Client operating guide

School Visitor Management System

A practical guide for parents, reception/security, staff and administrators.

Configure the timezone, phone format, privacy notice, safeguarding rules and visitor-retention policy according to the school's approved requirements.

1. System overview

The VMS records who is visiting, who they are meeting, why they are visiting, the scheduled appointment, actual arrival/departure, approval history and visitor pass.

Important: Scheduled time and actual attendance time are separate. Changing an appointment never changes the actual check-in or check-out timestamp.
Before arrival

Parent or staff creates a request. Admin reviews and approves it.

At reception

Reception verifies identity, checks in the visitor and prints a pass.

At departure

Reception scans the pass or enters its number and checks the visitor out.

2. Roles and permissions

RoleMain purposeTypical access
AdminSystem owner and approverAll visitors, approvals, users, staff, departments, reports, settings and audit logs.
Reception / SecurityDaily front-desk operationToday's visitors, visitor registration, check-in/out, QR/card scan, passes and operational reports.
Staff / TeacherPerson being visitedAssigned visitor information and notifications; approval only if enabled by the school.
UserLimited internal accountDashboard and notifications, plus only permissions granted by Admin.

Every protected page checks permissions on the server. Hiding a menu item is not the security control.

3. Parent or guest booking from home

Open Book an appointment. No staff login is required.

Step 1: Enter visitor name, mobile number, email if available and visitor type.
Step 2: Select visit date, expected IN/OUT time, person to meet, department and purpose.
Step 3: Submit the request. Save the generated reference number, for example PR-20260908-ABC123.
Step 4: Use Check booking status with the reference number or mobile number.
Public appointment booking screen example
A public booking is PENDING until Admin approves it. The reference number is the parent's tracking proof.

4. Reception and security workflow

  1. Log in with the Reception account.
  2. Open Pre-Registrations and confirm the appointment is APPROVED.
  3. Verify visitor name, mobile, photo/ID according to school policy, person to meet and purpose.
  4. Open Visitors or the appointment action and select Check-in.
  5. The system records actual IN time on the server and creates a unique visitor pass.
  6. Print the pass and give it to the visitor. The visitor wears/displays it while inside.
  7. When leaving, open Scan Card / Check-out, allow camera access, scan the QR code or type the pass number.
  8. Confirm the visitor and complete checkout. The system records actual OUT time and changes status to CHECKED_OUT.
Reception checkout screen example

5. Admin approval and control

Review: Dashboard and Notifications show new public/internal requests.
Approve: Confirm date, time, person and purpose. The request becomes APPROVED.
Reject: A rejection reason is required and is visible in status tracking.
Modify: Important appointment changes move an APPROVED request to MODIFIED/PENDING for re-approval.
Audit: Approval, rejection, edits, check-in and checkout are recorded in Audit Logs.
After CHECKED_IN or CHECKED_OUT, normal appointment editing is intentionally disabled so the attendance record remains reliable.

6. Staff or teacher workflow

  1. Log in and open Dashboard or Notifications.
  2. Review visitors scheduled to meet you.
  3. When a check-in notification arrives, contact reception if the visitor should be escorted or delayed.
  4. Reception remains responsible for identity verification, pass issue and checkout.

7. Walk-in visitor use case

  1. Reception searches mobile, name or visitor ID first to avoid duplicates.
  2. If no record exists, select Register visitor and capture/upload a photo if required.
  3. Select person to meet, department and purpose.
  4. Follow school policy: obtain approval before entry when required.
  5. Check in, print the visitor pass and notify the staff member.

8. Visitor card and QR

  • The pass number is unique and identifies the visit, not sensitive ID-proof data.
  • The QR code can be scanned from the printed card at exit.
  • If camera scanning is unavailable, use a USB QR scanner or type the pass number manually.
  • Never allow a visitor to leave without checkout being completed in the system.
  • Actual IN/OUT times are server-generated and cannot be changed through appointment editing.

9. Reports, notifications and audit

Admin and permitted Reception users can review visitor history, date ranges, status, department, person visited, current visitors and checkout details. Notifications cover new requests and operational events where the recipient account exists.

Exported reports should be stored securely and shared only with authorised school personnel. Audit Logs answer who created, approved, changed or closed a visit.

10. Deployment and security checklist

  • Set the application timezone and confirm date/time display with the school.
  • Document the accepted local phone-number format and validation rules.
  • Run the system over HTTPS on the production domain; camera access requires HTTPS or localhost.
  • Use individual accounts, strong passwords and least-privilege roles. Never share the Admin login.
  • Define who may view visitor photos, ID details, reports and audit logs.
  • Keep visitor photos and personal data protected, backed up and retained only for the school's approved period.
  • Display the school's privacy/visitor notice and obtain consent where required by school policy and applicable law.
  • Test daily backups, restore procedure, emergency contact process and offline/front-desk fallback.
  • Configure email/SMS/WhatsApp providers through environment settings; do not hard-code credentials.

11. Troubleshooting

Use HTTPS or localhost, allow camera permission, close other camera applications, then use manual pass-number entry or a USB scanner.

Check the reference number/mobile, confirm the correct date, and ask Admin to review the PENDING request.

Only a currently CHECKED_IN visit can be checked out. Search the pass number and confirm the visitor was checked in first.

OVERDUE does not automatically check out the visitor. Reception/Admin must verify the visitor and perform manual checkout.

12. Go-live checklist

☐ Timezone and date/time format confirmed☐ Admin account secured
☐ Reception/security accounts created☐ Staff and departments imported
☐ Public booking URL shared with parents☐ Privacy notice approved
☐ Camera/QR tested on reception device☐ Printer and pass stock tested
☐ Backup and restore tested☐ Emergency/offline procedure documented