A visitor arrives to a pass that already exists

Pre-registration, QR check-in, host notification and a register that keeps the history. A visitor management system built so the front desk transcribes nothing.

VCMS · Portal / Your passIllustrative
You’re all set, Mariana

Your pass is ready for check-in.

When
Tue 14 Oct · 10:00 to 12:30
Location
Harbour DepotNorth gate, visitor entrance
Host
J. Aldridge
Company
Kestrel Mechanical
Identity verified
4K2J

Show this at reception, or scan it at the entry kiosk. A copy has been emailed to you.

The pass is a hashed token with a display code and an expiry tied to the visit window plus the late grace period the site configures. The pattern above is illustrative and encodes nothing — there is no honest way to put a working pass on a public page.

An illustration of the VCMS Portal / Your pass screen, reconstructed from the application's own markup and stylesheet. Every name, organisation, site and figure shown is invented for the purpose of this illustration.
The journey

Six moments, one record

The host invites

From the console or a deep link, naming the site and the visit window. The invitation is single-use and it expires.

The visitor confirms

They fill in what your visit type asks for, and no more, because the form offers exactly the fields the server enforces.

A pass is issued

A QR pass with a display code, emailed to them, valid for the visit window plus the late grace period you configure.

They arrive

Scanned at reception, at an unattended kiosk, or from their own phone with nothing installed.

The host is told

Email and text. If nobody comes down, the wait escalates and reception can reassign the visitor to another host.

They leave

Check-out is recorded. The headcount falls and the visit joins the history the reports read from.

The front desk

What reception sees
when the doors open

The day ahead, with passes already issued — and anything screening has held surfaced as a decision rather than buried in a queue.

VCMS · ReceptionLiveIllustrative
Expected today

Fourteen arrivals. Anything held is first.

14
T. Nakamura · 10:45Held for review · screening returned an inconclusive resultDecide
M. Ferreira · 10:30Pre-registered · host J. Aldridge · pass issuedCheck in
Kestrel Mechanical · 3 people · 11:15Induction passed · documents current · cleared for the north gateOpen

A held visit is cleared or denied by a named person, and the decision stays on the record. Screening is fail-closed: a source it cannot reach returns “review”, never “clear”.

An illustration of the VCMS Reception screen, reconstructed from the application's own markup and stylesheet. Every name, organisation, site and figure shown is invented for the purpose of this illustration.
  • Expected arrivals, with the pass and the host already attached to each one.
  • A held visit ranks above everything else, because somebody is standing at a gate.
  • Clearing or denying a hold is attributed to the person who did it, on the record.
  • A waiting visitor escalates when nobody comes down, and can be reassigned outright.
  • Badges print from the same record, so the desk transcribes nothing.
Capabilities

What the visitor side does

Including the parts that only matter when something is not straightforward: a duplicate, a host who does not come down, a visitor who has to be held.

Invitations and pre-registration

Send a visitor or contractor a single-use link that already knows the site, the window and the requirements.

  • Email and SMS, per organisation, per event type.
  • A crew invitation creates one invitation and one approval per person, never one per company.
  • An invitation can be sent again from the system mailbox when the first one bounced.

The visitor register

One record per person, with the visit history attached to it.

  • Correct a name, merge nothing by accident: a duplicate is refused and the existing record is surfaced instead.
  • Removing somebody archives the profile. The visit history stays, because an evacuation roll has to be able to name a person who was on site.
  • Retention keeps running either way, and a disposed profile says so rather than showing a blank.

Visit types you configure

What a visitor is asked at the door is a tenant setting, not a code change.

  • One renderer serves reception, the kiosk and the phone, so a required field cannot be drawn in one place and enforced in another.
  • The form offers exactly the options the server enforces, and nothing else.

Reception

Check a visitor in, print a badge, tell the host, and hold anything that needs a second look.

  • The host is notified by email and by text, and again if the visitor is still waiting.
  • A waiting visitor escalates when nobody responds, and can be reassigned to another host.
  • A held visit is cleared or denied by a named person, and the decision is on the record.

QR passes and kiosk check-in

Contactless arrival at an unattended lobby, from a printed poster or a phone.

  • The kiosk route carries the site’s own check-in token; the site comes back from the server rather than being asserted by the device.
  • Installable as a kiosk app, and it keeps working through a dropped connection.
  • Passes expire with the visit window plus a configured late grace period.
Awkward cases

The bits that decide whether reception trusts it

Any product can check in a cooperative visitor at 9am. These are the moments that generate support calls.

A duplicateRefused, and the existing profile is put in front of the operator, including archived ones, rather than leaving them to search for what was just rejected. Two records for one person split their history and start a second retention clock.
A removed visitorRemoving somebody archives the profile. The visit history stays, because an evacuation roll has to be able to name a person who was on site last Tuesday.
A disposed profileRetention keeps running on an archived record. Once the personal information is disposed of, the screen says so instead of showing a blank that looks like a bug.
A host who does not come downThe visitor is marked waiting, the host is reminded, and after a configured interval it escalates to somebody who can act. Reception can reassign the host outright.
Somebody who has to be heldWatchlist screening is fail-closed: an unreachable source returns "review", never "clear". A held visit is cleared or denied by a named person and the decision is on the record.
An invitation that bouncedSend again from the system mailbox. Pending invitations only. Sending a link again once it has been accepted or revoked would email somebody a token that no longer works.

See it against your own front desk

Bring your visit types, your sites and the questions you have to ask at the door. We will show you what the configuration looks like.