At the moment, using the mobile app as a restricted user lets you circumvent some security related restrictions.
Specifically in my case, we have a sub-account for the cleaner. The cleaner is set to the role "Cleaner" which results in being able to look at the names and dates of the guests for the next stays, but not at the prices and of course not the messages we exchange with the guests - at least when being logged in via browser.
It now occured to me that the cleaner can indeed access the prices charged for the stay and also access the guest's communication when using the mobile app! The security settings connected to the role are not taken into account when using the mobile app. This is fatal to me because it violates some data privacy regulations in people seeing information that they are not entitled to see (internal vs. external).
Mobile app lets users circumvent role limitations - should respect role permissions
-
ashergibson
- Posts: 28
- Joined: Thu Jun 25, 2020 2:20 am
Thank you for bringing this to our attention. This is something we're currently reviewing, and we appreciate you highlighting how it’s affecting your setup.
-
fewobergsonne
- Posts: 19
- Joined: Fri May 02, 2025 7:45 am
Thanks for your feedback. I created a workaround for our cleaners which should work 'okay' for the moment. I believe it is best for both users and Beds24 to have a permanent solution for this and am happy if you are very aware of the situation.ashergibson wrote: ↑Wed Jul 09, 2025 5:06 amThank you for bringing this to our attention. This is something we're currently reviewing, and we appreciate you highlighting how it’s affecting your setup.
-
beachcomberboss
- Posts: 5
- Joined: Mon Nov 25, 2024 4:18 pm
@fewobergsonne
What's the workaround?
@Beds24
I'm also interested in this.
What's the workaround?
@Beds24
I'm also interested in this.
-
ashergibson
- Posts: 28
- Joined: Thu Jun 25, 2020 2:20 am
We are certainly aware of this issue. While we can’t give a timeline, a permanent solution may be implemented in the future.