How a rollout runs, and the questions that come up
No white papers and no case studies. There are none to point you at. What follows is the implementation shape, straight answers to the questions we are asked most, and a glossary so the words elsewhere on this site mean something specific.
Six phases
The first one is the one that decides how long the other five take.
- 01Shape
Your sites, your visit types, and the compliance matrix: which trades need what evidence, at which sites. This is the work that determines whether the rest goes quickly.
- 02Configure
Sites and geofences, visit types, document groups, inductions, roles and their permission sets, and the notification channels for each event.
- 03Connect
Sign-in through your identity provider, email through your relay, and any outbound integrations: webhooks, Teams, SharePoint, Power BI.
- 04Pilot
One site, live. Reception, the kiosk, one contractor cohort onboarded end to end, and one muster run as a drill before anybody needs it for real.
- 05Roll out
Site by site. Each one brings its own requirement additions without asking again contractors for evidence an earlier site already verified.
- 06Operate
Scheduled reports, expiry monitoring, and periodic reviews of who holds which role. The audit chain is there for the times you have to show your work.
Asked most often
No. Everything a visitor or contractor does happens in a browser: the invitation link, self-registration, document upload, induction and the QR pass.
There is an installable app, and a kiosk build that installs onto a lobby tablet, but they are conveniences. Nothing in the journey requires one.
The words this product uses
Site-access software is full of terms that mean slightly different things in different products. Here is what they mean in this one.
- Visit
- One person at one site between a check-in and a check-out. The unit everything else counts.
- Pre-registration
- A pass created before arrival, from an invitation or a self-registration, carrying the site and the visit window.
- Document group
- The set of documents a trade, or a particular site, asks for. Groups union rather than replace.
- Induction
- Site-specific content a contractor must pass before access. Attempts are limited and counted.
- Hold
- A visit stopped for a human decision, usually by screening. Cleared or denied by a named person.
- Muster
- An activated emergency roll call, starting from the live on-site list.
- Geofence
- A site boundary. Check-in coordinates are verified against it on the server.
- Credential
- An issued physical access pass, with its own issue, revoke and reinstate history.
- Outbox
- The queue every notification passes through, carrying its delivery state so "was this person emailed?" has an answer.
- Audit chain
- The hash-linked sequence of audit entries. Verifiable on demand; append-only is enforced.
- Site scope
- The set of sites a user may see. Enforced by the API, not by the menu.
- Tenant
- One organisation on the platform, with its own database schema in production.
Privacy, terms, and your account
The documents that govern this website, written to Australian law rather than adapted from somewhere else.
What this website collects, the one cookie it sets, and how personal information is handled inside VCMS itself.
Terms & conditionsThe terms for using this website, under Australian law. A VCMS subscription runs under a separate agreement.
Delete your accountHow to ask for your VCMS account and personal information to be deleted, and what has to be kept.
See VCMS against your own sites
A walkthrough with your site list, your contractor mix and the compliance evidence you actually have to collect. No obligation, and no access to anybody’s live data.