Roles and permissions
Give each person the access their job needs, by role and, on Growth and above, by site.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
Everyone who signs in to Agoo has a role. The role decides what they can see and do; on Growth and above, it can also be limited to particular sites. Front desk, hosts, security and admins each see only what their role and site allow.
See what each role can do in Console → Settings → Roles, and give people roles in Console → People.
Built-in roles
| Role | Typical person | Uses | Can |
|---|---|---|---|
| Owner | The account holder | Console | Everything, including billing, transferring ownership and closing the organisation. One per organisation. |
| Admin | IT, facilities or office manager | Console | Everything except ownership and closing the organisation: people, sites, devices, forms, branding, notifications |
| Site admin | Branch or site manager | Console | What an Admin can do, for their own sites only (Growth and above) |
| Receptionist | Front desk | Console, Workspace | Check visitors in and out, invite visitors for any host, log deliveries, print badges, see the on-site list |
| Security lead | Head of security | Console, Workspace | Everything a receptionist can do, plus manage the watchlist, run roll calls, see the audit trail for their sites and manage guards |
| Guard | Gate security | Kiosk (guard mode), Workspace | Scan passes, check people in and out at the gate, log vehicles, call or WhatsApp hosts |
| Host | Anyone who receives visitors | Workspace, Console | Invite their own visitors, approve or decline arrivals, manage their bookings, set delegates |
| Employee | Staff on attendance | Workspace | Clock in and out, request leave, see their own attendance |
| Auditor | Internal audit or compliance | Console (read-only) | Read reports, the visit history and the audit trail |
Each person has one role. An Employee who also receives visitors can be given the Receives visitors switch in Console → People, so they can invite guests and approve arrivals. Kiosks don't use roles: each kiosk is paired to a site as a device and can only do kiosk tasks.
The number of admin seats depends on your plan: 1 on Free, 3 on Starter, 10 on Growth, unlimited on Pro, and unlimited with delegated administration on Enterprise.
What each plan adds
| Plan | Roles |
|---|---|
| Free and Starter | Basic: the built-in roles, applying across the whole organisation |
| Growth | Per site: limit any role to particular sites, so a Tema Branch receptionist sees only Tema Branch |
| Pro | Custom roles: copy a built-in role and switch individual permissions on or off. Arrives in P9. |
| Enterprise | Approval chains: visits that need several sign-offs, such as host, then security, then facilities, with time limits and escalation. Arrives in P9. |
Give someone a role
Open Console → People
Find the person, or add them. Staff can also come from a CSV import or your Google or Microsoft directory.
Choose their role
Choose their role. On Growth and above, choose All sites or pick the sites the role applies to.
Save
The change takes effect straight away: if they're using Agoo, it catches up on their next click. Agoo emails them about it, and the change, with who made it, is recorded in the audit trail.
Good practice
- Keep Owners and Admins few. Give people the narrowest role that lets them do their job.
- Use two-step verification for everyone with admin access.
- Remove access on the day someone leaves. Deactivate them in Console → People; with single sign-on and SCIM, this happens automatically when they're removed from your directory.
- Review roles every quarter. Filter Console → People by role to check who has admin access.