1. Identity and eligibility: what the badge actually asserts
A credential is a claim about a person. Verification is the act of testing that claim at the moment of entry — which means the identity has to be resolved before the credential exists.
One identity per person, across editions
Duplicate registrations are the root cause of most credential disputes. Resolve returning attendees to a single identity so history, entitlements and consent travel with them instead of being re-collected and re-guessed at the desk.
Binding the credential to the holder
Bind at issue, not at print: the credential references the registration record, and the scan returns name, role and entitlements for a visual match. Photographs raise assurance where the risk justifies the extra personal data.
Data minimisation on the badge face
Configure printed fields per role. Anything not needed for a gate decision or a human greeting stays off the badge and off the lanyard that gets photographed and posted.
Fast-tracking VIPs, speakers and press without exempting them
Pre-verify these cohorts and issue in advance, then scan them at a dedicated gate. Speed comes from moving the verification earlier, never from skipping it.
2. On-site operations: verification under real conditions
Venue networks fail, coaches arrive together, and batteries die at 15:00. Design the gate for those conditions rather than for the demo.
Offline-safe validation
Credentials carrying a cryptographic signature can be validated by a scanner with no connectivity. Scans queue locally and reconcile on sync, where duplicate use and revocation conflicts are surfaced for review.
Throughput maths for the gate
Work backwards from arrivals: peak arrivals per minute divided by acceptable queue length gives the number of lanes. Sub-second scans keep the number of lanes affordable.
Capacity limits and session control
Room capacity belongs to the gate, not to a clipboard. When the limit is reached, further scans refuse with a reason that staff can explain and you can later evidence.
Reissue, revocation and lost badges
Revoke first, reissue second. Revocation must propagate to offline scanners on sync so a found badge cannot be walked to a quieter gate.
3. Exceptions and escalation: the path staff can actually follow
Exceptions are inevitable. What separates a controlled event from a chaotic one is whether the exception path was designed in advance.
Plain-language refusal reasons
Expired, revoked, wrong zone, capacity reached, already used. Each refusal carries a recommended next action so the decision leaves the barrier and reaches the resolution desk.
Permissioned overrides with a reason
Allow overrides only for roles that hold the permission, require a reason, and record them. An override that leaves no trace is indistinguishable from a breach.
Walk-ups and unregistered guests
Register, check eligibility, issue, log. The unplanned arrival gets the same chain as everyone else, in ninety seconds at the desk.
Passed-back badges and duplicate use
Flag second scans with the first scan's gate and timestamp. Most badge-sharing is caught by the pattern, not by the eye.
4. Access rules and governance: configuration over paperwork
The printed access matrix behind the desk is always one revision out of date. Put the rules where the scanner reads them.
Roles, zones and validity windows
Compose rules from role, zone and time window so a contractor is valid in the loading bay before doors and refused in the hospitality suite at all times, with no special badge stock.
Mid-event rule changes
Changes take effect on next scan for connected gates and next sync for offline scanners, always attributed to the person who made them.
Contractors, crew and clearances
Where insurance, method statements or clearances are prerequisites, record them against the credential before issue so the gate cannot admit an unevidenced worker.
5. Audit, privacy and retention: what you can prove afterwards
Verification produces evidence. Treat that evidence as a deliverable with a retention policy, not as a by-product.
Tamper-evident access trails
Hash-chained logs let you demonstrate that the record you are showing is the record that was written — grants, refusals, revocations, overrides, operators and gates included.
Consent for photographs and biometrics
Capture consent per purpose and version it. Where consent is withheld, issue without the photo and fall back to the configured alternative check.
Retention windows and deletion
Set retention per programme against your incident and contractual obligations, then delete on schedule and record that deletion happened.
Who can read the logs
Scope log access by role and audit the reads. An unaudited audit log is just a table.
A pre-event credential verification checklist
Run this two weeks out. Every unanswered line is an operational risk with a name attached.
Configuration
Roles, zones, validity windows, capacity limits and badge field sets confirmed and signed off by the client.
Hardware and connectivity
Scanner count per lane, charging plan, offline mode tested with the network physically disconnected.
People
Gate staff briefed on the five refusal reasons, the resolution desk location, and who holds override permission.
Evidence
Audit export tested end to end, retention window agreed, and the reporting recipient named before doors open.
Where each cluster is answered
- Identity & eligibility — 4 questions
- On-site operations — 4 questions
- Exceptions & escalation — 4 questions
- Access rules & governance — 3 questions
- Audit, privacy & retention — 4 questions
