Documents to sign
Your privacy notice, NDAs, waivers and site rules, accepted or signed before or at the visit, with fixed versions, re-sign rules and a signed PDF copy for the visitor.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
Some visits need an agreement first: your privacy notice, a non-disclosure agreement for a consultant, a waiver for a factory tour, the site rules for a ward or a building site. In Agoo you write each document once, publish it, and choose which visitors it's asked of. Visitors accept or sign it on their pass, when they check themselves in, at the kiosk or at the desk, and Agoo keeps a record you can rely on.
| Document | How it's agreed to | Plans |
|---|---|---|
| Privacy notice | A tick: "I've read and accept" | Every plan, Free included |
| Site rules | A tick, or a signature if you choose | Pro and Enterprise |
| NDA | A signature | Pro and Enterprise |
| Waiver | A signature | Pro and Enterprise |
A signature is the visitor's full name, typed, and a signature drawn with their finger or mouse. Electronic signatures are valid under Ghana's Electronic Transactions Act, 2008 (Act 772). Whether one suits a particular document is for your organisation to decide; take legal advice if you're unsure.
Write and publish a document
Documents are managed in Console → Settings → Documents by Owners and Admins.
Add a document
Select Add a document and choose its kind. Give it a name visitors will recognise, such as "Volta Bank visitor NDA" or "Ward visiting rules". Your organisation has one privacy notice.
Write the wording
Write it as plain paragraphs. Start a line with ## for a heading and - for a bullet point. Your draft is saved as you type, on your computer and to your account, so a power cut loses nothing and you can finish on another computer (see Unsaved work and drafts). Visitors see nothing until you publish.
Choose who's asked, and when again
Choose whether every visitor type is asked, or only the types you pick (you can also choose a type's documents from the type's settings in Settings → Forms). The privacy notice is always asked of everyone. Then choose when people sign again.
Publish
Select Publish. The wording becomes version 1, and visitors are asked for it from now on.
Versions never change
A published version is fixed. Agoo keeps its exact wording and a SHA-256 fingerprint of it, so anyone can show which words a visitor agreed to. To change the wording, edit the draft and publish again: it becomes version 2, version 1 is archived, and everything signed against version 1 stays tied to version 1. Publishing with nothing changed is refused. Versions lists every version, newest first, with who published it and when.
To stop asking for a document, Archive it. Its versions and signatures stay; Restore it to change or ask it again.
Your privacy notice
Every organisation, on every plan, can publish a privacy notice: why you keep a record of visits, what you collect, how long you keep it and how people can ask about their data. Once it's published, visitors accept it with a tick on their pass, when they check themselves in, when they ask to visit and at the kiosk, and Agoo keeps which version they accepted and when. See Data protection for what to put in it.
When visitors sign again
| Rule | A visitor is asked again |
|---|---|
| Only when it changes (default) | When you publish a new version. Their signature of the current version covers every visit until then. |
| After a number of days | When their last signature is older than the days you set, such as 365 for once a year. |
| Every visit | On every pass. One signature covers every day of a multi-day pass. |
The privacy notice follows the same rules. Signatures count for the visitor who gave them: someone who hasn't been matched to their earlier visits yet, such as a visitor who checked themselves in, signs again, so typing someone else's phone number never skips a signature.
Where visitors sign
| Where | What's asked |
|---|---|
| Their pass, before they arrive | Every document the visit asks for. See Details and documents before the visit. |
| Self check-in from a poster | Every document their visitor type asks for, before they check in. |
| Request a visit | Your privacy notice, with the request. The rest on their pass, once the host approves. |
| The kiosk | Every document still to do, at check-in. With the Kiosk app (iPad P5, Android P6). |
| At the desk | Recorded by reception: signed on paper, or agreed at the desk. See below. |
At the desk
Open the visit in Console → Visitors and look at Documents. For a document still to do, choose:
- Signed on paper: the visitor signed a printed copy. Keep the paper as your own rules say; Agoo records that it was signed, which version, when, and who recorded it.
- Accepted at the desk: the visitor agreed in person, for example after reception read the site rules to them.
Receptionists, security staff and site admins at the visit's site can record these, and so can the visit's host. Each is on the visit's timeline and in the audit trail as recorded by them.
Signed copies
Every agreement has a copy: a PDF made from what Agoo kept when it was given, so it reads the same every time. It shows the document's wording and version, who signed or accepted it with their drawn signature, when (in the site's time zone), how (on their phone, at the desk, on paper and who recorded it), the visit, the IP address for an online signature, and the fingerprint of the wording.
- The visitor downloads it from their pass. A document they signed is also emailed to them, with the PDF attached and in your organisation's name, if their record has an email address; a ticked one (the privacy notice, ticked site rules) isn't, so regular visitors don't get an email every visit.
- Reception and anyone who can see visitors download it from the visit's Documents in the Console. So can people who handle privacy requests.
What Agoo keeps
For each agreement: the document and version, the fingerprint of its wording, when, how, and who recorded it if staff did. For a signature, also the name the visitor typed and the signature they drew. For anything accepted or signed online, also the IP address and the browser they used, as evidence of the signature.
- Agreements stay with the visit, under your retention settings for visits.
- Erasing a visitor removes the name they typed, their signature, the IP address and the browser. The record that a version was agreed to, and when, stays. See Data subject requests.
- Documents, their versions and agreements are in the full organisation export.
- Publishing, signing and recording on paper are all in the audit trail.
If your plan changes
Moving below Pro stops NDAs, waivers and site rules being asked of visitors, and new versions of them can't be published; signatures already given, and their copies, are kept. Your privacy notice works on every plan.
Details and documents before the visit
Visitors answer your questions and accept or sign your documents on their pass before they arrive, so the desk only has to say hello.
Multi-day passes and pass rules
One pass for several days with daily hours and re-entry, and rules for when and where a pass admits, with defaults per visitor type and an override at the desk.