What you need to know
A visitor badge is only one moment in a longer control. Tie every non-public visit to an approved sponsor, defined destination and time window, appropriate escort, visible credential, confirmed departure, and reviewable record.
Potentially affected
Reception and security desks, visitor-management procedures, temporary badges, employee sponsors, contractors and vendors, delivery entrances, controlled interior areas, physical visitor logs, and access-control operators.
DSE recommendation
Define a single visitor lifecycle covering preregistration, identity verification, authorization, zone and time limits, escort rules, badge return, overdue escalation, record review, and privacy-conscious retention.
Source facts: visitor access extends beyond identity at the entrance
The Interagency Security Committee’s December 2020 Facility Access Control guide addresses the full access process for people entering federally occupied space: arrival, identity and authorization decisions, screening, movement, escort, and the first authentication point into non-public space. It treats visitor processing as part of the facility’s risk-based operating model, not a standalone badge-printing task.
The guide describes alternate access procedures for a person who cannot present the ordinary accepted identification, including a prearranged visit in which the security post contacts the agency point of contact for access and escort. It states that the visit sponsor, designee, or dedicated escort is responsible for the individual in federally occupied space. Escort procedures and ratios should reflect the type of visitor, associated risk, and operational requirements.
The ISC presents multiple escort levels, ranging from minimal practices for authorized personnel without local access through continuous, high-positive control for higher-risk circumstances. The chosen level drives proximity, visual or other control, briefing, and monitoring expectations. This is federal best-practice guidance; it does not prescribe a private facility’s identity documents, badge color, escort ratio, retention period, or authority. Applicable law, labor rules, accessibility needs, contracts, privacy obligations, and local facility risk govern the commercial workflow.
DSE recommendation: close every visit from request through departure
Build one workflow for guests, interview candidates, delivery personnel, technicians, auditors, temporary workers, and after-hours vendors. Different visitor classes can have different controls, but none should rely on the receptionist guessing what “normal” means.
- Require a responsible sponsor. Capture the sponsor, visitor identity information actually needed, organization, purpose, date and expected times, entrance, destination, approved zones, escort requirement, equipment or material being brought in, and any advance screening or accommodation. The sponsor should affirm the request, not merely appear in a directory.
- Verify the visit at arrival. Match the person to the approved request using the organization’s accepted method. Resolve misspellings, substitutions, early arrivals, groups, and unknown sponsors through a documented exception path. Front-desk pressure should not silently turn an unapproved visit into an approved one.
- Issue the least-capable credential. Make the badge visibly temporary and configure only the locations and hours needed. Do not copy an employee’s access profile for convenience. Where no electronic credential is needed, use a clearly recognizable visitor badge and control the movement procedurally.
- Make escort ownership explicit. State who receives the visitor, when custody transfers, where unescorted movement is allowed, and what happens if the host cannot be reached. Include restrooms, cafeterias, smoking areas, loading docks, evacuation, and emergency separation rather than assuming the visitor will remain beside the sponsor.
- Close out the visit. Record departure, recover or disable the credential, reconcile loaned keys or equipment, and alert on badges still active after the approved window. A checkout kiosk is useful only if someone investigates the exceptions.
- Review the record. Look for recurring overdue visits, missing badges, repeated sponsor exceptions, entries without departures, unusual after-hours activity, and attempts to reach unapproved areas. Route anomalies to a named owner and document disposition.
Minimize personal data. Define which fields serve an operational or legal need, who may see them, how long they are retained, how paper logs are protected from casual viewing, and how records are disposed of. Avoid collecting identification numbers or copies merely because the software offers a field.
Test the process with ordinary and difficult scenarios: a walk-in executive guest, a substitute technician, a large group, an after-hours contractor, a visitor whose sponsor is absent, a lost badge, an evacuation, and a person who declines the stated verification step. Measure time to resolve exceptions, overdue badge closure, unreturned credentials, sponsor response, and record completeness. The result should be welcoming without being vague: every non-public visitor has an owner, a purpose, a boundary, and a verified end.
Official references
- Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice, December 17, 2020.
- CISA, Interagency Security Committee policies, standards, and best practices.
Review the official source
CISA Interagency Security Committee: Facility Access Control—An ISC Best Practice · Published December 17, 2020
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE