Roles & Permissions

CRM / Users — Production view
HqO uses two separate role systems: Tenant Roles, which control what a user can do as an occupant within a building, and Building Admin Roles, which control what a user can manage as an administrator on behalf of a company or property. Users may have one or both types of roles, depending on their responsibilities.
Tenant Roles
Tenant Roles control access to workplace experiences and day-to-day functionality available to occupants. Assign them from CRM > Users > User Profile > Tenant Roles.
Building assignment
Before assigning tenant roles, a user must be associated with one or more buildings:
- Buildings — the buildings the user belongs to.
- Primary Building — the user's default building location. The user can also update this from their own profile.
Available tenant roles
| Category | Role | Description |
|---|---|---|
| Core Access | Building Tenant | Required to use HqO Admin and the HqO Mobile App. |
| System | Tenant Admin | Can manage tenant users and invitations, enable or disable tenant-facing apps and modules, and — where enabled at the building level — manage service requests and override resource booking notice windows. |
| Visitor Management | VIP Visitor Registration Admin | Can issue VIP visitor invitations that aren't visible to other visitor administrators. |
| Visitor Management | Visitor Registration Admin | Can add, edit, and cancel visitor invitations within their own tenant company, and manage visitor management settings such as group management, day pass approvals, and anonymous visitor visibility (if enabled). Users with a higher-permission role (landlord or internal) can view and manage visits across tenant companies. |
| Visitor Management | Visitor Registration Coordinator | Can add, edit, and cancel any visitors they invite or invite on behalf of another user. |
| Visitor Management | Visitor Registration Host | Can add, edit, and cancel their own visitors, but cannot view visits created by others. |
| Work Orders | Work Order Requester | Can submit and manage work order requests. |
| Work Orders | Work Order Admin | Can view and manage work orders submitted by employees. |
| Resource Booking | Resource Reservation Reserver | Can reserve workplace resources such as conference rooms, desks, and amenities. |
| Mobile Access | Mobile Access User | Can use mobile credentials and mobile access functionality. |
| Other | Guest User | Can use the application without a company association. |
| Custom Groups | Generic Group 1–5 | Custom user groups that can be granted access to utility buttons and configured experiences. |
⚠️ Note: The Building Tenant role is required for platform access. Users can be assigned multiple Tenant Roles, and permissions are cumulative. Some roles grant no functionality on their own and are instead used to target users in Feature Management, where access to specific features is configured.
For custom Generic Group configurations, contact your HqO account team or appsupport@hqo.co.
Building Admin Roles
Building Admin Roles grant administrative access for managing buildings, operations, users, and platform configuration. Assign them from CRM > Users > User Profile > Building > Admin Roles.
Available Building Admin Roles
| Category | Role | Description |
|---|---|---|
| Administration & Management | Super Admin | Can manage all apps, configurations, and users in HqO. |
| Administration & Management | Manager | Can manage company and module configurations. |
| User Management | User Admin | Can manage users and user authorization. |
| Experience | Programmer | Can create and manage content, surveys, events, and services. |
| Experience | Viewer | Can view audiences, users, companies, and content, but cannot make changes. |
| Experience | Notifier | Can create and manage notifications. |
| Operations | Operator | Can operate modules such as resource booking, service requests, and visitor registration, but cannot change system settings. |
| Operations | Security Admin | Can manage all visitor management functionality. |
| Operations | Building Guard | Can view visitors, manage visitor status, print badges, and notify hosts. |
| Intelligence | Intelligence | Can manage Intelligence features within their assigned scope. |
| Other | Guest User | Can use the application without a company association. |
Assigning Building Admin Roles
- Navigate to CRM > Users and open the user's profile.
- Under Admin Roles, select one or more administrative roles for the user.
- Select the buildings this user can manage — individually, or in bulk by selecting a landlord or portfolio:
- Select a Landlord to grant access to all buildings under that landlord.
- Select a Portfolio to grant access to all buildings within that portfolio.
- Select individual Buildings to grant access only to those buildings.
- Click Save.
💡 Tip: A Building Admin Role determines what a user can do; building selection determines where they can do it. A user needs both a role and at least one assigned building to manage properties in HqO.
Important notes
- A user can have multiple Tenant Roles.
- A user can have multiple Building Admin Roles.
- Building Admin permissions are scoped to the buildings assigned to that user.
- Available roles may vary based on which modules are enabled and customer-specific configuration.
- The Building Tenant role is required for access to HqO Admin and the HqO Mobile App.
Utility button permission settings
Utility buttons in App Configuration > Utility Buttons have their own Permission field:
| Setting | Who sees the button |
|---|---|
| None | All users at this building |
| Single | Users with a specific Tenant Role assigned (including Generic Groups) |
Set the permission on the utility button to match the Tenant Role assigned to the intended users.
FAQ
Can a user have multiple roles? Yes. Both Tenant Roles and Building Admin Roles are cumulative, not mutually exclusive — a user can hold several of each at once.
What's the difference between Tenant Roles and Building Admin Roles? Tenant Roles control what a user can do as an occupant within a building — booking rooms, registering visitors, submitting work orders. Building Admin Roles control what a user can manage as an administrator — configuring the platform, managing other users, overseeing operations.
Who can assign roles? Users with the User Admin Building Admin Role can manage roles and authorization for other users. Contact your HqO account team to request User Admin access.
What are Generic Groups used for? Generic Groups (1–5) give you five flexible role slots to gate any utility button for a subset of users not covered by the named roles above. Keep your own record of what each group maps to — HqO Admin doesn't display it.
How do I restrict a utility button to specific users? Set the button's Permission field in App Configuration > Utility Buttons to Single, then assign the matching Tenant Role to the intended users via CRM > Users.
Need help?
Contact your HqO account team or email appsupport@hqo.co.