> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getray.info/llms.txt
> Use this file to discover all available pages before exploring further.

# Visitor whitelist and blacklist

> In the RAY admin portal, visitors are whitelisted or blacklisted by their email, phone number or identification (ID), not by name. A whitelisted or blacklisted value applies to every existing and future visitor using it, shows as Access Status, and drives the Auto approve whitelisted and Auto deny blacklisted rules.

## Summary

The RAY admin portal can whitelist (السماح) or blacklist (الحظر) visitors. Whitelisting and
blacklisting are done **by email, phone number or identification (ID)**, not by the visitor's
name. Once a value is whitelisted or blacklisted, it applies to every existing and future visitor who
uses that same email, phone number or ID, whichever host registers them. Blacklisted visitors are
flagged when staff approve a visit, and the visit settings can approve whitelisted visitors and deny
blacklisted visitors automatically.

## What a visitor is whitelisted or blacklisted by

A visitor is whitelisted or blacklisted through one of three values entered for the visitor:

| Value | Example of the effect |
| - | - |
| **Email** | Blacklisting an email blacklists every visitor registered with that email. |
| **Phone Number** | Blacklisting a phone number blacklists every visitor registered with that phone number. |
| **Identification** | Blacklisting an ID blacklists every visitor registered with that ID. |

The visitor's name is never used. A person registered again with a different email, phone number and
ID is not matched. To block a person reliably, blacklist the values that are collected for every
visitor, which are the fields set to **Required** in **Access → Visit Settings → Visitors**.

## Where to whitelist or blacklist a visitor

Whitelist and blacklist buttons (shield icons, with the tooltips **Whitelist** and **Blacklist**)
appear next to a visitor's **Email**, **Phone Number** and **Identification** in:

* **Access → Visit Records**, **Visitors** tab.
* The **Visitors** and **Excluded Visitors** tabs of a visit's detail page.

## When the whitelist and blacklist buttons are shown

The buttons depend on how the field is set in **Access → Visit Settings → Visitors**:

| Field setting | What staff can do on that value |
| - | - |
| **Required** | Whitelist, blacklist, or remove an existing status. |
| **Visible** | Only remove an existing whitelisted or blacklisted status. A new status cannot be added. |
| **Hidden** | Nothing; the field is not shown. |

The **Visitors** tab of Visit Settings shows the same rule in a **Whitelist and blacklist fields**
message.

## How to blacklist a visitor

1. Open **Access → Visit Records**, **Visitors** tab, or open a visit's detail page.
2. Find the visitor and click the **Blacklist** button next to their **Email**, **Phone Number** or
   **Identification**.
3. Read the confirmation, for example "This email will be blacklisted for all existing and future
   visitors using it.", and click **Blacklist**.

The visitor's **Access Status** becomes **Blacklisted**.

## How to whitelist a visitor

1. Open **Access → Visit Records**, **Visitors** tab, or open a visit's detail page.
2. Click the **Whitelist** button next to the visitor's **Email**, **Phone Number** or
   **Identification**.

The value is whitelisted straight away, without a confirmation, and **Access Status** becomes
**Whitelisted**.

## How to remove a visitor from the whitelist or blacklist

Click the highlighted **Whitelist** or **Blacklist** button again on the same **Email**, **Phone
Number** or **Identification**. The status is removed for every visitor using that value. Removing is
also possible when the field is set to **Visible**.

## How the whitelist and blacklist affect visit approval

* **Access Status** shows **Whitelisted** or **Blacklisted** for each visitor in Visit Records and on
  the visit's detail page.
* Approving a visit with a blacklisted visitor asks for confirmation that blacklisted visitors are
  included.
* On a pending visit with several visitors, **Approve excluding blacklisted** approves the visit
  without the blacklisted visitors, who move to **Excluded Visitors**. See
  [Visit details](/access/visit-details).
* In **Access → Visit Settings → General Settings**, **Auto approve whitelisted** approves a visit
  automatically if all its visitors are whitelisted, and **Auto deny blacklisted** denies it
  automatically if one visitor is blacklisted. Both rules require **Email**, **Phone Number** or
  **Identification** to be set to **Required**. See [Visit Settings](/access/visit-settings).

## Common questions about the visitor whitelist and blacklist

### Can I blacklist a visitor by name?

No. Visitors are blacklisted by email, phone number or ID only. Blacklist the value next to the
visitor's **Email**, **Phone Number** or **Identification**.

### Does blacklisting affect other hosts' visitors?

Yes. A blacklisted email, phone number or ID applies to all existing and future visitors using it,
whichever tenant registers them.

### Why are there no blacklist buttons next to a visitor's email?

**Email** is not set to **Required** in **Access → Visit Settings → Visitors**. With **Visible**,
an existing status can only be removed; with **Hidden**, the email is not shown.

### Why is Auto deny blacklisted showing a "Requires Email, Phone Number, or Identification" message?

None of those visitor fields is set to **Required**. Click **Go to Visitor Settings** and set at
least one of them to **Required**.

## Related pages

* [Visit Records](/access/visit-records): the Visitors tab and its Access Status column.
* [Visit details](/access/visit-details): approving with or without blacklisted visitors.
* [Visit Settings](/access/visit-settings): visitor fields and the auto approve and auto deny rules.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.