Skip to content
All video guides

Front desk video guide

Lobby and reception staff who check visitors in, print badges and check visitors out.

These short videos support your own staff training records. They do not certify anyone and do not replace your security awareness or export-control training.

Start here

5 videos, about 5 minutes

  1. Read the transcript

    At a defense plant or any regulated site, the front desk should know who is walking in, screen them, and keep a record of every decision.

    A host invites their visitor ahead of time. When the visitor fills in their details, SecurePoint screens them against U.S. and international sanctions and restricted-party lists.

    Once they're cleared, a QR code arrives by email.

    At the lobby kiosk, they scan the code and their ID, take a badge photo, and sign the visitor agreement.

    If a name looks like a possible match, the visit is held until a reviewer decides, and their reason goes on the record.

    When everything checks out at check-in, the host gets an email that their visitor has arrived, and the front desk prints the badge.

    Every check-in, screening result and decision is logged, so when an auditor asks, you can export the evidence.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Video 1: SecurePoint Visitor in 90 seconds

    1:17

    The whole visit, start to finish.

    A host invites a visitor, the visitor is screened when they register and checks in at the lobby kiosk, and the front desk prints the badge. A possible match holds the visit for a reviewer, and every check-in, screening result and decision can be exported as evidence.

  2. Read the transcript

    The front desk runs the day from one screen: who's on site, who's waiting on a review, who's expected today, and who has left.

    Today's pre-registered visitors are listed ahead of time, and anyone past their expected time is flagged.

    When a visitor checks in and is cleared, their host gets an email, and a text if texting is set up for that host.

    At the end of the visit, the desk checks the visitor out, and the time and the staff member are recorded.

    If someone has to be removed, the desk can revoke the visit with a reason. The visit closes, and the visitor is recorded as denied.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Video 2: The front desk view

    0:58

    Your main screen, from arrival to check-out.

    One screen for the front desk: who's on site, who's waiting on a review, who's expected today and who has left. Today's pre-registered visitors are listed ahead of time and late arrivals are flagged. When a cleared visitor checks in, their host gets an email. The desk checks visitors out with the time and staff member recorded, and can revoke a visit with a reason.

    Good to know: Revoke is not an early check-out: it records the visitor as denied. Use Check Out for a normal departure.

  3. Read the transcript

    Step 1. At the kiosk, tap Scan ID or QR, and show the QR code from your email.

    Step 2. Your details fill in from your invitation. Check them, then continue.

    Step 3. If the kiosk asks, scan the front of your photo ID.

    Step 4. If an NDA appears, read it. You can make the text bigger, and you sign at the end.

    Step 5. Answer any questions your site asks, then take your badge photo if asked.

    When the kiosk says Checked In, you're done here. Your site can email your host that you've arrived.

    Screen visitors at check-in. Keep the decisions on record.

    Video 3: How to check in at the kiosk with your QR code

    0:59

    What visitors do at the kiosk, so you can help them.

    Step by step, a visitor checks in at the lobby kiosk with the QR code from their email, confirms the details from their invitation, scans a photo ID and reads an NDA when the site asks, takes a badge photo if asked, and sees Checked In.

  4. Read the transcript

    A badge is only available once the visitor is checked in and approved.

    While a possible match is under review, the visitor is asked to wait for staff, and the badge stays unavailable.

    Here, the visitor agreement and a photo of their ID are missing, so the badge is refused, and the desk sees what's still needed.

    Once those steps are done, the badge is available.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Video 4: When a check-in step is missing

    0:42

    Why a badge is refused, and what to finish first.

    A badge is available once a visitor is checked in and approved. While a possible match is under review, the visitor waits for staff and the badge stays unavailable. In this visit, the visitor agreement and a photo of the ID are missing, so the badge is refused until the front desk completes them.

    Good to know: Wherever badge photos are on, which is the default, a missing headshot also blocks the badge.

  5. Read the transcript

    Step 1. On the front desk screen, open the visitor's record.

    Badge is available once they're checked in and cleared.

    If it lists steps missing for this visit, like the NDA or ID,

    finish those first, or the badge is refused.

    Step 2. Select Badge to open the preview, and make sure the print check has passed.

    Step 3. Select Print Badge, then finish in your browser's print window if one opens.

    Step 4. The visit record then shows the badge was sent to print.

    SecurePoint Visitor. Screen visitors at check-in,

    and keep the decisions on record.

    Video 5: How to print a visitor's badge

    0:52

    Print a badge, step by step.

    How the front desk prints a badge: open a checked-in, cleared visitor's record, finish any steps missing for the visit, check the preview, then print, and the visit record shows it was sent to print.

    Good to know: When you print from the visitor's record on an iPad, the badge goes to your site's Print Connector if it runs one. Otherwise, and always from the check-in result screen, it prints through AirPrint, in black only.

    • Front desk

When it comes up

Watch these when the situation applies at your site.

  • Read the transcript

    Not every visitor is invited ahead of time. At the lobby kiosk, a walk-in starts by scanning their photo ID.

    Their name fills in from the ID. They add their company and a way to reach them, then find the person they're here to see.

    At an export-controlled site, they also give their country of citizenship and confirm the attestation the site requires.

    Then they read and sign the visitor agreement and take a badge photo.

    SecurePoint screens them against sanctions and restricted-party lists. Once they're cleared, the kiosk checks them in.

    Their host gets an email that they've arrived, and the front desk sees them on site, with their photo and ID on file.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Walk-in check-in

    1:04

    When a visitor arrives without an invite.

    A visitor with no invite checks in at the lobby kiosk: their photo ID fills in their name, they add their contact details, host, and country of citizenship, sign the visitor agreement and take a badge photo, and are screened before the kiosk checks them in.

  • Read the transcript

    Admins set up a badge template for each visitor type: the shape, a black or red stripe, and what the badge shows.

    A print check confirms the layout fits the label before anything prints.

    At the front desk, a badge is available once the visitor is checked in and cleared.

    It carries their photo, company and host, the hours it's valid, and a QR code. At an export-controlled site, it also shows their screening and escort status.

    It prints on a Brother QL-820NWB label printer, through the site's Print Connector or from the browser.

    The visit record now shows the badge was sent to print.

    At the end of the visit, they scan the badge's QR code at the kiosk to check out.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Badges that print

    1:07

    How badges print, and how visitors check out with the badge QR code.

    Admins set up a badge template for each visitor type, a print check confirms the layout fits the label, and the front desk prints the badge on a Brother QL-820NWB. At the end of the visit, the badge QR code checks the visitor out at the kiosk.

    Good to know: Red prints only on DK-2251 black-and-red labels. iPad and Android print dialogs print black only; the Print Connector on a Windows PC prints red and black.

  • Read the transcript

    Step 1. An admin turns on device declarations in the site's Device Policy.

    Step 2. At the kiosk, visitors say whether they've brought devices,

    like phones, cameras or laptops.

    Step 3. They pick each device and where it will be kept.

    For a locker, they type the locker ID, then continue.

    Step 4. If a declaration is missing, front desk staff can record it from the visit record.

    Choose how the devices are handled, add the locker,

    and save. It's saved with the visit.

    Screen visitors at check-in.

    Keep the decisions on record.

    How to record a visitor's devices

    0:52

    When your site asks visitors to declare devices.

    Step by step: an admin turns on device declarations for a site, visitors declare their devices and where each one will be kept at the kiosk, and front desk staff can record a missing declaration from the visit record.

    Good to know: Device declarations also need SecurePoint to switch the feature on. If the kiosk never asks about devices after you turn on Device Policy, contact SecurePoint.

  • Read the transcript

    Step 1. When you're ready to leave, tap Check Out on the kiosk.

    Step 2. Scan the QR code on your badge, or find your name in the list.

    Step 3. Check that it's your visit, choose a reason if asked, then tap Confirm Checkout.

    You're checked out, and your checkout time is saved with the visit.

    Step 4, for admins. Keep Auto-close leftover visits on for each site. Visits still under review are left open.

    Other visits left open overnight are closed and marked as having no verified departure. Your compliance contacts then get a summary email.

    Screen visitors at check-in. Keep the decisions on record.

    How to check out at the kiosk

    0:59

    How visitors check out at the kiosk, so you can help them.

    A how-to for visitors and site admins: tap Check Out on the kiosk, scan the QR code on your badge or find your name, and confirm it's your visit. Visits still under review stay open, and other visits left open overnight are closed and marked as having no verified departure.

  • Read the transcript

    Visitors are screened against lists like OFAC's SDN list, the BIS Entity List, and the UN, UK and EU sanctions lists.

    When a name comes back as a possible match to someone on a list, the visit is held. No badge can print until a person reviews it.

    The case goes to the compliance queue, which shows how long each review has been waiting.

    Open it to see exactly what matched: the listed name, the list it's on, and how closely the names compare.

    Compare that with what you know about the visitor. Then record your decision and the reason: not a match, approve, deny, or send it for senior review.

    The decision is saved with who made it and when, and the visit can continue.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    When a name looks like a sanctions match

    1:11

    What happens while a reviewer looks at a possible match.

    A walk-in visitor is screened at check-in, a possible sanctions match holds the visit, and a reviewer records a decision and the reason before the visit continues.

    Good to know: By default, only org admins and compliance managers can record a decision.

  • Read the transcript

    When the site requires it, a visitor who lists another country of citizenship acknowledges they're a foreign national, and that the visit may need an escort and more review.

    The kiosk asks the visitor to wait for their host. The host gets an email asking them to come to the kiosk, check the visitor's photo ID, and print the badge. It also says the visit needs an escort.

    At the kiosk, the host enters their name and confirms three things: they checked the visitor's nationality on their ID, they'll escort them at all times, and they won't share export-controlled technical data without authorization. Then the kiosk prints the badge.

    When the visitor checks out, the host is asked for an after-visit report: whether any controlled technical data was shared, and a short summary. If it's late, reminders follow.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Foreign-person visits

    1:13

    When a visitor is waiting at the kiosk for their host.

    When a site requires it, a visitor who lists another country of citizenship acknowledges they're a foreign national. Their host is emailed to come to the kiosk, confirms they checked the visitor's nationality on their ID, that they'll escort them at all times and won't share export-controlled technical data without authorization, and then the kiosk prints the badge. At check-out, the host is asked for an after-visit report.

    Good to know: The come-to-the-kiosk email and the host confirmation at the kiosk work only on kiosks set to autonomous check-in. Otherwise the visitor waits for the front desk.

Other videos

8 more, each labeled with the roles it is for.

Show 8 more videos
  • Read the transcript

    Hosts invite their own visitors from Host Hub, with the date and time of the visit and anything the visitor must do first, like acknowledging the NDA.

    The visitor gets a link by email. On their phone, they add their details, capture their ID if the site requires it, and acknowledge the NDA.

    When they submit, SecurePoint screens them against sanctions and restricted-party lists. If a name needs a closer look, a reviewer can decide before the visitor arrives.

    Once they're cleared, their QR code arrives by email, and their host is told.

    On the day, the front desk sees them under Expected Today.

    At the kiosk, they scan the code, and their details are already filled in from the invitation.

    When they're checked in, their host gets an email that their visitor has arrived.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Pre-register a visitor

    1:12

    A host invites a visitor from Host Hub, the visitor registers on their phone and is screened when they submit, and a name that needs a closer look goes to a reviewer before the visit. Once cleared, the QR code arrives by email, the front desk sees the visitor under Expected Today, and the kiosk fills in their details from the invitation.

    Good to know: At ITAR and DCSA sites, and in organizations with the CMMC Level 2 Evidence Pack, a site that uses the NDA has the visitor sign it at check-in on every visit, not when they register. DCSA sites do the same for the safety briefing.

  • Read the transcript

    Admins set up the visitor agreement and the safety briefing, and switch each one on for a site or a visit purpose.

    Hosts can add them to an invite, and the visitor is asked to acknowledge them while registering.

    At sites that turn it on, visitors who list U.S. citizenship attest they're a U.S. person. Others acknowledge their visit may need an escort and more review.

    At the kiosk, signing stays locked until the visitor reaches the end of the agreement, and the safety briefing comes next.

    At the front desk, visitors can sign on their own phone or right at the desk, with a typed or drawn signature.

    The signature is saved with the visit, along with the name they gave and the time, and staff can open a receipt.

    And if a required step is missing, the front desk sees what's still needed before the badge can print.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    NDAs and safety briefings

    1:13

    Admins switch the visitor agreement and safety briefing on for a site or a visit purpose. Visitors acknowledge them when they register and sign at the kiosk, on their phone, or at the desk, and a badge waits until the required steps are done.

    Good to know: At ITAR and DCSA sites, and in organizations with the CMMC Level 2 Evidence Pack, a site that uses the NDA has it signed at check-in on every visit, so registration does not ask for it. DCSA sites do the same for the safety briefing.

  • Read the transcript

    When an auditor asks how visitors were screened, an admin opens the Evidence Center and picks a template and a date range.

    SecurePoint builds a ZIP file with screening results, review decisions and audit records from that period, and its manifest lists an SHA-256 checksum for each file.

    Each pack's settings stay in the history, so the same period can be rebuilt later as a new pack.

    The audit ledger shows who did what, and when: check-ins, screening results, reviewer decisions, and exports.

    Users can't edit or delete ledger records, and exports from this page come with an SHA-256 checksum.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Evidence packs and the audit trail

    1:02

    An admin picks a template and a date range in the Evidence Center, and SecurePoint builds a ZIP of screening results, review decisions and audit records, with a manifest that lists an SHA-256 checksum for each file. The audit ledger shows who did what and when, and its CSV export comes with a checksum.

    Good to know: By default, only org admins and compliance managers can build or download evidence packs and export the ledger. Auditor accounts can view the ledger.

  • Read the transcript

    Sites can ask visitors to declare restricted devices, like phones, cameras and laptops, and say where each one will be kept during the visit.

    At the front desk, staff can record a declaration too, and it's saved with the visit.

    Turn on phone photos, and visitors can take their badge photo on their own phone: scan the code, take the picture, and it appears on the kiosk.

    Visitors can make the agreement text larger while they read.

    When a visit is held, your compliance team gets an alert email, and, on plans with SMS, a text message too.

    At each site's closing time, visits still open are closed and marked as not seen leaving, unless a review is still open, and a daily summary goes out.

    SecurePoint Visitor. Screen visitors at check-in, and keep the decisions on record.

    Features you might have missed

    1:06

    Restricted-device declarations at the kiosk and the front desk, badge photos taken on the visitor’s own phone, larger agreement text, alert emails (and text messages on plans with SMS) when a visit is held, and the end-of-day close of visits still open, with a daily summary.

    Good to know: Phone photos are a kiosk setting, off by default. Held-visit texts need a plan with SMS. Device declarations also need SecurePoint to switch the feature on.

  • Read the transcript

    Continuous Monitoring re-screens the employees, contractors and vendors you enroll, as often as every night.

    Import your roster, or add people and companies one at a time.

    Each run checks them against the sanctions and restricted-party lists your organization has turned on.

    When a name comes back as a possible match, a case opens for review, and your compliance contacts get an email summary.

    Nothing is blocked automatically. Your team reviews each hit and records the outcome.

    Every run is kept in Screening History, and every decision is written to the audit trail.

    SecurePoint. Re-screen the people you work with, and keep the decisions on record.

    Continuous Monitoring

    0:57

    The employees, contractors and vendors you enroll are re-screened as often as every night. A possible match opens a case for review and sends your compliance contacts a summary email. Nothing is blocked automatically: your team records the outcome, and every run and decision is kept.

    Good to know: Continuous Monitoring is an add-on that SecurePoint turns on for your organization. By default, org admins and compliance managers use it.

  • Read the transcript

    Step 1. Open Host Hub and start a new invite.

    Step 2. Enter your visitor's name, email and company, then the date and time of the visit.

    Step 3. Pick the purpose, and tick anything they must acknowledge first, like the NDA. Then send it.

    Step 4. Your visitor gets an email link. On their phone, they add their details, and their ID if your site requires it.

    Step 5. When they submit, SecurePoint screens them. Once they're cleared, their QR code for the kiosk arrives by email.

    Screen visitors at check-in. Keep the decisions on record.

    How to invite a visitor

    0:55

    A how-to for hosts: start an invite in Host Hub with the visitor's details, the visit date and time, and anything they must acknowledge first, and once the visitor registers on their phone and is screened and cleared, their QR code for the kiosk arrives by email.

    Good to know: At ITAR and DCSA sites, and in organizations with the CMMC Level 2 Evidence Pack, a site that uses the NDA has your visitor sign it at check-in on every visit, not when they register. DCSA sites do the same for the safety briefing.

  • Read the transcript

    Step 1. In Visitor Audit, under Reports, find the visitor's check-in date.

    Step 2. In Evidence Packs, pick a template, and dates from before the visit to a few days after.

    Step 3. Select Generate to download a ZIP of screening results, review decisions and audit records for those dates.

    Step 4. Open the ZIP's manifest. It lists an SHA-256 checksum for each data file, so you can check each one.

    Step 5. To rebuild it later, select Download ZIP in Evidence Pack History. It builds a new pack from current records, with the same settings and its own checksum.

    Screen visitors at check-in. Keep the decisions on record.

    How to rebuild an evidence pack for a past visit

    1:00

    A how-to for compliance teams: find the visitor's check-in date in Visitor Audit, generate an evidence pack whose dates cover the visit, check its files against the SHA-256 checksums in the manifest, and rebuild it later from Evidence Pack History as a new pack from current records.

  • Read the transcript

    Step 1. SecurePoint turns on the Screening API for your organization and issues your API key.

    Step 2. POST the name to prescreen as the subject, with your key in the Authorization header. The key identifies your organization, so you don't send one.

    Step 3. Read the result: a screening ID, a risk level and score, the number of possible matches, and whether review is required.

    When review is required, the name goes to your compliance team's review queue, and the status reads pending.

    Step 4. Keep the screening ID. Later, GET the screening by that ID to read the stored result.

    Screen visitors at check-in. Keep the decisions on record.

    How to screen a name with the Screening API

    1:00

    A how-to for developers: once SecurePoint turns on the Screening API for your organization and issues your API key, POST a name to prescreen, read the screening ID, risk level and score, possible matches and whether review is required, then GET the stored result by that ID.

Video Guide: Front desk | SecurePoint USA