User management and user roles

Everybody who signs in to the Vizito backoffice has a role, and that role decides which menu items and actions they get. There are five built-in roles: Employee, Security guard, Receptionist, Local admin and Global admin. On Enterprise you can also compose custom roles from individual privileges. Add a user when a colleague needs backoffice access, and give them the role that matches the work they do there.

What each role can do

Permission Global Admin Local Admin Receptionist Security Guard Employee
Dashboard
View dashboard Yes Yes Yes Yes Yes
Emergency
View current visitors Yes Yes Yes Yes No
Send emergency notification Yes Yes Yes Yes No
Mark visitors as safe Yes Yes Yes Yes No
Export the list of current visitors Yes Yes Yes Yes No
Account settings
Manage account settings Yes Yes No No No
Manage other locations Yes No No No No
Reporting
View all visitor information Yes Yes Yes Yes Yes
Export the visitor list Yes Yes Yes Yes No
Host management
Add/remove hosts Yes Yes Yes No No
User management
Add/remove users Yes Yes No No No
Visitor management
Pre-register visitors Yes Yes Yes No Yes
Export the registered visitor list Yes Yes Yes No No
Sign in visitors Yes Yes Yes No No

An Employee cannot download the visitor log: the “Export” button under the “Visitors” list is hidden for them, and they consult the list on screen. Every other role can export it. “Export CSV” and “Export XLS” on the “Emergency” page are available to every role that can open it, because that list is the evacuation list. See Visitor log.

Custom roles

The five built-in roles are fixed: you cannot change what they may do. When the closest one gives somebody too much or too little, an administrator can create a custom role and tick exactly the privileges it needs, for example only the emergency list for a fire warden, or the settings without the visitor log for a facility manager. Custom roles are an Enterprise feature.

Roles have a tab of their own: “Roles”, next to “Users” under “Administration” > “Manage users”. It lists the five built-in roles, marked “Built-in”, and the custom roles of this location, with the number of privileges and users each one has. Click a built-in role to see exactly which privileges it holds. It opens read-only.

The Roles tab with the five built-in roles and one custom role

What to keep in mind when you give somebody a custom role:

  • It belongs to one location. A custom role only exists in the location it was created in, so other locations do not offer it under “Role”.
  • It comes after the built-in roles in the “Role” list of “User details”. A custom role that holds a privilege you do not have yourself is greyed out there.
  • A change applies to everybody who has the role, straight away, also to users who are signed in at that moment.
  • The own-visits filter of an Employee does not carry over. A custom role that may open the visitor log sees every visit of the location, even when it started as a copy of Employee.
  • It cannot come from Microsoft Entra ID. Users from the Azure Synchronization get one of the five built-in roles.
  • Some things stay with the Global admin. Creating locations and location groups and managing API keys cannot be put in a custom role.

Custom roles explains step by step how to create, change and delete a custom role and how to give it to a user.

Without custom roles, give the person the smaller built-in role and cover the missing part another way: an Employee who has to run the evacuation list becomes a Security guard, for instance, and an Employee who should only see their own visitors is linked to their host under “Host CN”, as described below.

What an Employee sees

An Employee gets “Dashboard”, “Reports” > “Visitors” and “General” > “Manage registered visitors”. The visitor log only shows the visits of the host linked to them under “Host CN” in their user details, so “own visits” means the visits where they are the host. Without a linked host there is nothing to filter on and the Employee sees every visit of the location, so always link the host when you give somebody this role.

An Employee cannot open “Emergency”. For a manager or team lead who has to run the evacuation list for their department, use Security guard instead: that role adds “Emergency” and shows the whole visitor log, but a Security guard cannot pre-register visitors. Give people who need the emergency list and have to pre-register visitors as well the Receptionist role. See Employees on the emergency list for putting staff on that list.

Add a user

  1. Open the Vizito backoffice and select “Administration” > “Manage users” in the left menu. The “Users” page opens on the “Users” tab, next to “Roles”.

  2. Click “Add” above the list. The “User details” window opens.

    vizito manage users

  3. Fill in “First name”, “Last name” and “Email / login”. The address under “Email / login” is the one the new user signs in with, so use an address they can receive email on. Check it before you save: once the user exists, “Email / login” can no longer be changed. “Function title” is optional.

  4. Optionally link the user to a host under “Host CN”. When that user invites a visitor, the linked host is filled in as the host by default, which saves your colleagues picking themselves from the list every time.

  5. Select a “Role”. This is the setting that decides what the user may do once they are in, so check the table above before you choose. Custom roles of this location come after the built-in ones. A role that holds privileges you do not have yourself is greyed out, so only a Global admin can make somebody Global admin.

    The open Role list with Global admin greyed out and a custom role at the end

  6. Click “Save”.

    add new user

Vizito confirms with “An email has been sent to the user that allows them to set their password.”

Change or delete a user

  1. On the “Users” tab, click the row of the user. “User details” opens with the buttons “Close”, “Save”, “Reset password” and “Delete”.
  2. Change “First name”, “Last name”, “Function title”, “Role” or “Host CN” and click “Save”.
  3. To remove the user, click “Delete” and confirm with “Yes”. They are signed out and lose their access to this location. The visits in the visitor log stay.

“Reset password” sends the user a link to choose a new password: see Login and password problems.

Three things you cannot do here:

  • Change “Email / login”. The field is greyed out for every user, yourself included, because it is the address the user signs in with and the one reset links go to. If the address is wrong or has changed, add a new user with the right address, the same “Role” and the same “Host CN”, and delete the old user once the new one can sign in. The new user gets the welcome email and sets a password of their own.
  • Change your own role or delete yourself. “Role” is greyed out and “Delete” is missing when you open yourself. Another administrator has to do it.
  • Change a user whose role you could not hand out yourself. A Local admin who opens a Global admin sees every field greyed out and only “Close”.

How the new user activates their account

The new user receives an email from Vizito with a link to their account.

confirmation email user role

The link opens “Select a password and verify your account”. They type the same password in “Password” and “Retype password”, then click “Verify account”. From then on they sign in at https://backoffice.vizito.be/ with their email address and the password they chose.

password reset

The link stays valid for 48 hours. If it has expired, if the user never received the email, or if they forget their password later, see Login and password problems. Users synchronised from Microsoft Entra ID sign in with their Microsoft account and get a different email, without a password to set: see Azure Synchronization.

What the new user sees

A user only gets the menu items their role allows, so the left menu is shorter for everybody except an admin. Among the built-in roles, “Account settings” and “Administration” only appear for a Local admin or a Global admin. A custom role shows the menu items whose privileges it holds.

The screenshot below is the backoffice as a Security guard sees it: “Dashboard”, “Emergency” and “Visitors” under “Reports”, and nothing else.

vizito dashboard