ArabGym
Operations

Who Sees What: Staff Roles and Permissions in a Gym

In most gyms there is one account called “reception” that everyone knows the password to. It works efficiently right up until the day you need to know who cancelled that membership — or until an employee leaves and the account stays. Here is a better way to divide the access.

5 min read

Ask any gym owner how many system accounts they have and the answer is usually far smaller than their headcount. One account called “reception” that both the morning and evening shift know, and the owner’s account used for anything the first one refuses. The arrangement works with genuine efficiency — right up until you need the answer to one question: who did this?

A membership cancelled at a full discount, a cash amount recorded then edited, a member deleted. With a shared account there is no answer — the log says “reception”, and that is the name of four people. Dividing access is not about distrusting staff; it is about being able to answer that question, and about protecting the employee from an accusation they cannot disprove.

The rule: the least access the job needs

The principle is simple, boring and effective: each employee gets what their job needs and nothing beyond it. Not because they will misuse it, but because what never appears on their screen cannot be leaked by accident, edited by a mis-tap during a rush, or extracted from them by a third party.

Three categories of data in any gym deserve to be told apart: money (revenue, invoices, receivables), member personal data (phone, ID, health notes), and operations (the timetable, attendance, classes). Most roles need one or two of them, not all three.

A sensible split for a mid-sized gym
RoleMoneyMember dataOperations
OwnerFullFullFull
ManagerFullFullFull
ReceptionTake payments, no reportsFullFull
AccountantFullNoneNone
CoachNoneOwn classes onlyOwn schedule only
A sensible split for a mid-sized gym

The most important distinction in that table is between “take a payment” and “see the revenue report”. Reception needs the first every shift and never needs the second; in most systems they are two entirely separate permissions. Conflating them is the commonest reason reception ends up with full visibility of the gym’s numbers.

Member data is not one category

A member’s name and membership status is operational information that everyone on the door needs. Their phone and email is contact information that reception and marketing need. Their national ID and health notes are something else entirely: sensitive data that most people working in a gym do not need on any ordinary day.

Health notes in particular deserve separate treatment. A previous injury or a heart condition is information the coach writing the programme needs, and the accountant and the receptionist do not. A good working rule: any field that would be a news story if it leaked should sit behind a specific role, not behind “employee”.

Branches: the dimension most people forget

In a multi-branch gym it is not enough to ask “what does this employee see?”, but “where do they see it?”. A receptionist in the Jeddah branch does not need the Riyadh branch’s member list or its attendance, and their appearing is less a security risk than noise: longer lists, searches returning people they will never meet, and numbers that are not about their work.

The care needed here is that the restriction be consistent. A branch-restricted employee who sees 922 of her branch’s members on one screen and then the gym-wide 1,152 on another will lose confidence in both. Partial scoping is worse than none, because it reads as a fault in the numbers rather than as a rule.

And some numbers cannot be scoped by their nature. An invoice belongs to the business rather than to a club, so the revenue report stays at company level. That is fine — what matters is that it is said out loud, rather than leaving a branch-restricted accountant to assume the figure is their branch’s.

The audit trail: the real payoff of individual accounts

The bigger benefit of giving each employee an account is not preventing anything; it is recording everything. When every action carries a name and a time, the questions in a gym change in kind: from “is somebody stealing?” to “that is three large discounts in one shift, let us ask about it.” The second question can be answered; the first cannot.

The events worth reviewing periodically are few and well known: discounts above a threshold, membership cancellations, editing or deleting a recorded payment, changing a plan price, and deleting a member. A five-minute weekly review of that list surfaces most of what is findable and replaces any heavier monitoring.

Moving from one account to several

  1. Create an account for every person who works with you, in their own name, including part-timers and seasonal staff.
  2. Start each role at the least reasonable access and widen it at the first genuine need. Widening on request is easier than narrowing after people have grown used to it.
  3. Disable the old shared account on an announced date rather than gradually. A shared account kept “for emergencies” is kept forever.
  4. Review the list quarterly: who left without being disabled, who was promoted without a permission change, and who holds access they have never once used.

The first step alone solves more than half the problem and costs minutes. The hard part is not technical but social: explaining to the team that separate accounts protect them as much as you — because the employee working under their own account is the only one who can prove they did not do something.

Frequently asked questions

What is wrong with one shared reception account?
Three problems. First, you cannot tell who performed an action — the log says “reception”, which is several people. Second, the account is always granted the highest access anyone using it needs, so everyone sees more than they require. Third, the employee who leaves still knows the password, and changing it means telling everyone, so it gets postponed.
Should a receptionist see revenue reports?
Usually not, because “take a payment” and “see the gym’s total revenue” are different permissions. Reception needs the first every shift and does not need the second to do their job. Conflating the two is the commonest reason reception ends up with full visibility of the gym’s numbers without anyone deciding it explicitly.
What should a coach be able to see?
Their own schedule and classes, the roster for those classes, and body metrics and health notes for the members they train — because those are necessary to write a safe programme. They do not need revenue figures, invoices, the full member list, or the ability to edit another coach’s sessions.
Should I delete an employee’s account when they leave?
Disable it rather than delete it. Disabling blocks access immediately, while deleting can sever the link between past actions and the name that performed them, costing you the historical record. Make disabling the first item in the exit process, before the keys come back.
How do I restrict an employee to one branch?
Attach the employee’s account to the branch they work at, and leave owner and manager accounts unrestricted. What matters most is that the restriction is consistent across every screen: someone who sees their branch’s member count on one and the gym-wide total on another will lose confidence in both. Some numbers — revenue, for one — belong to the business by nature and cannot be scoped; that just needs saying clearly.

Related ArabGym features