Prove the badge belongs to the person wearing it
Verification starts before the gate: one identity per person, resolved against the registration record, then bound to a credential that cannot be shared silently.
- How do I confirm a badge belongs to the person presenting it?
- Scanning resolves the credential to its registration record and returns the holder's name, photo (when captured), role and entitlement set on the scanner screen. Staff confirm a visual match, and every scan is written to the access log with the operator, gate and device.
- organiservenue staffsecurity
- Should credentials show photos, names or just a QR code?
- Print only what the gate decision requires. Badge fields are configured per role, so a delegate badge can carry name and organisation while a contractor badge carries a photo and zone codes only. The QR resolves the rest server-side.
- organiserprivacy
- How do we verify VIPs, speakers and press without a queue?
- Pre-verify those cohorts ahead of the event and issue credentials in advance. On the day they are handled at a fast-track gate that still scans — verification is preserved, the wait is not.
- organiservenue staff
- Can the same credential be validated at multiple gates?
- Yes. Entry, session rooms, hospitality and back-of-house each evaluate the credential against their own access rule, so one badge can be admitted at one gate and refused at another.
- organiservenue staff
Verification that keeps moving when the venue does not
Gates fail in predictable ways: no network, flat batteries, a coach of 200 arriving at once. The verification rules stay the same; only the transport changes.
- What happens if the venue Wi-Fi drops mid-session?
- Credentials carry an offline-verifiable signature, so scanners keep validating without connectivity and queue their scan records locally. When the link returns, the queue syncs and any duplicate-use conflicts are flagged for review.
- organiservenue staff
- How fast should a verification scan be?
- Target under a second per scan at the gate. Anything slower and the queue, not the software, becomes the security risk — which is why validation is a local signature check rather than a round trip.
- venue staff
- Can we enforce room capacity at the door?
- Yes. Each access gate can hold a capacity limit; once reached, further scans are refused with a clear on-screen reason and logged so you can evidence the decision afterwards.
- organiservenue staff
- Someone lost their badge — what is the safe reissue process?
- Revoke the original credential, then reissue. The revoked credential is refused at every gate from that moment, including offline scanners once they next sync, and both actions are attributed to the staff member who made them.
- venue staffsecurity
Decide the edge cases before the queue does
Most credential disputes are resolved by a documented exception path, not by argument at the barrier. Configure the path, then let staff follow it.
- What should staff do when a credential is refused?
- The scanner returns a plain-language reason — expired, revoked, wrong zone, capacity reached or already used — and the recommended next action. Staff route the holder to the resolution desk rather than making a judgement call at the gate.
- venue staffsecurity
- Can staff override a refusal?
- Only with a permission that allows it. Overrides require a reason, are attributed to the operator, and appear in the on-site exception report — so an override is a recorded decision, not a bypass.
- organisersecurity
- How do we handle walk-ups and unregistered guests?
- Register them at the desk, apply the same eligibility checks, and issue a credential with the same audit trail. Verification is not skipped because the arrival was unplanned.
- venue staff
- What if the same credential is scanned twice at two gates?
- Duplicate-use detection flags the second scan with the earlier scan's gate and timestamp so staff can investigate a passed-back badge immediately.
- venue staffsecurity
One rule set, applied identically everywhere
Zones, roles and time windows belong in configuration, not in a printed matrix taped behind the desk.
- How do we model zones, roles and time windows?
- Access rules combine role, zone and validity window. A contractor credential can be valid for the loading bay from 06:00 to 10:00 and refused everywhere else, with no separate badge stock required.
- organisersecurity
- Can access rules change during the event?
- Yes. Rule changes take effect on the next scan for connected gates and on next sync for offline scanners, and every change is recorded with who made it and when.
- organiser
- Do contractors and crew need different verification?
- They need the same verification with stricter rules: shorter validity, narrower zones and, where required, evidence of insurance or clearance recorded against the credential before it can be issued.
- organisersecurity
Evidence a reviewer will accept
After the event, the question is no longer who got in — it is what you can prove, and how little personal data you kept to prove it.
- What can we prove after the event?
- Who was granted, refused or revoked access, at which gate, under which rule and by which operator — exported as a tamper-evident bundle with an integrity verification result.
- organisersecurityprivacy
- How long should credential records be retained?
- Keep access logs for as long as your incident and contractual obligations require, then delete on schedule. Retention windows are configured per programme rather than left to habit.
- privacyorganiser
- How is consent handled for photos on credentials?
- Photo capture is a distinct, versioned consent purpose. Without it, the credential issues without a photo and gates fall back to the configured alternative check.
- privacy
- Who can read the verification logs?
- Log access is role-scoped and itself audited, so reading the access trail is a recorded event — which is what separates an audit log from a spreadsheet.
- privacysecurity
Still an open question?
Send us your access matrix and accreditation rules. We will answer against your actual gates, zones and reporting obligations rather than in the abstract.
Talk to the credentialing team