Guest Pass
1. What it is
Guest Pass manages visitors from registration through check-out. Employees pre-register guests, or guests self-register through a public link. Each approved visitor receives a QR-code digital badge, and the host is notified when their guest arrives and departs.
- Enablement: Guest Pass is pay-as-you-go. It is available in the Apps Marketplace with no license to purchase; you are billed per visitor check-in.
- What it is not: Guest Pass tracks who is on-site. It does not reserve rooms, desks, or workspaces — that is Bookings. When a booking includes external guests, Bookings hands them off to Guest Pass for check-in, badges, and screening.
2. Standing it up
- Go to Admin → Apps Marketplace, find Guest Pass, and enable it.
- Configure access: in Admin → Access Management, set which audience (departments, locations, or roles) can open the app. Access is governed by platform Access Management, not by a setting inside Guest Pass.
- Open Guest Pass → Settings and review the defaults. The three settings that most affect behaviour are Require Host Approval (on by default), Enable Guest Self-Registration (off by default), and Enable Visitor Watchlist (on by default).
- If your reception desk will use a self-service kiosk, share the public self-registration link (found under the self-registration portal). Visitors open the link, fill in their details, and pick their host.
- To confirm it works, pre-register a test visitor from Guest Pass → Visitors → Pre-Register. The visitor should appear as Pending, and the host should receive a notification.
What silently does nothing until you pair it: enabling self-registration exposes the public portal, but visitors still enter the approval queue unless you also turn on Auto-Approve Visitors. Without both, self-registered guests wait in limbo.
3. How it fits together
Visitors and their lifecycle. A visitor record captures who is coming (name, email, company, phone, purpose), who is hosting them, and the expected arrival and departure window. Every visitor moves through a status lifecycle:
Pending → Approved → Checked In → Checked Out
A visitor can also be Rejected, Cancelled, or Expired (a no-show whose expected departure has passed). Only approved visitors can be checked in. Checking in records the actual arrival time; checking out records the actual departure and deactivates the badge.
Example: Jan Kolar from Acme Corp visits on Tuesday. The host pre-registers Jan with an expected arrival of 10:00 AM and departure of 2:00 PM. Jan starts as Pending. A manager approves Jan → status moves to Approved and a QR badge is generated automatically. At 10:05 AM reception checks Jan in → Checked In and the host is notified. At 1:50 PM Jan checks out → Checked Out and the badge is deactivated.
Party size. A single registration can cover a party of up to 50 people. The party size defaults to 1.
Visitor types determine the badge colour and default access tier. There are four types: Visitor (standard, blue badge, basic access), Contractor (orange, standard access), VIP (purple, VIP access), and Escort Required (red, basic access — the visitor must be accompanied). The type is set at registration and governs the badge that is generated.
Digital badges. When a visitor is approved, the system generates a QR-code digital badge automatically. The badge carries the visitor’s name, host, company, and an expiry window (24 hours by default). Badges can be downloaded as PNG or SVG, printed as PDF, or added to Apple Wallet. Google Wallet is not supported. At a self-service kiosk, scanning the badge QR checks the visitor in. Badges can be revoked, reactivated, or regenerated individually or in bulk. Each badge has an access level from 1 (basic) to 10 (emergency), set automatically from the visitor type.
Watchlist screening. The watchlist is a register of flagged people. Each entry has a name, a risk level (Low, Medium, High, or Critical), a reason, and an optional expiry date. Visitors are matched by name, email, or phone against active watchlist entries at both approval and check-in. A match blocks the action. At a self-service kiosk, a flagged visitor sees only a generic “contact reception” message, never that they were flagged.
Automated housekeeping. Three background jobs run on schedule:
- An hourly reminder job sends overdue-checkout alerts to hosts (re-alerting every 4 hours until the visitor leaves) and one-time visit reminders to approved visitors arriving within 24 hours.
- An hourly no-show sweep expires visitors still pending or approved past their expected departure, moving them to Expired and deactivating dangling badges.
- A daily retention job purges visitor records (and their badges, photos, and access logs) older than the configured Data Retention (Days) setting.
Host notifications. The host receives notifications when a visitor is registered, arrives, departs, and when a check-out is overdue. Approved visitors also receive an email with their badge and a calendar (.ics) invite. When Require Host Approval is enabled, the host’s registration email includes one-tap approve/reject links. These links use a single-use token so the host can approve or reject without logging in.
Host preferences. Each employee can set their own preferences: auto-approve their visitors, set a default visit duration (8 hours by default), define their weekly availability schedule and quiet hours, choose notification channels (email, push, in-app, SMS), and set default access permissions for the areas their visitors can reach.
Integrations. Bookings creates a Guest Pass visitor record when a room booking includes an external guest. Appointment Scheduler links appointments to Guest Pass visitors for check-in and badge tracking.
Roles and who sees what
| Tier | Who | What they see |
|---|---|---|
| Everyone in audience | Any employee with app access | My Visitors (their own visitors), Host Preferences |
| Visitor management | Roles listed in Can Manage Visitors + App Administrators | Visitors list, Pending Approval, check-in/check-out, import |
| Reception / Manager | Manager or above + App Administrators | Dashboard (today’s visitors, metrics), Security Dashboard, Analytics, Reports |
| Security / Admin | Admin or above + App Administrators | Digital Badges, Access Logs, Watchlist, Settings, Real-Time Status |
An employee who only has basic access sees the My Visitors tab (visitors they are hosting or created) and their Host Preferences. They can pre-register visitors for themselves but cannot access the org-wide reception board.
4. Running it
Approving visitors
- Go to Guest Pass → Pending Approval.
- Review the visitor’s details, purpose, and host.
- Click Approve or Reject (with an optional rejection reason).
On approval, the system generates a digital badge and emails the visitor their badge and a calendar invite. On rejection, the visitor receives a declined notice.
Checking visitors in and out
From the Visitors list or the visitor’s detail page, click Check In (records the arrival time and notifies the host) or Check Out (records the departure time and deactivates the badge). At an unattended kiosk, visitors scan their badge QR to self check in.
Bulk pre-registration
Go to Guest Pass → Visitors → Import to upload a CSV or paste rows. Each row creates a pending visitor record. Imported visitors enter the normal approval queue.
Managing the watchlist
Go to Guest Pass → Watchlist (visible when the watchlist is enabled). Add entries with a name, risk level, reason, and optional email, phone, or expiry. Entries can be resolved, deactivated, or made permanent. Active entries are checked automatically at approval and check-in.
Running reports
Go to Guest Pass → Security & Reports → Reports. Four reports are available, each downloadable as CSV or PDF:
- Visitor Summary — visitor volume and trends
- Security Audit — security events and compliance trail
- Host Activity — host engagement and approval activity
- Badge Usage — badge issuance and scan activity
Reviewing the access log
Go to Guest Pass → Access Logs. Every visitor action (registration, approval, check-in, check-out, badge scan, watchlist match) is logged with a timestamp, the acting user, and success/failure status. Failed access attempts and watchlist matches are flagged as security events and appear in the Security Dashboard.
Using the Security Dashboard
Go to Guest Pass → Security & Reports → Security Dashboard (Manager or above). The dashboard shows total access attempts, failed attempts, watchlist matches, active and expired badges, and recent security alerts. Use this surface during an evacuation or a security incident to see who is currently on-site.
Analytics
Go to Guest Pass → Security & Reports → Analytics. Visitor volume trends, popular visit times, host activity summaries, badge usage statistics, and a compliance score are available for 7-day, 30-day, or 90-day windows.
5. Settings
Settings are at Guest Pass → Settings (Admin or App Administrator required).
| Setting | Default | What it changes |
|---|---|---|
| Enable Visitor Agent | On | Whether the built-in AI agent can register and check in visitors on behalf of employees. |
| Auto-Approve Visitors | Off | When on, newly registered visitors are approved immediately and receive a badge without manual approval. |
| Enable Guest Self-Registration | Off | When on, exposes a public registration portal where guests enter their own details and pick their host. |
| QR Code Badges | On | Whether approved visitors receive a QR-code digital badge. |
| Badge Expiry (Hours) | 24 | How many hours a digital badge remains valid after it is issued. |
| Include Visitor Photo | On | Whether the visitor’s photo is displayed on their digital badge. |
| Notify on Visitor Arrival | On | Whether the host receives a notification when their visitor checks in. |
| Notify on Visitor Departure | On | Whether the host receives a notification when their visitor checks out. |
| Require Host Approval | On | Whether new visitors must be approved before they can check in. When on, hosts receive one-tap approve/reject links in their notification email. |
| Data Retention (Days) | 90 | How long visitor records (and their badges, photos, and access logs) are kept before the nightly retention job purges them. |
| Enable Visitor Watchlist | On | Whether visitors are screened against the watchlist at approval and check-in. |
| Email Security Alerts | On | Whether security alerts (failed access, watchlist matches) are sent by email. |
| SMS for Critical Alerts | Off | Whether critical security alerts are also sent by SMS. |
| Notify Managers | On | Whether managers receive security alert notifications. |
| Can Manage Visitors | Manager, Admin, Super Admin | Which roles can view the full visitor list, pre-register visitors, import visitors, and perform check-in/check-out. |
| Can Approve Visitors | Manager, Admin, Super Admin | Which roles can approve or reject pending visitors. |
6. More help
- Guest Pass FAQ — specific setup, operating, and troubleshooting questions.
- Ask AI — the assistant can register a visitor, check them in or out, and answer questions about Guest Pass from these articles.