Roles & Accounts
How staff and customer accounts work, and who can do what.
LSCApp runs two completely separate account systems — staff and customers never share a login, a sign-up flow, or even the same authentication app underneath.
Staff accounts
Staff sign in through an invite-only system. There is no public staff sign-up page — an existing OWNER or ADMIN must invite you by email before you can create an account at all. This is deliberate: it's a security boundary, not an oversight.
The three staff roles
| Role | Can do |
|---|---|
| OWNER | Everything. The only role that can act instantly on staff invites and role changes without a second approval. |
| ADMIN | Everything day-to-day: approve refunds, manage the catalog, review registered-office applications, run reports. Staff invites and role changes they propose need OWNER approval. |
| FRONT_DESK | Day-to-day front-desk operations: check-ins, mail intake, walk-in sales, staff-created bookings. Refunds, invoice voids, and weekend bookings they initiate always need OWNER/ADMIN approval — regardless of amount. |
The exact rules for what needs approval and from whom are covered in Approvals.
Signing in
Staff use manage.lionshare.cloud or admin.lionshare.cloud (both serve
the same role-gated admin area) on the web, or the staff companion mobile
app. If you ever hit "Not authorized" after previously being able to sign
in, see
Staff Can't Log In —
it's a known, quick fix.
Customer accounts
Customer sign-up is open — anyone can create a portal account at
portal.lionshare.cloud, no invitation needed. But creating an account is
never required: every public purchase flow can be completed as a guest,
start to finish, with an optional "create an account to track this later"
email sent afterward.
If a guest later signs up using the same email they used to check out, the new account links to their existing customer record automatically — it never creates a duplicate. See Guest Checkout Policy for the reasoning and the exact mechanics.
Customers reach their account through:
- The web portal at
portal.lionshare.cloud - The native customer app (iOS/Android)
Both talk to the exact same backend and see the exact same data — there's no feature gap between them by design, only presentation differences.
Company roles
Within a company (a shared billing/access group), a customer can also hold company-level flags, independent of anything above:
- isAdmin — can manage the company's team and settings from the customer portal.
- isBillingContact — pays for the group; sees invoices the rest of the team doesn't.
- isEmployee — counts toward the company's shared day-pass pool and (if the company has an office lease) that lease's shared meeting-room credit pool and seat count.
A real person can hold any combination of these, or none.