Creating Users, Groups and Credentials in Brivo Access
Brivo administrators use people, credentials, groups, schedules and door permissions together. A user record identifies the person; a credential gives that person a way to authenticate; and group or access assignments determine where and when the credential works.
The exact labels and screen locations can change as Brivo updates its cloud interface. The workflow below focuses on the security decisions that remain important regardless of minor interface changes.
Before creating a user
Confirm the person’s identity, job role, required doors, approved schedule and expiration date before assigning access. Avoid copying broad permissions from another employee without reviewing whether they are appropriate.
For contractors, vendors or temporary staff, document the sponsoring manager and the date access should end. Temporary access should expire automatically whenever possible.
Create the person record
- Sign in with an administrator account authorized for the correct Brivo account and site.
- Open the people or users area and create a new person.
- Enter the person’s name and the contact information required by your organization.
- Add an employee number or other internal identifier if it helps prevent duplicate records.
- Set an expiration date when the access is temporary.
- Save the record before assigning credentials and permissions.
Use consistent names and identifiers. Duplicate or incomplete records make audits and offboarding more difficult.
Assign the credential
Depending on the system and subscription, a person may use a card, fob, PIN, mobile credential or another supported credential. Enter or enroll the credential according to the reader technology and account configuration.
Mobile credentials normally require a valid email address or mobile invitation and may consume a licensed credential. Confirm that the recipient completes enrollment before relying on the phone for entry.
When dual-credential readers are installed, the organization can issue the credential type that best fits the user while maintaining a path for future migration.
Use groups for repeatable permissions
Groups simplify administration by assigning the same access rules to people with similar responsibilities. Useful examples include employees, managers, cleaning crews, contractors, pharmacy staff or after-hours personnel.
A well-designed group should answer two questions:
- Where? Which doors or sites can group members enter?
- When? Which schedule, holidays and date limits apply?
Avoid groups such as “All Doors, All Times” unless the business has formally approved that level of access. Apply the least privilege necessary for the person’s job.
Build schedules and holiday rules
Schedules define when access permissions are valid. Review opening hours, shift changes, weekends, holidays and after-hours exceptions before assigning the schedule to a group.
Holiday rules should be reviewed before each calendar year. A schedule that works during a normal week may unintentionally grant or deny access on a holiday if the exception is not configured.
Test the complete user experience
After creating the user:
- Present the credential at an authorized reader.
- Confirm access is granted and the correct person appears in event history.
- Test a door or time period that should be denied when practical.
- Confirm the door closes and latches after entry.
- Check door-position and request-to-exit events.
- Verify door-held-open and forced-door alerts if they are part of the design.
A successful reader beep alone does not prove the entire opening works. The lock, latch, closer and door monitoring must also be tested.
Offboarding and lost credentials
Disable access immediately when a credential is lost or a person leaves the organization. Do not simply remove the person from a commonly used group while leaving another credential or permission active.
Offboarding should include:
- Suspending or deleting active credentials.
- Removing mobile passes and PINs.
- Reviewing direct door assignments and group memberships.
- Removing administrator privileges.
- Documenting the date and person who completed the change.
Review administrators and access regularly
Periodically review active users, unused credentials, expired contractors, group permissions and administrator accounts. Access control stays accurate only when the organization maintains its data as employees and responsibilities change.
Brivo subscription and support
Brivo requires an active subscription for cloud management and licensed services. Avenger Security can help establish or transfer a subscription, configure groups and schedules, train administrators and troubleshoot doors or controllers.
Read our Brivo cloud access control guide or visit our access control services page for project and support information.