Skip to content
Resources

How VizPass Works, From the Gate to the Register

VizPass shows how visitor management software works in practice: gate-tablet capture with photo and OCR ID scan, WhatsApp/SMS/email OTP verification, host approval from a phone, and a printed or digital pass that tracks the visitor through to exit.

A visitor walking onto your plant floor is a security question, a safety question, and a paperwork problem all at once — and most Indian factories still answer it with a register book, a landline call to the host, and a guard who's guessing whether the person in front of him is who they say they are. VizPass replaces that guesswork with a sequence: capture, verify, approve, pass, track, exit. Here's exactly how each step works, gate to register.

Getting the Visitor to the Gate

There are three ways a visit starts, and none of them require the visitor to have done anything in advance.

  • Pre-registered by the host — an employee expecting a vendor or auditor enters the visit ahead of time, and the visitor gets a WhatsApp or email invite with a QR code and a calendar .ics attached, so it sits in their phone's calendar like any other meeting.
  • Walk-in at the gate — the guard starts the check-in directly on the gate tablet when someone arrives unannounced, which covers the far more common case of a supplier's delivery boy or a job applicant showing up cold.
  • Self-check-in — a visitor scans a QR poster stuck up at the gate and does the check-in on their own phone, which is useful when there's a queue of contractors at shift-change and one guard can't process all of them by hand.

All three land in the same record, so it doesn't matter which door a visit came through.

What Happens at the Gate

Once check-in begins — whether the guard or the visitor is doing it — the tablet takes over the parts that used to be handwritten.

The visitor's photo is captured directly with the tablet camera. An ID document — Aadhaar, PAN, driving licence, whatever the visitor is carrying — is photographed, and the name and number are read off it automatically using OCR, so nobody is typing a sixteen-digit Aadhaar number into a register by hand and getting it wrong. For someone who's visited before, the system finds their record just by mobile number, so a returning auditor or a contractor's supervisor who comes weekly isn't photographed and re-entered every time.

This is the layer that turns a paper register — legible on a good day, illegible on a busy one — into a searchable database, which is really what /features covers in full if you want the complete list of what the tablet does.

On Verification

A company can require an OTP sent to the visitor's mobile, over WhatsApp, SMS, or email, depending on how that setting is configured. It's also fine to switch OTP off entirely — some sites decide the extra step slows down a high-traffic contractor gate more than it's worth, and in that case the visit is simply captured as unverified rather than blocked. That's a deliberate trade-off a Company Admin makes, not something we make for you.

Host Approval, Without the Landline Call

The traditional gate call — guard rings an extension, extension doesn't pick up, visitor stands around — is replaced by a WhatsApp and email notification the moment someone arrives. The host approves or declines from their phone, and the gate sees the decision the moment it's made. No walking to the security cabin, no waiting on hold.

Not every visit needs this back-and-forth. Companies can mark certain visitor types — say, a regular tanker driver or an internal auditor on a recurring schedule — to enter without approval, so the host isn't pinged for someone who's already cleared to be there.

The Pass Itself

Once approved, a pass prints — A6, A7, badge, thermal, or one of six sizes total, chosen to fit whatever printer the site already has. Every pass carries a QR code and a validity time, which is the detail that makes the rest of the system self-enforcing: the pass isn't just a slip of paper, it's a clock.

Contractors, Materials and Staff Movement

A plant floor isn't only visitors in the reception-desk sense. Three other kinds of movement matter just as much, and VizPass treats them as variations on the same record rather than separate systems.

Contractors and agency staff are entered as visitors, but with a validity period tied to their contract, and an induction or licence expiry that's checked right at the gate — so a fabricator whose safety induction lapsed three weeks ago doesn't walk in on the strength of last month's clearance. This matters more in Indian plants than the software vendor's brochure usually admits: contract labour turnover is high, inductions expire, and a guard checking a laminated card from memory is not a control, it's a hope. For the safety-compliance side of contractor entry, DGFASLI's guidance on factory safety at https://dgfasli.gov.in is worth reading alongside whatever your induction process already covers.

Material and courier movement gets its own pass type. A material pass — inward or outward, returnable or not — records items, quantity, and vehicle number. Outward movement needs approval before the material is actually released, so a compressor motor going out "for repair" doesn't leave the premises on a guard's say-so alone. Couriers are logged and the recipient is told, closing the loop that a paper register never really closed — nobody in most factories can tell you, six months later, whether a particular parcel was ever actually collected.

Staff stepping out during a shift — for a bank errand, a doctor's visit, whatever — raises an out-gate pass from the employee's side, gets approved by the manager, and is stamped both out and back in at the gate. It's the same discipline applied to your own people that you'd apply to a visitor.

The Register and the Exit

Exit is deliberately simple: scanning the pass QR, or searching the visitor's name if the pass is misplaced, closes the record and stamps the exit time. There's no separate "mark as left" step for the guard to remember or forget.

This is also where the live "who's on site right now" list comes from — it's derived from open records, never typed in separately, so it can't drift out of sync with reality the way a manually maintained whiteboard count does.

  • Overstay is handled the same way: a visitor still inside past their pass's validity time is flagged automatically, and the host is chased — not just once, but until the visitor is accounted for.
  • The register itself is searchable by name, phone, company, vehicle, or date, and exportable to CSV or Excel for whoever has permission to pull that data — useful when a safety audit asks for last quarter's contractor entries and you don't want to be counting carbon-copy pages.
  • Corrections don't delete history. A mistaken entry is reversed with a reason attached, so the record stays honest about what actually happened, which matters if that register is ever produced as evidence of who was on site during an incident.

Roles, and Who Sees What

A Security Guard sees the gate — check-in, passes, exit — and nothing else. A Receptionist handles the front desk. A Company Admin configures sites, gates, hosts, and settings like the OTP switch. The host role, deliberately, can only approve or decline — nobody wants a visitor's approving manager also able to edit the register. This separation is less about hierarchy and more about not handing every login the same keys.

Setting It Up

Go-live doesn't require new hardware. A company signs up, adds its sites and gates, adds hosts with name, email and phone, and prints the QR poster for self-check-in. Any Android tablet with a camera works at the gate — there's nothing to buy beyond that, and a typical rollout is live within a week.

Two things it deliberately doesn't do: it won't open a barrier or read a number plate automatically, and it doesn't integrate with biometric turnstiles for visitor movement — those stay separate systems if you already run them. If you're weighing this against what else is on the market, /use-cases and /industries walk through how different plants configure it, and /contact is the fastest way to see the gate tablet flow live before deciding.

How VizPass Works, From the Gate to the Register FAQs

How does the host get notified when their visitor is at the gate, and can they approve entry without walking down?

The host gets an alert the moment check-in starts at the gate, whether it began as a pre-registration, a walk-in, or a self-check-in, and they can approve or deny the visit right from their phone. Once the guard or visitor enters the details on the gate tablet, that record is pushed to the host as an app notification or a WhatsApp/SMS message with the visitor's name, photo, and purpose of visit attached. The host taps approve or deny from wherever they are — their desk, a meeting room, another floor — and that decision is what unlocks the next step at the gate. Until the host responds, the visitor's status stays pending on the guard's screen, so nobody gets waved through on the guard's judgment call alone. This is what replaces the landline call to the host: instead of the guard chasing someone by phone and describing the visitor verbally, the approval happens against the actual check-in record, with the photo and details already attached. The full sequence, including how approvals connect to badge issuance and exit tracking, is laid out on the features page.

Does VizPass actually check a visitor's ID proof, or does it just take their word for who they are?

VizPass captures ID proof as part of the check-in itself, rather than relying only on a name typed into a form. Whether the guard is doing the check-in on the gate tablet or the visitor is self-checking-in from their phone via the QR poster, there's a step to photograph or upload an ID document — a driving licence, Aadhaar, or company card — which is attached to that visit's record alongside the visitor's photo. The guard can then look at the person standing in front of them and match them against what's on screen, instead of guessing. This is the verify step in the capture-verify-approve-pass-track-exit sequence, and it's what turns "a person who says they're the auditor" into a record with a face and a document tied to it. Because this involves storing personal identity documents, it's worth checking your organisation's own data handling policy against the government's guidance on personal data at https://www.meity.gov.in before deciding how long ID copies should be retained or who internally can view them.

How do we know who's still inside the factory if we need to run an emergency evacuation count?

VizPass keeps a live record of every visitor who has checked in but not yet exited, which is what you'd pull up during an evacuation headcount. Every visit follows the same capture-verify-approve-pass-track-exit sequence, and the "track" step means the system knows a visitor is on-site from the moment they're approved at the gate until they scan or check out on the way back through it. That status doesn't depend on the guard remembering who came in three hours ago or flipping back through a register book — it's just whoever hasn't been marked as exited yet. For factories specifically, this list can be cross-checked against your muster point count during a drill or a real evacuation, since it's the same underlying record used for day-to-day gate management. It doesn't replace your formal safety procedures or muster protocols — for those, the DGFASLI guidelines at https://dgfasli.gov.in are the reference point — but it does give you a real-time answer to "who's currently checked in" rather than a paper trail you'd have to reconstruct after the fact.

Can VizPass fully replace the paper visitor register we currently keep for audits?

Yes — every visit, from the moment it's captured at the gate to the moment the visitor exits, becomes one continuous digital record instead of a handwritten line in a register book. Because all three ways a visit can start — host pre-registration, guard-led walk-in, or visitor self-check-in — land in the same system, you're not maintaining separate logs for expected versus unexpected visitors. Each record carries the same fields a register book would: name, ID, host, purpose, time in, time out, plus the photo and approval status that a paper register can't capture. For an audit, that record can be searched and exported instead of flipped through page by page, and there's no gap where a guard forgot to log someone or a page went missing. What you keep and how long you keep it is still your call to make, and it's worth checking that against your own compliance requirements before you retire the register book entirely. Details on what's included at each plan tier are on the pricing page.

Will the guard get warned if someone checking in was flagged or blacklisted during an earlier visit?

Yes — because every visit is tied to the same underlying record regardless of which of the three ways it started, a person's prior visit history is visible to the guard the moment their details are entered again. If a visitor was flagged during a previous check-in, that flag shows up on the gate tablet before the approval step goes to the host, so the guard sees it while the person is still standing in front of them rather than after they've already been let onto the floor. The host still has to make the actual approve-or-deny call, since VizPass surfaces the flag rather than making the decision automatically. This matters most for the walk-in and self-check-in paths, where there's no pre-registration from a host to catch a name in advance. It's a check against the visit history already sitting in the system, not a separate database that has to be maintained by hand. How this fits alongside other gate controls for your specific site is covered on the use cases page.

How does a visitor check out at the gate, and does that update our records automatically?

A visitor checks out by scanning their QR pass again at the gate, and that single scan is what closes their visit record and marks them as exited. There's no separate exit form to fill in — the same code issued during entry, whether it came through a WhatsApp invite, a printed slip, or a self-check-in on their phone, is what the guard or the visitor scans on the way out. The moment that happens, the record's status flips from "on-site" to "exited" and the exit time is stamped against it, which is also what keeps the on-site tracking list accurate for anyone checking who's still inside. If a visitor leaves without scanning out, that visit simply stays open on the dashboard, which is itself a useful flag that something didn't follow the normal sequence. This closes the loop that starts at capture and ends at exit, with nothing left for the guard to write down by hand afterward. If you want to see this step work end-to-end on your own gate hardware, you can book a walkthrough.

Going Live: What the First Week Actually Looks Like

Rollout is deliberately unglamorous. A company signs up, adds its sites and gates, adds hosts with their name, email and phone, and prints the QR poster for the gate. There's no cabling to run, no turnstile to install — any Android tablet with a camera does the job, so a plant that already has a spare tablet in the security office can be live before the next shift change. Most sites are up within a week. The real work isn't technical; it's deciding who your hosts are, which visitor types skip approval (a regular transporter, say, versus a first-time auditor), and who on your team gets the Company Admin role to configure it, as laid out on /features.

Where Rollouts Go Wrong

The mistakes we see aren't about the software — they're about skipping the decisions above and hoping defaults will do.

  • Turning off OTP everywhere to save a step. It's a valid setting for a low-risk gate, but doing it plant-wide means every visit is captured unverified, which defeats the point on a day you actually need to prove who walked in.
  • Not training guards on roles. A Security Guard account only sees the gate — it can't run reports or reverse an entry. If your guards don't know that, they'll call the office for things the tablet already handles.
  • Leaving every visitor type on manual approval. If a host has to approve a routine daily contractor every single morning, they'll stop checking WhatsApp for it. Set that visitor type to enter without approval and save host approval for the visits that actually need a decision.
  • Ignoring the pass validity field. It's what makes the overstay flag work at all — set it casually and you'll get chased for people who were never really overstaying.

What to Watch Once You're Running

Once the gate is live, the register itself is the thing worth checking, not just the tablet. It's searchable by name, phone, company, vehicle and date, and exportable to CSV or Excel for anyone with permission — which is usually where a plant head's Monday review starts: who overstayed, whose induction or licence is close to expiry, how many material passes went out without a matching return. A mistaken entry gets reversed with a reason, never deleted, so that export stays an honest record rather than a cleaned-up one. If your safety audits already follow the recordkeeping expected under DGFASLI norms, this register is built to sit alongside that, not replace it.

Where VizPass Stops

Worth saying plainly: VizPass doesn't open barriers, doesn't read number plates, and doesn't talk to biometric turnstiles for visitors. If your gate process depends on any of those, VizPass handles the visitor and material paperwork around them, not the physical access control itself. That's a narrower job than some vendors promise, and it's the honest boundary of what a QR-and-approval system should do. For how that boundary plays out across a warehouse, a corporate office or a multi-gate plant, /industries and /use-cases go through it site by site — and if you'd rather see the gate flow on your own tablet before deciding, /contact gets you a walkthrough instead of a slide deck.

Know who is on your site

Free for 7 days. Add a gate, invite your hosts, and check your first visitor in this afternoon.