the ideal model. Shared kitchen terminals, service accounts linking the PMS to the POS, and remote vendor access need their own rules, with an identified owner and periodic review. Many SaaS-based PMS and POS platforms offer limited integration with identity directories, which requires combining automation with manual checklists. In a small restaurant, a departure checklist followed with discipline may be enough, while a hotel group with multiple properties benefits from centralization and identity risk detection. Where the internal team is small, continuous technical support can ensure account creation and deactivation at night and on weekends, periods when hotel operations continue running.
Simple discipline sustains operations
Managing access for seasonal staff is primarily a process problem, not a technology one. Individual identification, role-based profiles and deactivation tied to contract end dates can help reduce risks of fraud, guest data exposure and audit difficulties. The right design depends on business size, payment architecture and vendor capabilities, and specific obligations should be confirmed for each case.
Related
- How Observability and AIOps help accelerate incident response
- Managed SOC/NOC for SMEs: an alternative to 24/7 in-house operations
- CMDB: managing dependencies before the incident
- Runbooks: turning incident response into repeatable operations