Docs
Security and safety

Roles and permissions

Give each person the access their job needs, by role and, on Growth and above, by site.

Early access· P3For owners and admins

Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.

Everyone who signs in to Agoo has a role. The role decides what they can see and do; on Growth and above, it can also be limited to particular sites. Front desk, hosts, security and admins each see only what their role and site allow.

See what each role can do in Console → Settings → Roles, and give people roles in Console → People.

Built-in roles

RoleTypical personUsesCan
OwnerThe account holderConsoleEverything, including billing, transferring ownership and closing the organisation. One per organisation.
AdminIT, facilities or office managerConsoleEverything except ownership and closing the organisation: people, sites, devices, forms, branding, notifications
Site adminBranch or site managerConsoleWhat an Admin can do, for their own sites only (Growth and above)
ReceptionistFront deskConsole, WorkspaceCheck visitors in and out, invite visitors for any host, log deliveries, print badges, see the on-site list
Security leadHead of securityConsole, WorkspaceEverything a receptionist can do, plus manage the watchlist, run roll calls, see the audit trail for their sites and manage guards
GuardGate securityKiosk (guard mode), WorkspaceScan passes, check people in and out at the gate, log vehicles, call or WhatsApp hosts
HostAnyone who receives visitorsWorkspace, ConsoleInvite their own visitors, approve or decline arrivals, manage their bookings, set delegates
EmployeeStaff on attendanceWorkspaceClock in and out, request leave, see their own attendance
AuditorInternal audit or complianceConsole (read-only)Read reports, the visit history and the audit trail

Each person has one role. An Employee who also receives visitors can be given the Receives visitors switch in Console → People, so they can invite guests and approve arrivals. Kiosks don't use roles: each kiosk is paired to a site as a device and can only do kiosk tasks.

The number of admin seats depends on your plan: 1 on Free, 3 on Starter, 10 on Growth, unlimited on Pro, and unlimited with delegated administration on Enterprise.

What each plan adds

PlanRoles
Free and StarterBasic: the built-in roles, applying across the whole organisation
GrowthPer site: limit any role to particular sites, so a Tema Branch receptionist sees only Tema Branch
ProCustom roles: copy a built-in role and switch individual permissions on or off. Arrives in P9.
EnterpriseApproval chains: visits that need several sign-offs, such as host, then security, then facilities, with time limits and escalation. Arrives in P9.

Give someone a role

Open Console → People

Find the person, or add them. Staff can also come from a CSV import or your Google or Microsoft directory.

Choose their role

Choose their role. On Growth and above, choose All sites or pick the sites the role applies to.

Save

The change takes effect straight away: if they're using Agoo, it catches up on their next click. Agoo emails them about it, and the change, with who made it, is recorded in the audit trail.

Good practice

  • Keep Owners and Admins few. Give people the narrowest role that lets them do their job.
  • Use two-step verification for everyone with admin access.
  • Remove access on the day someone leaves. Deactivate them in Console → People; with single sign-on and SCIM, this happens automatically when they're removed from your directory.
  • Review roles every quarter. Filter Console → People by role to check who has admin access.

On this page