Skip to main content

Teamgo Security Best Practices Guide

Security tips for Administrators and Users of Teamgo to keep your account safe and secure.

Security Best Practices When Setting Up Teamgo

A practical setup guide for administrators and workplace users

This guide outlines recommended security practices when deploying Teamgo Visitor Management across your workplace. Following these steps helps ensure your system supports strong privacy protection, controlled access, and compliance with organisational policies such as ISO 27001-aligned security expectations and workplace safety obligations.

These recommendations apply whether you are deploying:

  • iPad or Android kiosk sign-in points

  • QR code contactless check-in

  • visitor pre-registration workflows

  • employee attendance

  • contractor sign-ins

  • badge printing stations

  • emergency evacuation tools


Administrator Security Setup Guide

Administrators are responsible for configuring Teamgo securely before rollout to staff and visitors.

1. Enable Single Sign-On (SSO) where available

Where possible, connect Teamgo to your identity provider:

Recommended providers:

  • Microsoft Entra ID (Azure AD)

  • Okta

  • Google Workspace (where applicable)

Benefits:

  • βœ… Centralised authentication

  • βœ… Automatic password policy enforcement

  • βœ… Faster user provisioning and removal

  • βœ… Reduced credential risk

2. Require Multi-Factor Authentication (MFA)

Administrator accounts should always use MFA.

This prevents access if:

  • passwords are compromised

  • devices are lost

  • accounts are targeted externally

Best practice:

  • πŸ”’ Enforce MFA through your identity provider rather than individually per application

3. Apply Role-Based Access Control (RBAC)

Only assign permissions necessary for each user’s role.

Typical access structure:

Role

Recommended access

Global Admin

Limited to system owners

Location Admin

Site-level configuration

Reception / Front Desk

Visitor management only

Hosts

Visitor approvals only

Avoid granting full admin access broadly.

4. Implement Joiner / Mover / Leaver access processes

Access should follow your organisation’s lifecycle controls:

Joiner

  • access approved before activation

Mover

  • permissions updated when roles change

Leaver

  • access removed immediately on departure

Tip πŸ’‘ If using SSO provisioning, this can be automated.

5. Configure visitor data retention settings

Teamgo allows administrators to define automatic record retention periods.

Recommended approach:

Organisation Type

Suggested retention

Corporate office

30–90 days

Schools / childcare

per regulatory requirement

Healthcare

policy-aligned

Government / regulated

compliance-driven

Benefits:

  • βœ… Privacy compliance

  • βœ… Reduced data exposure risk

  • βœ… Cleaner reporting datasets

6. Configure privacy collection notices

Administrators can customise consent wording displayed during sign-in.

Recommended inclusions:

  • why visitor data is collected

  • how it is used

  • who it may be shared with

  • retention period

  • contact details for privacy enquiries

This supports compliance with:

  • Australian Privacy Act

  • GDPR (where applicable)

  • workplace safety obligations

7. Secure kiosk devices (iPads / Android tablets)

Kiosks should operate in controlled device mode.

Recommended configuration:

  • βœ… Enable Guided Access (iPad)

  • βœ… Enable Android kiosk mode

  • βœ… Disable app switching

  • βœ… Disable browser access

  • βœ… Prevent system setting changes

Optional advanced protection:

πŸ” Deploy via Mobile Device Management (MDM) Examples:

  • Microsoft Intune

  • Jamf

  • Kandji

  • Workspace ONE

8. Secure badge printing infrastructure

If using visitor badge printing:

Ensure printers:

  • sit on secure internal networks

  • are not publicly accessible

  • are assigned static IP addresses where possible

  • are restricted to kiosk network segments

This prevents unauthorised print access.

9. Restrict location visibility

Multi-site organisations should apply location-level permissions. Example:

Sydney staff
β†’ see Sydney records only

Melbourne staff
β†’ see Melbourne records only Benefits:

  • βœ… Privacy separation

  • βœ… Reduced accidental exposure

  • βœ… Cleaner reporting access

10. Review administrator permissions regularly

Schedule periodic reviews:

Recommended frequency:
πŸ“… Every 3–6 months Check:

  • unused accounts

  • excessive privileges

  • duplicate administrators

11. Keep kiosk apps updated

Always run the latest:

  • Teamgo kiosk app version

  • iPadOS / Android OS updates

Benefits:

  • βœ… security patches

  • βœ… improved QR scanning

  • βœ… better badge printing reliability

  • βœ… compatibility improvements


Security Best Practices for Staff and Hosts

Everyday users play an important role in maintaining workplace security.

1. Use secure authentication practices

If not using SSO:

  • βœ… Use strong passwords

  • βœ… Do not reuse passwords across systems

2. Never share login credentials

Each Teamgo user must have an individual account. Shared logins:

  • ❌ reduce accountability

  • ❌ weaken audit trails

  • ❌ increase risk exposure

3. Confirm visitor legitimacy before approving entry

Always verify:

  • expected visitor identity

  • purpose of visit

  • correct meeting host

Especially important for:

  • 🏒 government environments

  • 🏫 education settings

  • πŸ₯ healthcare locations

4. Protect visitor personal information

Access only information required for your role. Do not:

  • ❌ export records unnecessarily

  • ❌ share screenshots externally

  • ❌ retain visitor data offline

5. Lock unattended computers

When stepping away:

  • πŸ”’ lock workstation screens immediately

This prevents dashboard access by unauthorised persons.

6. Keep contact details updated

Ensure your:

  • email address

  • phone number

  • notification preferences

remain current for emergency alerts and visitor approvals.

7. Report unusual activity promptly

Notify administrators if you notice:

  • ⚠️ unexpected visitor approvals

  • ⚠️ incorrect badge information

  • ⚠️ unknown administrators

  • ⚠️ kiosk behaviour changes

Early reporting helps prevent incidents.


Advanced Security Controls (Recommended for Regulated Environments)

Organisations with higher compliance requirements should consider:

  • βœ… SSO enforcement

  • βœ… automated provisioning (SCIM where available)

  • βœ… scheduled permission reviews

  • βœ… watch lists / blocked visitor alerts

  • βœ… restricted export permissions

  • βœ… device fleet management via MDM

  • βœ… privacy-region hosting alignment (AU / UK / US)

  • βœ… periodic security configuration reviews

These controls are commonly used by:

  • government agencies

  • education providers

  • healthcare organisations

  • customs-controlled sites

  • infrastructure operators


Printable Security Setup Checklist

You can copy or print this checklist for deployment teams.


Teamgo Security Deployment Checklist

Identity & Access

☐ SSO configured
☐ MFA enabled for administrators
☐ Role-based permissions assigned
☐ Joiner / mover / leaver process defined
☐ Administrator access reviewed


Privacy & Data Protection

☐ Data retention policy configured
☐ Privacy collection notice customised
☐ Export permissions reviewed
☐ Location-level access separation configured


Kiosk Device Security

☐ Guided Access / kiosk mode enabled
☐ OS updates installed
☐ App updated to latest version
☐ Device physically secured
☐ MDM applied (if available)


Badge Printing Security

☐ Printer connected to secure network
☐ Printer not internet-exposed
☐ Static IP configured (optional best practice)


Operational Controls

☐ Staff accounts individually assigned
☐ Staff trained on visitor approval process
☐ Emergency notification contacts verified
☐ Periodic admin review scheduled


Ongoing Maintenance

☐ Quarterly permission review scheduled
☐ Device updates scheduled
☐ App updates monitored
☐ Retention policy validated annually


Get in touch with Teamgo if you would like to discuss this guide or require additional support and assistance.

Did this answer your question?