Branding
Logo
Shown in the header of every page and at the top of every email.
Browser icon
The small icon on the browser tab, and the icon a phone uses when someone adds the page to their home screen.
A square image works best. It is kept at 180 pixels with any transparency left alone.
An uploaded logo is stored on a white background, so on the navy header it sits on a white panel, as shown above.
Address and directions
Shown in the confirmation email every visitor receives, with a button that opens the address in Google Maps.
Applies to emails sent from now on. Emails already sent are not changed.
Meeting rooms
Offered when someone asks for a diary entry. Use the room's mailbox address.
Guest checklist
What visitors are asked in their confirmation email and on their visit page. Lunch is asked only when the booking is marked “Requires lunch”, and the answer is emailed to the address below with their name, the visit time and the host. Accessibility and charging answers go to the host only.
Visitors who have not answered about lunch are emailed a reminder at this time on the day before their visit. If the address is left empty, answers are kept with the booking but not sent anywhere.
Shown to visitors above the accessibility and charging questions. Leave the charging text empty to stop asking about charging.
QR codes
Visitors can hold the QR code from their email up to the reception tablet instead of typing their code. Typing the code still works.
The tablet picks this up within a minute. The first time it opens the code screen afterwards, it asks to use its camera: tap Allow. The camera is only on while a code screen is showing, and what it sees is read on the tablet itself, never sent or saved.
Emails already sent have no QR code. Their codes still work, or you can resend one from My Visitors.
Automatic printing
Passes are printed in a batch ahead of the visit.
The job is checked every 15 minutes, so printing starts at or shortly after this time.
On the pass
Wallet passes
Lets visitors add their pass to Apple Wallet or Google Wallet from their confirmation email. The pass carries the same code as the email, so the reception tablet can scan it. See SETUP-WALLET.md for how to get these details.
Apple Wallet
Off1. Make a signing request here and upload it to your Apple Developer account.
A signing request is waiting for its certificate from Apple.
2. Upload the certificate Apple gives back.
Use a .p12 file instead
For a certificate already made on a Mac, exported from Keychain Access with its private key.
Google Wallet
OffThe .json key file for the service account you invited to the issuer account.
Saved details are never shown again. Press a padlock to replace one. They are encrypted, and only administrators can change them.
Emails from
The address visitor emails are sent from. Microsoft 365 has to allow this system to send as that address, so changing it here is only half the job.
Leave a box empty to keep the value shown in it, which comes from the config file.
What to change in Microsoft 365
Someone with Exchange admin rights has to do this before you save a new address here. The commands below already use the address typed above.
- Make sure the mailbox exists. It must be a mailbox or a shared mailbox in your tenant. A shared mailbox is usually best: it needs no licence. If the address is an alias, add it to a mailbox and put that mailbox in Mailbox to send through.
-
Let this system send as it. The system may only send as mailboxes in one mail-enabled security group, set by an application access policy. Add the mailbox to that group in Exchange Online PowerShell:
If your group has a different name, use that. To find it:Add-DistributionGroupMember -Identity "Visitor System Senders" -Member visitors@example.comGet-ApplicationAccessPolicyshows the group’s address as ScopeName. -
Check it is allowed. Changes can take up to 30 minutes to apply.
AccessCheckResult: Granted means it is ready.Test-ApplicationAccessPolicy -Identity visitors@example.com -AppId your app’s client ID - Save here, then send yourself a test. Book a visitor with your own email address and check Emails in the menu. ErrorAccessDenied means step 2 has not applied yet; ErrorInvalidUser means there is no mailbox with that address.
Leave the old mailbox in the group until the new one is working. The full guide, including setting up the group from scratch, is SETUP-EMAIL.md on the server.
Emails to hosts
Each host can get a morning list of the visitors they are expecting that day, with times and rooms.
Checked every 15 minutes, so it goes at or shortly after this time. Hosts with no visitors that day get nothing.
For example, when an assistant books for a director. Nothing is sent when people book for themselves.
Technical Services notes
When someone fills in “Anything Technical Services should know” while booking, or changes it later, the note is emailed here with the visitor, time, host and who booked it.
Leave empty to email everyone with the Technical Services role instead.
Phone calls
Rings the host's extension and reads out who has arrived. People add their extension, and can turn calls off, on their My details page.
A queue, ring group or extension on the phone system, such as reception. It rings once, straight after an unanswered call, and says who the visitor is for. Leave empty for no failover.
An answerphone cannot press 1, so an unconfirmed call counts as not answered and the failover line rings. Needs the “press 1” step installed on the phone system (see the setup guide); until then, calls play as normal.
Mobile calls go out over the company phone line, so they cost the normal call rate and show the company's number. Each person also has to switch them on for themselves on My details.
Outside these hours only the arrival email is sent.
Privacy notice
What visitors are told about their details. The summary appears on the reception tablet and in confirmation emails; the full notice appears on the visitor's own visit page. Leave a box empty to show nothing there.
One or two sentences. Keep it short: people read it standing at the desk.
Blank lines separate paragraphs. Say what you hold, why, how long, and how someone asks to see or delete it. Have whoever looks after data protection check the wording.