Buyer guide
Visitor management system requirements: the 18-point checklist.
Every visitor management demo shows the same happy path: a visitor types their name, a badge prints, the host gets a message. The differences that matter live in the requirements nobody demos. This checklist covers all 18, grouped by who in your organisation cares about each.
Security team requirements
1 to 5: what the security lead should demand
- 1. Watchlist and sanctions screening at sign-in. Names checked against OFAC, UN, and EU consolidated lists plus your internal ban list, before a badge prints, not in a nightly batch.
- 2. Silent alert on a screening hit. A match must alert security without tipping off the person standing at the kiosk.
- 3. Evacuation roll call from a phone. A live list of everyone on site, filtered by zone, with one-tap safe marking. If the vendor's answer is an emailed CSV, keep shopping.
- 4. No biometric collection by default. Face capture creates obligations under Illinois BIPA, Texas CUBI, and similar state laws. Prefer systems that work without storing biometrics at all.
- 5. Full audit trail. Every sign-in, sign-out, screening result, badge print, and record edit, timestamped and attributable, exportable for investigations.
Facilities and reception requirements
6 to 10: what makes the front desk actually faster
- 6. Pre-registration with QR fast lane. Hosts invite visitors ahead; the visitor scans a QR on arrival and the badge prints in seconds.
- 7. Badge printing that identifies at a glance. Name, photo, host, validity period, and a visual category (visitor, contractor, delivery) readable from across a room.
- 8. Multi-entrance, one record. A person signing in at Gate B must appear on the same site list as reception sign-ins. Per-entrance silos break mustering and screening.
- 9. Automatic sign-out. End-of-day auto sign-out plus optional exit scanning, so the on-site list does not accumulate ghosts.
- 10. Works during an internet outage. The kiosk must keep signing people in locally and sync later. Ask the vendor what specifically happens when the connection drops.
Compliance requirements
11 to 14: what keeps the audit painless
- 11. Contractor document verification at the gate. Insurance certificates, inductions, and permits checked for validity at sign-in, with expired documents blocking entry.
- 12. Configurable data retention. Visitor records auto-purge on your schedule per data category, satisfying GDPR-style minimisation and your legal team.
- 13. NDAs and site rules signed at the kiosk. Version-tracked documents with signature records retrievable per visitor per visit.
- 14. Per-tenant data isolation. For multi-tenant buildings and multi-site companies: one tenant's visitor data must be invisible to every other tenant, provably.
IT requirements
15 to 18: what gets the deployment approved
- 15. SSO against your identity provider. SAML or OpenID Connect for staff access, per tenant, with no shared logins at reception.
- 16. Directory sync and SCIM. Hosts provisioned and deprovisioned automatically from Entra or your IdP; leavers disappear as hosts the day they leave.
- 17. Standard hardware. Runs on off-the-shelf tablets and label printers you can buy anywhere, not proprietary kiosks with proprietary replacement cycles.
- 18. Export everything. Full data export in open formats at any time. The system you choose today should not hold your visitor history hostage in five years.
Score BeckonDesk against all 18.
Bring this checklist to a 30-minute demo and go through it point by point. We are comfortable with that conversation.