Who can do what in EvTrack, and why a menu or button may be missing. To change a role, see Roles.
The starter roles
A new system starts with five roles. They are ordinary roles: your administrator can rename them, change what they hold, or add others.
| Role | Holds by default |
|---|---|
| Administrators | Everything, including roles, permissions and system settings |
| Power Users | Everything day to day, including adding users, the Logbook, reports and bulk approval; not roles, permissions or system settings |
| Receptionists | The Visitors Dashboard with quick check-in and check-out, visitor records and invitations, all visitors, card pools, assigning a different host |
| Hosts | Their own visitors: inviting, changing and cancelling. The default for a new account |
| Guards | The guard app at the checkpoint; no menus in the web product |
Visitors have no role: they never log in. No starter role is meant for auditors or location managers: a person who needs the Logbook and reports is given a role that holds them, and a location manager is assigned on the location (see below).
One role per person
Each user holds exactly one role, and their permissions come only from it. To give one person something more, give them a different role, or create a role for that job. A Host who also approves requests for a location is a Host who is assigned on that location’s Managers tab.
Locations
Permissions apply across the whole system. A location decides two other things:
- Who approves its requests: the users on its Managers tab, where Require Manager Approval is on - see Managers.
- Which registration link a visitor uses, since each location has its own.
Reports can cover every location. A person who sees fewer visitors than a colleague on the Visitors Dashboard and in visitor lists usually lacks Visitor Management Admin Privilege : View All Visitors, not a location.
Gates you will meet
| To | You need |
|---|---|
| See the Reports menu, and run a report | Reports: List, and Reports: Generate |
| Search the Logbook | Logbook: Search |
| See every visitor, not only your own | Visitor Management Admin Privilege : View All Visitors |
| Approve many requests at once | Registrations: Process Visitors - Bulk Approve |
| Invite on behalf of another host | Visitor Management: Assign Different Host for Visit Pass |
| Issue a Temporary Visitor Permit | Enable Temporary Visitor Permit switched on, and Visitor Management: Create Temporary Visitor Permit Invite |
| Add people to a watchlist | Watchlist Management: Watchlist Entry - Add |
| Delete a visitor | Visitor Management: Delete |
| Add users | Configuration: Permissions: Users - Add User |
A menu you may not use is hidden, not greyed out.
I cannot see something
- Is it switched on? Some features are off until your administrator turns them on (Temporary Visitor Permit, badge printing, WhatsApp, the check-out follow-up email).
- Does your role hold it? Ask a colleague in a different role whether they see it. If they do, your role lacks the permission.
- Is it someone else’s visitor? Without View All Visitors, you see only the visitors you added.
- Is it for another location? Approvals go to that location’s managers.
Then ask your administrator, saying what you tried to do and what you saw. See also By Role.
Granting access well
- Grant by role, never by exception: there are no per-person permissions, so a new need is a new or changed role.
- Keep View All Visitors to the people who need it: it opens every visitor’s personal details.
- Keep adding watchlist entries to a few trained people - see Use the Watchlist Responsibly.
- Review the roles when people change jobs, and disable accounts that are no longer used.