Visitor and Vendor Tracking
Back to Data Center Management · Badge or Biometric Access · Access Logging · Cage or Rack-Level Restriction · Service Offerings
This is external access escorted and logged, not left on the honour system. It matters because the visitor is the gap in everything else on this list: they have no credential, so the access list does not cover them, the door log does not name them, and the review in access logging has nothing to review.
1. A Visit Has a Shape, and It Must Close
Treat a visit as a short-lived grant of access with a defined lifecycle, exactly as you would a temporary account. The illustration above walks it through, and the final step is the one that is routinely skipped:
- Pre-authorised — who approved it, for what purpose, on what date, and which areas.
- Identity verified on arrival, against photo identification, not against the name on the calendar entry. Anyone can state a name that is expected.
- Credential issued, scoped to the areas needed and expiring at the end of the day by itself.
- Escorted, if the area requires it.
- Signed out, with the time.
- Credential returned and deactivated.
An unclosed visit is not an administrative untidiness. It means you do not know whether that person is still in the building, and — if the badge was not recovered — that a working credential for your data centre is somewhere you cannot see. The fix is the same as for contractors: expiry by default, so an unreturned badge stops working at midnight whether anyone chased it or not.
2. Escorted Means Accompanied, Continuously
"Escorted" quietly degrades into "let in by someone who then went back to their desk". If the area needs an escort, the policy has to say what that means and who is responsible.
- Named escort per visit, recorded, and accountable for the visitor the whole time.
- A stated limit on how many visitors one person can escort at once.
- A handover rule, because shifts end and lunches happen.
- A clear statement of which areas can be entered unescorted by a recurring vendor, if any — decided deliberately rather than by habit.
3. Vendors Are the Sharper Case
Visitors come once. Vendors come repeatedly, know the building, are often trusted by sight, and arrive with tools and a legitimate reason to touch equipment. That combination means the controls slacken for exactly the population with the most physical capability.
- Standing vendor access is staff access. If an engineer from a maintenance company holds a credential that works without an escort, that person belongs in the same joiners-movers-leavers process as your own people — including removal when they change employer, which their company will not tell you about unless the contract says they must.
- Per-visit authorisation tied to work. A visit should reference a ticket, a change record or a maintenance schedule. A vendor arriving with no corresponding work is the single most useful exception to notice. See scheduled maintenance.
- The contract carries the assurances you cannot verify yourself: background checks on their staff, confidentiality, notification when their personnel change, and your right to audit. This is part of vendor management rather than of the door.
- Remote hands in a colocation facility is vendor access by another name, and the provider's own staff have physical access to your equipment by design. Scope what they may touch and require that it be logged — see cage or rack-level restriction.
4. Record What They Did, Not Only That They Came
A visitor book that captures a name and a time answers who was present. It does not answer the question that actually gets asked after something breaks, which is what they touched.
- The purpose of the visit, and the ticket or change it belongs to.
- Which equipment was worked on, recorded against the asset tag rather than by description.
- What was taken in and what was taken out. Hardware leaving the building is the case where this matters most, and a disk removed for warranty replacement is a data handling event as much as a logistical one.
- Anything left behind — a laptop on the floor of a cage, a test device still plugged in.
5. Two Things People Forget
- The visitor register is the evacuation roll call. In a fire, the list of people in the building who are not on the staff system is the visitor log, and it only works if sign-out is real. This is often the argument that gets the process taken seriously when the security argument does not.
- The register holds personal data. Names, identification details, sometimes vehicle registrations and images. It needs a retention period and access restrictions of its own, and the open paper book on the reception desk where every visitor can read the previous entries is a disclosure, not a record.
How We Approach It
- Review how external access happens today, including the informal paths: recurring vendors, couriers, cleaners, the provider's own staff.
- Define the visit lifecycle and make the credential expire by itself, so closing a visit does not depend on anyone remembering.
- Separate escorted from unescorted by area, and state what escorting requires.
- Bring standing vendor access into joiners, movers and leavers, with the contractual obligations that support it.
- Record the work, not just the attendance, against asset tags, including equipment in and out.
- Settle the register's own handling — retention, who can read it, and its role in evacuation.
What You Get
- A visit lifecycle with pre-authorisation, verified identity and a credential that expires on its own.
- A list of currently outstanding credentials, which on a first pass is rarely empty.
- An escort policy that says what escorting means, by area.
- Recurring vendor access handled like staff access, with the contract terms that make it enforceable.
- A register that records work and equipment movements against asset tags, with its own retention and access rules, and that functions as a roll call.
The useful question is not how many visitors you had last month. It is how many badges you issued and how many came back.