Team access manual
Give each person the access needed for their actual shift and responsibility.
Entriza uses personal accounts and scoped roles so a scanner operator does not need finance or publishing access. Clear ownership also makes changes and exceptional decisions traceable. This guide explains how to plan a team, protect sensitive roles and remove access after a person or device is no longer involved.
Map responsibilities before inviting
List who owns publication, inventory, customer cases, entrance and rewards. One person may hold more than one role, but each permission should have a current reason and an accountable owner.
What to do
- Write down operational responsibilities.
- Choose the smallest matching role.
- Name an escalation owner for each event.
Use one personal account per person
Invite each colleague through their own Entriza account. Shared logins make it hard to end one person's access, review actions or protect two-factor authentication.
What to do
- Invite the colleague's controlled email.
- Never send a shared password in chat.
- Confirm the correct person before assigning access.
Choose the correct role
Organizer administrators manage broader workspace settings. Event managers operate assigned events. Entrance scanners and reward staff need narrower station-specific capabilities. Do not grant an administrator role only to solve a scanner problem.
What to do
- Match the role to the daily task.
- Limit event and station scope where available.
- Review any request for broader access separately.
Protect sensitive work with MFA
Require a protected account for publication, claims, customer data and other sensitive actions. Staff should enroll their own authenticator and keep recovery material private. A manager must never collect everybody's one-time codes.
What to do
- Complete MFA before the first sensitive task.
- Test login before the event day.
- Keep recovery information with the account owner.
Prepare devices and shift handover
Sign in before doors open and confirm the selected event, role and scanner mode. At shift change, transfer responsibility through assigned accounts rather than handing over an unlocked personal phone.
What to do
- Verify every device and role before opening.
- Use named accounts for the next shift.
- Escalate missing access instead of sharing credentials.
Remove access promptly
When a shift, contract or collaboration ends, remove the role and sign out old sessions. This does not delete completed operational records. Review access again after the event and after every team change.
What to do
- Remove expired roles immediately.
- Sign out lost or shared devices.
- Run a final post-event access review.
Team access check
0 of 5 completed
The checklist remembers your progress in this browser.
Team access manual
Common permission questions
Why can a scanner user not edit the event?
Scanner access is intentionally limited to admission work. An event manager or organizer administrator must handle event changes.
Should I make everyone an administrator before the event?
No. Grant the narrow role needed for each task. Broad access increases risk and makes responsibility less clear.
Does signing out a device remove its workspace role?
Not necessarily. End the session and remove obsolete assigned roles. Both controls matter when access should stop.