Give staff access to exactly what they need — nothing more
Every staff account is backend-enforced, not just hidden in the UI. Grant exactly the permissions a role needs — company-wide or scoped to a single location — so a front-desk hire can manage the calendar without ever seeing revenue.
Sign upHow it works
01
Add a staff account
Invite a staff member by email. They get their own login — never a shared password — with access scoped to exactly what you grant them.
02
Grant specific permissions
Choose from 7 permission categories — viewing revenue, managing services, managing other staff, viewing clinical notes, managing locations, managing the waitlist, and viewing client records — and assign only what that role actually needs.
03
Scope by location if you run more than one
For multi-location businesses, override a staff member's permissions per location — a manager can have full access at their own branch and none at the others, enforced automatically on every request that touches multiple locations.
Real access control, not a hidden button
Enforced by the API, not just hidden in the UI
Permission checks run on the backend for every request — hiding a button in the dashboard isn't the security model. A staff member without revenue access can't pull that data by calling the API directly either.
Assign staff to the services they actually perform
Limit which services each staff member can be booked for, so your public booking page only offers a client the providers who are actually qualified for that service.
Scales from a solo front desk to a 50-person team
Staff accounts scale from 5 on Starter to 50 on Scale, with the same permission model at every tier — you're not forced onto a more expensive plan just to add role-based access.
Staff permissions comparison
| Feature | Waine | Vagaro | Square | Acuity | Calendly |
|---|---|---|---|---|---|
| Backend-enforced (not just UI-hidden) permissions | ✓ | Partial | Partial | Partial | — |
| Per-location permission overrides | ✓ | Partial | — | — | — |
| Per-service staff assignment | ✓ | Partial | Partial | Partial | Partial |
Waine capabilities are verified in-product. Competitor capabilities were last reviewed in September 2026 against each vendor's public documentation — “Partial” means the capability exists but with limits. See our detailed comparisons.
Frequently asked questions
What can I control with staff permissions?
Seven categories: viewing revenue and financial data, managing services, managing other staff accounts, viewing clinical or intake notes, managing locations, managing the waitlist, and viewing client records. Grant only what a role needs.
Can I give different access at different locations?
Yes. For multi-location businesses, you can override a staff member's permissions per location — useful when a manager should have full access at their own branch but only basic access elsewhere.
How many staff accounts can I add?
5 on Starter, 15 on Growth, and 50 on Scale — the Free plan doesn't include staff accounts. Every tier that includes staff gets the same permission system.
Give your team access without giving up control
Staff permissions are enforced by the API on every plan that includes staff accounts — starting at Starter.
Sign up