Visitors
- Invitations and pre-registration
- The visitor register
- Visit types you configure
- Reception
- QR passes and kiosk check-in
VCMS is not a sign-in book with a screen. It is a register of people, the evidence that cleared them, and the events that happened to them, and every surface in the product reads from that same register.
Ordered by how long it can safely wait.
Most recent check-in first.
Most site access problems are really reconciliation problems: the sign-in sheet, the contractor spreadsheet and the induction folder describe three different populations, and nobody knows which is right.
VCMS collapses those into one object. A visitor invited by a host, a contractor who came in through onboarding, and an employee scanning the poster by the door all produce the same kind of record, attached to the same site, feeding the same roster.
That is what makes the downstream claims possible. The headcount on the dashboard, the roll a warden works through during a muster and the row in the exported report are the same data read three ways, so they cannot drift apart. And when the roster cannot be read at all, the screen says so. A headcount that is quietly wrong is more dangerous than one that is visibly missing.
In order, because the order is the product.
A host invites a visitor, an administrator invites a contractor, or somebody registers themselves from the form on the door. Every route creates one record, and a repeat registration reuses the profile rather than forking it.
An invitation names the site it is for, which scopes the document requirements and the mandatory inductions that come with it. The link is single-use and expires.
Photo ID and a selfie can be matched automatically, and anything inconclusive routes to a human reviewer rather than passing quietly. Watchlist screening is fail-closed: an unreachable source holds the visit for review, it never clears it.
The pass is a hashed token with a display code and an expiry tied to the visit window. Where a site has a geofence, the coordinates are checked on the server. A photographed QR is worth nothing off-site.
A server-sent event stream keeps the roster current. The dashboard headcount, the evacuation roll and the muster count are one number from one source, so they cannot disagree.
Activate a muster and the current on-site list becomes the roll to work through, marked off person by person. Incidents are recorded against the categories a WHS regulator recognises.
Check-out is recorded, the headcount drops, and the visit joins the history the audit log and the reports read from.
Ordered by how long it can safely wait.
Most recent check-in first.
On site now, active contractors, documents pending review and credentials expiring soon — the four the console computes, over a roster kept live by a server-sent event stream. Beside them, everything waiting on a person, ordered by how long it can safely wait: a visitor held at a gate ranks above a credential with thirty days on it. When the roster cannot be read the screen says so rather than showing a number it cannot stand behind.
Follow any of these through to the detail, or open the feature explorer and filter the lot.
Worth saying plainly, because a platform that claims everything is impossible to evaluate.
VCMS decides who is allowed through and holds the record; it does not replace your door controllers. Barrier release can be handed to a site access control system over a documented, signed bridge, and where no bridge is configured the platform says so rather than pretending it opened something.
Shifts and timesheets exist because contractor hours have to be approved against the work order that authorised them. Payroll happens somewhere else, and the export is how it gets there.
A walkthrough with your site list, your contractor mix and the compliance evidence you actually have to collect. No obligation, and no access to anybody’s live data.