One record per person, from the invitation to the check-out

VCMS is not a sign-in book with a screen. It is a register of people, the evidence that cleared them, and the events that happened to them, and every surface in the product reads from that same register.

01Harbour Depot, 09:04

VCMS · DashboardLiveIllustrative
Harbour DepotNorth gate and yard
On site now47Open reception
Active contractors128141 on the registerOpen register
Documents pending review6Awaiting verificationOpen queue
Credentials expiring soon3Renewal required within 30 daysOpen register
Needs attention

Ordered by how long it can safely wait.

3
J. Abadi is held at the gateContractor · flagged for watchlist review · held 4 minutes agoDecide
6 documents awaiting verificationSubmitted through an invite link or the contractor portalReview
3 credentials expire within 30 daysInsurance, licences and site inductions coming up for renewalOpen
Open reception
On site now

Most recent check-in first.

47
  • D. OkaforContractor · Northline Electrical08:5212 minutes ago
  • A. WhitmoreVisitor · hosted by R. Sandoval08:4024 minutes ago
  • S. BaptisteContractor · Redgum Scaffold07:151 hour ago
View all 47 in reception
An illustration of the VCMS Dashboard screen, reconstructed from the application's own markup and stylesheet. Every name, organisation, site and figure shown is invented for the purpose of this illustration.
The idea

Why one record matters

Most site access problems are really reconciliation problems: the sign-in sheet, the contractor spreadsheet and the induction folder describe three different populations, and nobody knows which is right.

VCMS collapses those into one object. A visitor invited by a host, a contractor who came in through onboarding, and an employee scanning the poster by the door all produce the same kind of record, attached to the same site, feeding the same roster.

That is what makes the downstream claims possible. The headcount on the dashboard, the roll a warden works through during a muster and the row in the exported report are the same data read three ways, so they cannot drift apart. And when the roster cannot be read at all, the screen says so. A headcount that is quietly wrong is more dangerous than one that is visibly missing.

Console screens61 routes across the operator console, kiosk, mobile and the public portal.
Capabilities28 distinct capabilities grouped into six areas.
Message templates59 branded email and SMS templates, with per organisation channel control for each event.
SurfacesOperator console, reception desk, unattended kiosk, phone browser, installable mobile app and a self-service portal for contractors.
Lifecycle

The seven steps

In order, because the order is the product.

  1. 01
    RegisterA person exists in the system before they exist on the site.

    A host invites a visitor, an administrator invites a contractor, or somebody registers themselves from the form on the door. Every route creates one record, and a repeat registration reuses the profile rather than forking it.

  2. 02
    Pre-registerThe invitation carries the site, the visit window and what is required.

    An invitation names the site it is for, which scopes the document requirements and the mandatory inductions that come with it. The link is single-use and expires.

  3. 03
    VerifyIdentity, documents and screening are settled before arrival, not at the door.

    Photo ID and a selfie can be matched automatically, and anything inconclusive routes to a human reviewer rather than passing quietly. Watchlist screening is fail-closed: an unreachable source holds the visit for review, it never clears it.

  4. 04
    ArriveA QR pass at reception, a kiosk, or a phone with no app installed.

    The pass is a hashed token with a display code and an expiry tied to the visit window. Where a site has a geofence, the coordinates are checked on the server. A photographed QR is worth nothing off-site.

  5. 05
    MonitorThe on-site list is live, and it is the same list everything else reads.

    A server-sent event stream keeps the roster current. The dashboard headcount, the evacuation roll and the muster count are one number from one source, so they cannot disagree.

  6. 06
    RespondWhen something happens, the roll is already correct.

    Activate a muster and the current on-site list becomes the roll to work through, marked off person by person. Incidents are recorded against the categories a WHS regulator recognises.

  7. 07
    Check outDeparture is an event, not an absence of one.

    Check-out is recorded, the headcount drops, and the visit joins the history the audit log and the reports read from.

Product tour

What the console looks like

VCMS · DashboardLiveIllustrative
Harbour DepotNorth gate and yard
On site now47Open reception
Active contractors128141 on the registerOpen register
Documents pending review6Awaiting verificationOpen queue
Credentials expiring soon3Renewal required within 30 daysOpen register
Needs attention

Ordered by how long it can safely wait.

3
J. Abadi is held at the gateContractor · flagged for watchlist review · held 4 minutes agoDecide
6 documents awaiting verificationSubmitted through an invite link or the contractor portalReview
3 credentials expire within 30 daysInsurance, licences and site inductions coming up for renewalOpen
Open reception
On site now

Most recent check-in first.

47
  • D. OkaforContractor · Northline Electrical08:5212 minutes ago
  • A. WhitmoreVisitor · hosted by R. Sandoval08:4024 minutes ago
  • S. BaptisteContractor · Redgum Scaffold07:151 hour ago
View all 47 in reception
An illustration of the VCMS Dashboard screen, reconstructed from the application's own markup and stylesheet. Every name, organisation, site and figure shown is invented for the purpose of this illustration.

On site now, active contractors, documents pending review and credentials expiring soon — the four the console computes, over a roster kept live by a server-sent event stream. Beside them, everything waiting on a person, ordered by how long it can safely wait: a visitor held at a gate ranks above a credential with thirty days on it. When the roster cannot be read the screen says so rather than showing a number it cannot stand behind.

Areas

What sits in each area

Follow any of these through to the detail, or open the feature explorer and filter the lot.

Visitors

  • Invitations and pre-registration
  • The visitor register
  • Visit types you configure
  • Reception
  • QR passes and kiosk check-in

Contractors

  • The contractor register
  • Guided onboarding
  • Shifts and timesheets
  • Work orders

Compliance & WHS

  • Document verification
  • Document groups
  • Inductions
  • Incident reporting
  • Site policies and acknowledgement

Site operations

  • Live on-site roster
  • Emergency muster
  • Geofenced check-in
  • Access credentials
  • Safety alerts

Insight

  • Analytics
  • Reports and exports
  • A verifiable audit log

Administration

  • Roles and permissions
  • Site-scoped access
  • Sign-in and MFA
  • Notification control
  • Retention and disposal
  • Outbound integrations
Fit

Where VCMS ends

Worth saying plainly, because a platform that claims everything is impossible to evaluate.

It is not an access-control head end.

VCMS decides who is allowed through and holds the record; it does not replace your door controllers. Barrier release can be handed to a site access control system over a documented, signed bridge, and where no bridge is configured the platform says so rather than pretending it opened something.

It is not an HR or payroll system.

Shifts and timesheets exist because contractor hours have to be approved against the work order that authorised them. Payroll happens somewhere else, and the export is how it gets there.

See VCMS against your own sites

A walkthrough with your site list, your contractor mix and the compliance evidence you actually have to collect. No obligation, and no access to anybody’s live data.