Each user in the system is assigned one or more roles that determine their access rights and permissions. These roles define what actions the user can perform, what data they can view or modify, and which system features they can access.
You can assign predefined roles that come with a standard set of permissions, or you can create custom roles tailored to your organization’s specific needs. Custom roles allow you to design a flexible permission structure by selecting and combining precise access rights, ensuring that users have only the level of access required to perform their responsibilities.
System user roles
There are three predefined system roles that are always available:
User
A User can access the system to create and manage reservations for personal use. Recurring bookings on desks or parking spaces are not possible with this user role.
Booking Manager
A Booking Manager has all the permissions of a User and, in addition, can manage bookings for others, including editing and deleting reservations. Recurring bookings on desks or parking spaces are not possible with this user role.
The assigned insight level determines how much booking detail is visible. For more information, please refer to the General Settings article.
Administrator
An Administrator has full access to the entire system, including all modules, user management, and system settings. This role has the highest level of permissions and unrestricted access to configuration and administrative functions. Recurring bookings on desks or parking spaces are not possible with this user role.
These roles can be manually applied within Settings > Users > Roles or synchronized via Active Directory. For more information view the Azure AD / Active Directory synchronization article or Step 5 in SCIM User Provisioning (EntraID/AzureAD) – GoBright Help Center article.
Custom User Roles
In addition to the default roles, you can create custom roles by navigating to Settings > Users > Roles.
Note: This is highly recommended because for each custom role, you can define a tailored set of permissions to match specific responsibilities within your organization.
This allows you to precisely control what users can view, create, edit, or delete across different modules and features of the system.
Per custom user role, you can configure the following permissions:
- Bookings
- Not allowed:
The user is not allowed to make or manage bookings. - Allowed to make bookings:
The user can make and manage personal bookings but not for other users. - Allow the make and manage bookings:
The user is allowed to make and manage bookings for themselves and for other users.
- Not allowed:
- Booking permissions:
- Allowed for all locations/rooms/desks
- Only allowed for specific locations/rooms/desks
- Bookings permissions: Including locations
The selected locations are visible to book - Bookings permissions: Excluding locations
The selected locations are not visible to book - Bookings permissions: Including spaces
The selected rooms/desks are visible to book - Bookings permissions: Excluding spaces
The selected rooms/desks are not visible to book
- Bookings permissions: Including locations
Check the articles below for examples and best practices on how to structure and specify locations effectively:
Limit users to make bookings in specific locations
Limit users to make bookings on specific days
- Allow access to Week planner
When enabled the user can use the Week planner feature. -
Additional option is to allow users to change their status within the Week planner. When the option to change status is disabled, users will no longer be able to manually update their status through the portal or mobile app.
Note: The status changes can still be applied externally through the API, which will override the user's current status.
Keep in mind that the permissions work in a hierarchy. So, when the parent is excluded/included, all the elements below are also excluded/included.
If you exclude any specific location or space, you should also include the location/space where the user with this role is allowed to make booking.
Rooms
- Allow to book outside opening hours
The opening hours of a room are set within the assigned room profile. - Limit in advance booking period
- Allowed to book … days in advance
The number of days the user can book in advance - Allowed to book … days in advance: Skip weekends
When enabled and 'Allowed to book … days in advance' is set to 1 or 2 days, you can choose to 'Skip weekends' to be able to book a room the days in advance accordingly. - Allowed to book … days in advance: Start time
Dictates the time at which the last day of the advanced booking window can be booked.
E.g. today is Monday. When 'allowed to book … days in advance' is set to two and 'Allowed to book … days in advance: Start time' is set to 10:00, the user can now book for Monday and Tuesday, but not yet for Wednesday. Booking for Wednesday becomes available the day before at 10:00. So, on Tuesday at 10:00.
- Allowed to book … days in advance
- Limit duration of bookings
Limit the duration of a single booking. Note that the same user can make another booking in the same day with this duration. - Limit on which days of the week bookings can be made
When enabled, bookings can be made only on the selected day(s).
Desks
- Allow recurring bookings
Allow recurring desk bookings for all or specific locations/spaces. - Allow to book outside opening hours
The opening hours of a room are set within the assigned desk profile. - Limit in advance booking period
- Allowed to book … days in advance
The number of days they may book in advance - Allowed to book … days in advance: Skip weekends
When enabled and 'Allowed to book … days in advance' is set to 1 or 2 days, you can choose to 'Skip weekends' to be able to book a desk the days in advance accordingly. This also applies for single bookings. - Allowed to book ... days in advance: Start time
Dictates the time at which the last day of the advanced booking window can be booked.
E.g. today is Monday. When 'allowed to book ... days in advance' is set to two and 'Allowed to book ... days in advance: Start time' is set to 10:00, the user can now book for Monday and Tuesday, but not yet for Wednesday. Booking for Wednesday becomes available the day before at 10:00. So on Tuesday at 10:00.
- Allowed to book … days in advance
- Limit duration of bookings
Limit the duration of a single booking. Note that the same user can make another booking in the same day with this duration. - Limit on which days of the week bookings can be made
When enabled, bookings can be made only on the selected day(s).
Parking spaces
- Allow recurring bookings
Allow recurring parking space bookings for all or specific locations/spaces. - Allow to book outside opening hours
The opening hours of a parking space are set within the assigned desk profile. - Limit in advance booking period
- Allowed to book ... days in advance
The number of days they may book in advance - Allowed to book ... days in advance: Skip weekends
When enabled and 'Allowed to book … days in advance' is set to 1 or 2 days, you can choose to 'Skip weekends' to be able to book a parking space the days in advance accordingly. This also applies for single bookings. - Allowed to book ... days in advance: Start time
Dictates the time at which the last day of the advanced booking window can be booked.
E.g. today is Monday. When 'allowed to book ... days in advance' is set to two and 'Allowed to book ... days in advance: Start time' is set to 10:00, the user can now book for Monday and Tuesday, but not yet for Wednesday. Booking for Wednesday becomes available the day before at 10:00. So on Tuesday at 10:00.
- Allowed to book ... days in advance
- Limit duration of bookings
Limit the duration of a single booking. Note that the same user can make another booking in the same day with this duration. - Limit on which days of the week bookings can be made
When enabled, bookings can be made only on the selected day(s).
- Analytics
- Not allowed
The user is not allowed to see these reports. - Allowed for all locations/rooms/desks/parking
The user is allowed to access data from all locations/rooms/desks/parking places - Only allowed for specific locations/rooms/desks/parking
- Analytics permissions: Including locations
The selected locations are visible to analyze - Analytics permissions: Excluding locations
The selected locations are not visible to analyze - Analytics permissions: Including spaces
The selected rooms/desks are visible to analyze - Analytics permissions: Excluding spaces
The selected rooms/desks are not visible to analyze
- Analytics permissions: Including locations
- Not allowed
- Access to 'No show' and 'Booking history'
- Allowed
- Not allowed
The user is not allowed to access these two reports from the Analytics section.
- Access to 'Reports'
- Allowed
- Not allowed
The user is not allowed to access these reports.
Keep in mind that the permissions work in a hierarchy. So, when the parent is excluded/included, all the elements below are also excluded/included.
If you exclude any specific location or space, you should also include the location/space where the user with this role is allowed to make booking.
- Booking approvals
- Not allowed
The user is not allowed to manage booking approvals - Allowed for all locations/rooms
The user is allowed to manage the approvals of the bookings for all locations/rooms - Only allowed for specific locations/rooms
- Booking approvals permissions: Including locations
Only allowed to manage the approvals of the selected locations - Booking approvals permissions: Excluding locations
Explicitly not allowed to manage the approvals of the selected locations - Booking approvals permissions: Including spaces
Only allowed to manage the approvals of the selected spaces - Booking approvals permissions: Excluding spaces
Explicitly not allowed to manage the approvals of the selected spaces
- Booking approvals permissions: Including locations
- Not allowed
Keep in mind that the permissions work in a hierarchy. So, when the parent is excluded/included, all the elements below are also excluded/included.
If you exclude any specific location or space, you should also include the location/space where the user with this role is allowed to make booking.
- Teams management
- View own teams - User can only see the teams they belong to.
- Manage own teams
When enabled the user can see and manage (add or remove members) their own teams - Manage all teams
When enabled the user can see and manage (add or remove members) the teams of every user
- Allowed to make booking on behalf (for rooms)
- Disabled - User is not allowed to book a room on behalf of another user
- Enabled - When this option is enabled, the user can change the organizer of the meeting, while the original creator of the meeting will still remain visible.
- Allowed to make team bookings and to book on behalf (for desks/parking)
- Disabled - User is not allowed to book a desk or parking space on behalf of another user
-
Enabled - When this option is enabled, the user can book desk or parking space to another user.
Note: 'Booking on behalf of' feature is valid only for non-integrated desks or parking spaces.
- Allow simultaneous bookings on desks
Allow users to make multiple desk bookings simultaneously - Hygienic desk mark clean
- None
The user cannot clean any desks - Can clean anonymous desks
The user can only clean desks that are anonymously booked - Can clean anonymous and own desks
The user can only clean desks that are anonymously or personally booked - Can clean all desks
The user can clean all desks
- None
Services
- Services
- Not allowed
The user is not allowed to manage the catering service providers - Allowed to manage for a single service provide
The user is allowed to manage only services from one specific provider - Allowed to manage for all service providers
The user is allowed to manage all service providers
- Not allowed
- Managing statuses
- Allowed to manage all statuses
The user can manage all statuses of the service requests - Only allowed for service order handling (statuses: open/ready/completed)
The user can manage the service requests with status Open, Ready or Completed.
- Allowed to manage all statuses
- Issues
- Not allowed
The user is not allowed to manage the issue handling - Allowed to manage for a single-issue handler
The user is allowed to manage only reported issues from one specific provider - Allowed to manage for all issue handlers
The user is allowed to manage all reported issues
- Not allowed
- Maintenance
- Not allowed
The user is not allowed to manage the maintenance mode - Allowed for a specific location
The user is allowed to manage maintenance only in specific locations - Allowed for all locations
The user is allowed to manage maintenance for all locations
- Not allowed
- Visitors
- Not allowed
The user can manage only their own visitors. The user is not allowed to manage visitors to other hosts. - Allowed to manage visitors for a single location
The user is allowed to manage visitors for other hosts in a specific location - Allowed to manage visitors for all locations
The user is allowed to manage all visitors for all locations
- Not allowed
System
- System settings
- Not allowed
The user cannot access the Settings of the GoBright portal. It's not allowed to manage system settings. - Allowed
The user can manage all system settings
- Not allowed