Guest Pass FAQ
Answers to common setup and operating questions about Guest Pass.
For what the app is and how to set it up from scratch, see the
Guest Pass Overview.
Setup
What do I need to configure before Guest Pass does anything useful?
Three settings control how the app behaves out of the box. Require Host Approval is on by default, so every new visitor waits in a pending queue until someone approves them. Enable Guest Self-Registration is off by default, so only employees can register visitors. Enable Visitor Watchlist is on by default, so visitors are screened at both approval and check-in.
At minimum: enable the app in the Apps Marketplace, set up who can access it in Admin → Access Management, and have someone pre-register a test visitor to confirm the approval and notification flow works.
I turned on self-registration but guests are stuck waiting — what happened?
Self-registration opens the public portal, but visitors still enter the approval queue. They will not be approved automatically unless you also turn on Auto-Approve Visitors in Guest Pass settings. Without both settings enabled, self-registered guests sit in the Pending Approval queue until someone manually approves them.
A host can also enable auto-approval just for their own visitors in Host Preferences, even when the app-level setting is off. The host’s auto-approval still checks the watchlist and the escort-required flag — a flagged or escort-required visitor is never auto-approved.
Permissions and access
Who can approve or reject visitors?
Users whose role appears in the Can Approve Visitors setting, plus App Administrators for Guest Pass. The default is Manager, Admin, and Super Admin. You can expand or narrow this in Guest Pass → Settings.
Why can’t an employee see the Visitors tab or the dashboard?
The app has four access tiers. An employee with basic app access only sees the My Visitors tab (visitors they are hosting or created) and Host Preferences. The full Visitors list and Pending Approval require a role listed in Can Manage Visitors (default: Manager, Admin, Super Admin) or being an App Administrator. The Dashboard, Security Dashboard, Analytics, and Reports require Manager or above (or App Administrator). Digital Badges, Access Logs, Watchlist, and Settings require Admin or above (or App Administrator).
Day-to-day
How do visitors check in?
Two ways. A visitor can scan their badge QR code at an unattended kiosk or tablet to self check in. Alternatively, reception or a manager can check them in from the desktop Visitors list or the visitor’s detail page. Either path records the actual arrival time and notifies the host. Watchlist screening runs again at check-in even if the visitor was already screened at approval.
What happens when a visitor is approved?
The system generates a QR-code digital badge automatically, sends the visitor an approval email with the badge and a calendar invite (.ics file), and notifies the host. The badge is valid for 24 hours by default (configurable in settings under Badge Expiry (Hours)). The visitor’s status moves from Pending to Approved, and they can now be checked in.
Can a host auto-approve their own visitors without an admin turning it on for everyone?
Yes. Each host can enable auto-approval in their Host Preferences tab. This works independently of the app-level Auto-Approve Visitors setting. The host’s auto-approval still enforces two safety checks: visitors flagged on the watchlist are never auto-approved, and visitors marked as Escort Required are never auto-approved.
How does watchlist screening block a visitor?
The watchlist is checked at both approval and check-in. If an active, unexpired watchlist entry matches the visitor by name, email, or phone, the action is blocked. The approver or receptionist sees the name and risk level of the matching entry. At a self-service kiosk, the visitor sees only a generic “contact reception” message and is never told they were flagged. You can disable screening entirely by turning off Enable Visitor Watchlist in settings.
Can I change a visitor’s details after they are registered?
You can edit a visitor while they are in Pending, Approved, or Rejected status. Once a visitor is checked in, checked out, expired, or cancelled, the record is locked. The visitor’s host, the person who registered them, and anyone with visitor-management permissions can make edits.
When something looks wrong
“My visitor was supposed to be auto-approved but they’re stuck on Pending”
Three things prevent auto-approval even when the setting is on. First, the visitor matches an active watchlist entry. Second, the visitor is marked Escort Required. Third, the app-level Require Host Approval is on and the person registering is not the host — in that case, auto-approval is suppressed. Check the visitor’s detail page for a watchlist flag, and verify the host’s own Host Preferences if they expected their personal auto-approval to apply.
“I never got notified when my guest arrived”
Check three things. First, confirm that Notify on Visitor Arrival is on in Guest Pass settings. Second, check your Host Preferences — if you turned off arrival notifications, or if the arrival happened during your quiet hours (default 10:00 PM to 8:00 AM), the notification is suppressed. Third, verify that your business-level email notifications are enabled, since Guest Pass email alerts respect the platform email setting.
“A visitor’s badge says Expired but they haven’t arrived yet”
Two things can cause this. First, the badge validity window expired — badges are valid for 24 hours by default from the time of approval, not from expected arrival. If the visitor was approved well before their visit, the badge may expire before they arrive. Extend the Badge Expiry (Hours) in settings, or regenerate the badge from the visitor’s detail page. Second, the hourly no-show sweep marks visitors as Expired if they are still pending or approved after their expected departure has passed. Their badges are deactivated at the same time.
“A visitor I checked in hours ago still shows as on-site”
A checked-in visitor stays in that status until someone explicitly checks them out — from the visitor’s detail page, the Visitors list, or a mobile check-out action. If the visitor was expected to leave and has not been checked out, the host receives an overdue-checkout alert. These alerts repeat every 4 hours until the visitor is checked out or the visit ages out (7 days). To resolve it, check the visitor out manually.
“My visitor can’t scan their badge at the kiosk”
The badge must be active and within its validity window. If it has expired, regenerate the badge from the visitor’s detail page. If the badge was revoked, reactivate it first. Also verify the visitor is in Approved status — only approved visitors can check in. Visitors in Pending, Rejected, Expired, or Cancelled status cannot scan in.
Licensing and limits
Does Guest Pass require a licence?
No. Guest Pass is pay-as-you-go. It is available to every tenant in the Apps Marketplace with no license to purchase and no per-seat fee. You are billed per visitor check-in. Enabling it costs nothing until visitors actually start checking in.
Are there limits I should know about?
| What | Limit |
|---|---|
| Party size per registration | 1 to 50 |
| Badge access levels | 1 (Basic Access) to 10 (Emergency Access) |
| Badge expiry | Configurable; default 24 hours |
| Visitor photo size | 5 MB maximum (JPEG, PNG, GIF, or WebP) |
| Purpose of visit | Up to 1,000 characters |
| Watchlist reason | Up to 2,000 characters |
| Host default visit duration | Up to 168 hours (1 week) |
| Watchlist risk levels | Low, Medium, High, Critical |
| Notification frequency options | Immediate, Hourly, Daily |
How long are visitor records kept before they are purged?
The Data Retention (Days) setting controls this. The default shown in settings is 90 days. A nightly retention job permanently deletes visitor records — along with their badges, photos, and access logs — older than the configured window. If you need records for compliance, increase the retention period before they are purged. Deleted records cannot be recovered.
Badge and notification details
What badge formats can I give visitors?
Every approved visitor receives a QR-code digital badge. You can download the QR image as PNG or SVG, print a badge PDF, or add the pass to Apple Wallet (.pkpass). Google Wallet is not supported. Badges can be revoked, reactivated, or regenerated individually or in bulk from the Digital Badges tab.
More help
- Guest Pass Overview
- Ask AI — the assistant can register a visitor, check them in or out, and answer Guest Pass questions from these articles.