HqO

Roles & Permissions

HqO Admin Users page showing user records with name, email, company, building, and role columns

CRM / Users — Production view

HqO uses two separate role systems: Tenant Roles, which control what a user can do as an occupant within a building, and Building Admin Roles, which control what a user can manage as an administrator on behalf of a company or property. Users may have one or both types of roles, depending on their responsibilities.

Tenant Roles

Tenant Roles control access to workplace experiences and day-to-day functionality available to occupants. Assign them from CRM > Users > User Profile > Tenant Roles.

Building assignment

Before assigning tenant roles, a user must be associated with one or more buildings:

  • Buildings — the buildings the user belongs to.
  • Primary Building — the user's default building location. The user can also update this from their own profile.

Available tenant roles

CategoryRoleDescription
Core AccessBuilding TenantRequired to use HqO Admin and the HqO Mobile App.
SystemTenant AdminCan manage tenant users and invitations, enable or disable tenant-facing apps and modules, and — where enabled at the building level — manage service requests and override resource booking notice windows.
Visitor ManagementVIP Visitor Registration AdminCan issue VIP visitor invitations that aren't visible to other visitor administrators.
Visitor ManagementVisitor Registration AdminCan add, edit, and cancel visitor invitations within their own tenant company, and manage visitor management settings such as group management, day pass approvals, and anonymous visitor visibility (if enabled). Users with a higher-permission role (landlord or internal) can view and manage visits across tenant companies.
Visitor ManagementVisitor Registration CoordinatorCan add, edit, and cancel any visitors they invite or invite on behalf of another user.
Visitor ManagementVisitor Registration HostCan add, edit, and cancel their own visitors, but cannot view visits created by others.
Work OrdersWork Order RequesterCan submit and manage work order requests.
Work OrdersWork Order AdminCan view and manage work orders submitted by employees.
Resource BookingResource Reservation ReserverCan reserve workplace resources such as conference rooms, desks, and amenities.
Mobile AccessMobile Access UserCan use mobile credentials and mobile access functionality.
OtherGuest UserCan use the application without a company association.
Custom GroupsGeneric Group 1–5Custom user groups that can be granted access to utility buttons and configured experiences.

⚠️ Note: The Building Tenant role is required for platform access. Users can be assigned multiple Tenant Roles, and permissions are cumulative. Some roles grant no functionality on their own and are instead used to target users in Feature Management, where access to specific features is configured.

For custom Generic Group configurations, contact your HqO account team or appsupport@hqo.co.

Building Admin Roles

Building Admin Roles grant administrative access for managing buildings, operations, users, and platform configuration. Assign them from CRM > Users > User Profile > Building > Admin Roles.

Available Building Admin Roles

CategoryRoleDescription
Administration & ManagementSuper AdminCan manage all apps, configurations, and users in HqO.
Administration & ManagementManagerCan manage company and module configurations.
User ManagementUser AdminCan manage users and user authorization.
ExperienceProgrammerCan create and manage content, surveys, events, and services.
ExperienceViewerCan view audiences, users, companies, and content, but cannot make changes.
ExperienceNotifierCan create and manage notifications.
OperationsOperatorCan operate modules such as resource booking, service requests, and visitor registration, but cannot change system settings.
OperationsSecurity AdminCan manage all visitor management functionality.
OperationsBuilding GuardCan view visitors, manage visitor status, print badges, and notify hosts.
IntelligenceIntelligenceCan manage Intelligence features within their assigned scope.
OtherGuest UserCan use the application without a company association.

Assigning Building Admin Roles

  1. Navigate to CRM > Users and open the user's profile.
  2. Under Admin Roles, select one or more administrative roles for the user.
  3. Select the buildings this user can manage — individually, or in bulk by selecting a landlord or portfolio:
    • Select a Landlord to grant access to all buildings under that landlord.
    • Select a Portfolio to grant access to all buildings within that portfolio.
    • Select individual Buildings to grant access only to those buildings.
  4. Click Save.

💡 Tip: A Building Admin Role determines what a user can do; building selection determines where they can do it. A user needs both a role and at least one assigned building to manage properties in HqO.

Important notes

  • A user can have multiple Tenant Roles.
  • A user can have multiple Building Admin Roles.
  • Building Admin permissions are scoped to the buildings assigned to that user.
  • Available roles may vary based on which modules are enabled and customer-specific configuration.
  • The Building Tenant role is required for access to HqO Admin and the HqO Mobile App.

Utility button permission settings

Utility buttons in App Configuration > Utility Buttons have their own Permission field:

SettingWho sees the button
NoneAll users at this building
SingleUsers with a specific Tenant Role assigned (including Generic Groups)

Set the permission on the utility button to match the Tenant Role assigned to the intended users.

FAQ

Can a user have multiple roles? Yes. Both Tenant Roles and Building Admin Roles are cumulative, not mutually exclusive — a user can hold several of each at once.

What's the difference between Tenant Roles and Building Admin Roles? Tenant Roles control what a user can do as an occupant within a building — booking rooms, registering visitors, submitting work orders. Building Admin Roles control what a user can manage as an administrator — configuring the platform, managing other users, overseeing operations.

Who can assign roles? Users with the User Admin Building Admin Role can manage roles and authorization for other users. Contact your HqO account team to request User Admin access.

What are Generic Groups used for? Generic Groups (1–5) give you five flexible role slots to gate any utility button for a subset of users not covered by the named roles above. Keep your own record of what each group maps to — HqO Admin doesn't display it.

How do I restrict a utility button to specific users? Set the button's Permission field in App Configuration > Utility Buttons to Single, then assign the matching Tenant Role to the intended users via CRM > Users.

Need help?

Contact your HqO account team or email appsupport@hqo.co.

  • Users — Manage and assign roles to tenant and admin users
  • Features — Enable and manage building features
  • Buildings — Building configuration and settings

Was this page helpful?

Ask HelpHub

Ask me anything about HqO

I can help you find information in the documentation.