Digital Business Cards for Employees: A Company Setup Guide

·9 min read

To give every employee a digital business card without creating a mess, issue the cards centrally instead of asking staff to sign up for their own. Decide three things before you launch: what personal data goes on the card, who holds the account, and how a card gets taken down when someone leaves. A digital business card is really just a hosted page that a QR code, email signature or NFC card points at, so whoever controls that page controls the card — which is why company-issued pages, provisioned on work email and revocable by the company, are the version that still works in two years.

Someone has asked you to give everyone at the company a digital business card. Maybe it came out of a sustainability discussion, maybe a trade show is coming, maybe a director watched a competitor tap a phone against another phone. The task sounds small — it is a link — so it lands with HR, ops or marketing rather than with IT.

The reason it is not small is that it is a rollout, and rollouts rot quietly. Six months after a cheerful launch you can be looking at 140 cards in five formats, a dozen created on personal Gmail addresses, three departments still using last year's logo, two people who left in March still presenting themselves as staff, and nobody able to log in and fix any of it.

Almost all of that is preventable by decisions made before the first card goes out. This guide covers those decisions in the order you have to make them, then how issuing cards centrally works. If your brief is a sales team rather than the whole company, the sales-team version of this guide goes deeper on rep-level detail; this one is about company-wide rollout and policy.

What a digital business card actually is

There are two separate parts here, and confusing them is the most common reason these projects stall.

The first is the destination: a web page with the person's name, photo, role, contact details and links. The second is the delivery method: how someone gets to that page — a QR code on a badge or slide, a link in an email signature, a link in a social profile, or a plastic NFC card the other person taps their phone against.

The destination is the part that matters for governance. It goes stale, it carries your brand, and it is what you need to be able to change or remove. Delivery methods are cheap and swappable; you can reprint a QR code. But if the page behind them belongs to an individual employee, you have no controls at all.

Be clear with stakeholders about hardware, because it comes up. Biotree does not sell NFC cards or plastic smart cards, and does not do vCard contact-file exchange — the tap-to-save-my-contact trick. A Biotree page is the destination those things point at. If leadership specifically wants the tap gesture, that is a different category of product and you may want both: hardware from a card vendor, plus a centrally managed destination you can update and revoke. Decide deliberately rather than discovering it at the trade show. QR code business cards for teams covers the delivery side in more detail.

Decide what goes on the card

This is a data decision before it is a design decision, and skipping it buys you a difficult conversation later. You are about to publish personal information about your staff on the open internet.

Work through it field by field and write the answer down:

  • Name, role, department — the whole point. Agree on role-title formatting now, or you will get "Snr. Acct Mgr", "Senior Account Manager" and "Account Management Lead" from one team.
  • Work email and office phone — fine. These are company contact details.
  • Personal mobile number — default to no. If a role genuinely needs it, make it opt-in, and make sure people know it will be publicly scrapeable.
  • Headshot — fine, but opt-in in practice. Some people will not want a photo published. Have a fallback that still looks intentional.
  • Location — city or office. Never a home address, including for remote staff.
  • Personal social accounts — default to no. A company card linking to someone's personal Instagram blurs a line you will regret blurring.

Then decide the standard link set: the four to six links that appear on every card. Usually the company site, a contact or book-a-call route, the current brochure or media kit, careers, and the main company social account. Departments can request an extra, but the base set should be identical everywhere. That consistency is the whole reason to do this centrally.

Decide who owns the account

This decision quietly determines whether the project succeeds, and most companies get it wrong because the wrong answer is the easy one.

The easy answer: send everyone a link to a free tool, ask them to make a page, tell them to use the brand colours. It costs nothing, takes an afternoon, and produces an asset the company does not own. Every page belongs to an individual. The login is theirs; the email on the account may be personal. When they leave you cannot edit the page, take it down, or even see what it says. You are reduced to asking a former employee, politely, to please remove the page presenting them as your Head of Partnerships. Sometimes they do. Sometimes they keep it and quietly repoint the links at their new employer.

If employees make their own cards, the company owns nothing. That is not a risk to manage; it is the default outcome. The ownership question is worth understanding properly before you commit, because brand consistency, offboarding and IT sign-off all follow from it.

ApproachWho holds the accountWhen someone leavesRealistic fit
Employees create their own free pagesThe employeeYou ask nicely and hopeA 3-person team where everyone knows everyone. Genuinely fine at that size.
Shared company login on a consumer toolWhoever has the passwordSomeone remembers to edit itUp to about 10 pages, before password sharing and manual edits become the bottleneck
Company-issued managed pagesThe organizationRevoked centrally, same dayAny rollout where staff turn over and brand consistency is expected
NFC hardware only, no managed destinationDepends entirely on the card vendor's setupThe card still works, pointing wherever it pointedOnly alongside a destination you control

The issued model: provision, don't invite

The alternative to asking staff to sign up is issuing the card the way you issue a laptop or a mailbox. The company creates the page, the company controls it, and the employee receives one that is already correct.

That is what Biotree for Organizations does. Through the Partner API, a single call creates the whole thing: the account on the person's work email, the page, the handle that becomes handle.biotree.bio, the profile photo, the bio, the links, the social icons, the background and the style — one of classic, minimal, bold, soft, modern or warm. It publishes live immediately. No invitation email, no employee choosing a template, no half-finished drafts three weeks after launch.

Practically, the rollout becomes a spreadsheet and a script rather than a change-management campaign. You export names, roles and emails from your HR system, map them to fields, and run the provisioning. New starters get a card as part of onboarding instead of as a task they will get to eventually. The provisioning API is worth handing to whoever does your integrations.

Two points matter for how you communicate this internally. First, tenant isolation: an organization can only touch pages it created. Second, say this explicitly in your announcement — a personal Biotree page is a completely separate asset. The company page is provisioned on the work email; it is never converted from, absorbed into, or able to take down anything an employee already had personally. People will ask, and answering up front removes most of the resistance.

A live example: ProLend, a private lending business in South Africa, issues a branded page to every independent consultant, all under prolend.biotree.bio. Same structure, same standard, one place to manage it.

Getting IT and security sign-off

If your company has any kind of review process, get ahead of it. The questions are predictable, and the issued model answers most of them better than the alternative.

  • What data is involved? Only what you chose to publish above — no customer data, no contact files downloaded to visitors' devices, nothing collected from people who view the page.
  • Who can publish and change content? The organization, through an API key your team holds. Employees do not each hold a login that can be phished or reused.
  • What happens at termination? The page is revoked centrally. This is the answer security actually cares about, and the one a bring-your-own-tool approach cannot give.
  • Is it on our domain? Pages run on a subdomain of the platform, so there is no DNS or certificate work on your side.
  • What analytics exist? Basic page views and clicks. No CRM, no lead capture forms, no email sequences, no visitor profiling — which usually shortens the privacy review considerably.

Send this list to IT before they ask, together with the field list from your data decision. That often turns a three-week review into a short email thread.

Keeping departments consistent

Consistency fails in two places: appearance and content. Handle them differently.

Appearance is a provisioning problem. Pick one style and one background treatment for everyone and set it at creation time. Do not offer a choice. The moment marketing gets bold and finance gets soft, you no longer have a company standard, you have a preference survey. If you genuinely need a visual difference between customer-facing and internal roles, allow exactly two variants and document which roles get which.

Content is a maintenance problem, and it is the one that bites at scale. The brochure gets replaced, the events page moves, the pricing PDF is superseded. If each of 140 cards contains its own copy of that URL, updating it is 140 edits nobody will do.

The fix is redirect indirection. A shared button on every page points at a fixed address — biotree.bio/go/{org}/{slug} — rather than at the current destination. When the brochure moves, you repoint that one destination through the API and every member page follows instantly, with no per-page edits. Set these up on day one for anything you know will change: the media kit, the events calendar, the current campaign landing page. Updating one link across every employee page explains the pattern in more detail, and it is the single feature that keeps a rollout from decaying.

When someone leaves

Add the card to your offboarding checklist on the day you launch, not the first time you need it.

With issued pages, revocation is one action: the page is unpublished and stops resolving. Content is preserved, so if the person returns, or if the revocation was triggered in error during a notice period, re-granting restores the page as it was. That distinction matters more than it sounds — it means the safe move is to revoke promptly rather than to hesitate over whether the work is recoverable.

What revocation does not do is reach into the world and update everything that pointed at the card. Printed QR codes still exist; they simply lead nowhere now, which is the correct outcome. Email signatures on messages already sent are unchanged. Anything the departing person controls personally — their own LinkedIn profile, their own social bios — is theirs, and you should not expect a platform to change it. The full list of digital assets to take down at offboarding is worth walking through once and turning into a checklist.

One governance note: agree who triggers revocation. In most companies it should sit with the same person who disables the email account, not with the department manager, because managers are busy on the day someone leaves and it will slip.

A rollout that holds up

Do it in this order and it stays clean:

  • Pilot one department. Twenty cards, four weeks, ideally a customer-facing team who will actually use them and tell you what is missing.
  • Write the one-page policy while the pilot runs. It needs six things: which fields appear, which are opt-in, the standard link set, who approves exceptions, who triggers revocation, and who holds the API key. One page. Nobody reads two.
  • Fix the naming standard before you scale. Handle format, role-title format, photo specification. Retrofitting these across 140 pages is miserable; setting them once is free.
  • Provision company-wide from your HR export. Then wire creation into onboarding and revocation into offboarding so it maintains itself.
  • Diarise a review at six months. Roles change more than you expect. A short re-sync from the HR system catches most drift.

The broader pattern here — issued rather than invited, owned rather than borrowed — applies to more than business cards, and the complete guide to link in bio for teams and organizations covers how the same model handles member directories, franchise networks and professional bodies.

If you are ready to see what issuing cards centrally looks like for your headcount, take a look at Biotree for Organizations and provision a pilot department before you commit to a company-wide rollout.

Frequently Asked Questions

Can a company create digital business cards for all its employees?

Yes. The cleanest way is to issue them centrally rather than asking each employee to sign up for their own. With Biotree for Organizations, a company provisions a managed page for each employee on their work email through the Partner API — the account, page, handle, photo, bio, links and styling are all created in one call and published live. The organization controls and can revoke every page it created.

Who owns an employee's digital business card?

It depends entirely on who created the account. If the employee signed up themselves, they own it — the company cannot edit or remove the page after they leave. If the company issued it as a managed page on the employee's work email, the organization owns the asset and can update or revoke it centrally. This is the single most important decision in a company-wide rollout.

What happens to a digital business card when an employee leaves?

With a company-issued managed page, the organization revokes it and the page is unpublished immediately, so the link stops resolving. Content is preserved, so re-granting restores the page if the person returns or the revocation was premature. With employee-created pages, the company has no ability to take the page down at all.

Do digital business cards need IT or security approval?

Usually a light review rather than a full one, because a card is a public web page containing only information you chose to publish. The questions to prepare for are what personal data appears, who can publish changes, and how a card is removed at termination. Centrally issued pages answer all three better than employee-created accounts, since there is no per-employee login and revocation is a single controlled action.

Do digital business cards require NFC cards or special hardware?

No. An NFC card is one way to deliver the link, but a QR code, an email signature link or a link in a social profile all work without hardware. Biotree does not sell NFC cards or do vCard contact-file exchange — a Biotree page is the destination those things point at. If you specifically want the tap-to-save-contact gesture, you would buy hardware from a card vendor and still want a managed destination page you can update and revoke.

How do you keep employee digital business cards consistent across departments?

Set appearance at provisioning time rather than offering choices — one style and background for everyone, applied when the page is created. For content, put shared links such as the media kit or events page behind a fixed redirect address so the organization can repoint the destination once and every employee page follows instantly, with no per-page edits.

Create Your Free Page