User Guide

GateVMS Visitor Management System

A complete guide for Super Administrators and Company Administrators — how to manage companies, admins, zones, QR codes, employees, visitors, reports, and settings.

Getting Started

Everything you need to know before using the system.

What is this system?

GateVMS VMS is a multi-company visitor management platform. Companies run their own visitor check-in process from one shared system, with strict data isolation — each company only ever sees its own data.

There are two levels of access:

RoleWhoWhat they manage
Super AdminPlatform administrator (e.g. GateVMS staff)All companies, all admin users, all visitors, audit log
Company AdminA company's administrator (e.g. Intellico Berhad)Their own zones, QR codes, employees, visitors, reports, settings

How visitors check in

Visitor side (no login)

  1. Visitor scans the zone QR code (printed at the entrance) with their phone.
  2. The mobile kiosk opens: they enter their mobile number.
  3. Returning visitor? The system shows a masked hint ("Is this you?"). New? They enter name + email.
  4. They take or upload a photo.
  5. They select the host they're visiting, and a purpose.
  6. They review, tick consent, and Check In.

What the admin sees

  • The check-in appears in Visitors and on the Dashboard.
  • The host + admins get an arrival email; the visitor gets their own confirmation email.
  • Admins can check the visitor out and generate a visitor pass PDF.

Signing in

  1. Open the system URL: https://vms.khanster.net
  2. You'll be taken to the sign-in page. Enter your email and password.
  3. Click Sign in. You'll land on your dashboard.
  4. To leave, click Logout at the bottom of the sidebar.
Security: Always log out when finished, especially on shared devices. If you're locked out, ask a Super Admin to reset your password.

Understanding the sidebar

The dark sidebar on the left is your main navigation. The items you see depend on your role:

Super Admin sees

  • Dashboard
  • Companies
  • Admin Users
  • All Visitors
  • Audit Log

Company Admin sees

  • Dashboard
  • Visitors
  • Zones
  • Employees
  • Reports
  • Settings

On a phone/tablet, tap the ☰ menu icon in the top-left to open the sidebar.

Super Admin Guide

You are the platform administrator. You set up companies and their admins, and you have a read-only view across the whole system.

Dashboard

The Super Admin dashboard shows platform-wide summary cards. (Note: companies/visits data appears once tenants are active.)

  • Today's Visitors — check-ins today across all companies.
  • Currently Inside — who is checked in right now.
  • Checked Out Today — departures today.
  • Total Visitors — lifetime visitor count.

Managing Companies

Companies are your tenants. Each is fully isolated from the others.

Create a company

  1. Sidebar → Companies → click + New Company.
  2. Fill in: Company Name (required), Registration No., Address, Phone, Email, Logo (optional image), and Status.
  3. Click Create Company. The company's default settings are created automatically.

View / edit a company

  • In the Companies list, click View to see the company's details, stats (admins, zones, employees, visits), and its admin users.
  • Click Edit to change its info or logo.
  • On the View page you can Suspend or Activate a company. A suspended company's QR check-in links stop working (visitors get a 404).

Search & filter

Use the search box (name, email, reg no.) and the Status dropdown to find companies.

Managing Company Admin Users

Company Admins are the people who run a company's day-to-day visitor management. Each is tied to exactly one company.

Create a company admin

  1. Sidebar → Admin Users → click + New Admin.
  2. Fill in: Name, Email, Password + confirm, and select the Company from the dropdown.
  3. Click Create Admin. The user is now active and can log in.

Reset a password

  1. In the Admin Users list, find the user and click Reset Password.
  2. Confirm. The system generates a new random password and shows it on the next screen.
  3. Share the new password securely with the admin (e.g. private message, not a group chat).
Important: A company admin can only see their own company's data. Assign them to the correct company — this cannot be "shared across" companies.

All Visitors (platform-wide view)

This is a read-only, cross-company list of every visitor in the system.

  • Search by name, phone, or email.
  • Filter by company.
  • Click View on a row to see the visitor's photo and full visit history (cross-company).
Super Admins can view but not edit visitor records — management happens in each company's own console.

Audit Log

A record of every admin action across the platform, for accountability and security.

ColumnWhat it shows
TimeWhen the action happened
UserWho did it
CompanyWhich company it relates to
Actione.g. create, update, checkout, export, test-email, regenerate-qr
ModuleWhat area (company, admin_user, zone, employee, visit, settings, report)
RecordThe record ID affected
IPIP address of the user

Search by action/module and filter by company.

Company Admin Guide

You run a single company's visitor management: zones, QR codes, employees (hosts), visitors, reports, and settings.

Dashboard

Your at-a-glance view of the company's visitor activity today:

  • Today's Visitors — check-ins today.
  • Currently Inside — who's on site right now.
  • Checked Out Today — departures today.
  • Total Visitors — lifetime total.
  • Visitors by Zone — today's volume per zone (bar chart).
  • Visitors by Day — the last 7 days at a glance.

Setting up your company for the first time

Follow this order to go live:

  1. Employees (hosts): add the people visitors will select as their host.
  2. Zones + QR: create a zone for each entrance and generate its QR code.
  3. Settings: set required fields, your privacy notice, and notification emails.
  4. Print the QR and place it at each entrance.
  5. Visitors can now scan and check in.
You don't create "visitors" yourself — they register via the kiosk. You view and manage them in the Visitors area.

Employees / Hosts

Employees are the people a visitor can select as their host. They don't have logins — they're just entries in the host list (and they get the arrival email).

Add an employee

  1. Sidebar → Employees+ New Employee.
  2. Enter: Name (required), Department, Designation, Email, Phone, and Status.
  3. Click Add.

Import from CSV (bulk)

  1. On the Employees page, click Import CSV and choose a file.
  2. The file should have a header row: name, email, department, designation, phone.
  3. The system imports and reports how many were added. Rows without a name are skipped.

Search employees by name/email/department, or Edit/Delete individual rows.

Tip: The host email must be correct — that's where the visitor arrival notification goes.

Managing Visitors

The Visitors area is where you see check-ins, manage who's on site, and issue passes.

Visitors list

Shows each visit with the visitor's photo, the host they're meeting, zone, check-in/out times, and status.

Filter with:

  • Search — name, phone, or email.
  • Zone — all or a specific entrance.
  • Host — all or a specific employee.
  • Status — Checked In / Checked Out / Expected / Cancelled.
  • Date range — from / to.
  • Department — filter by the host's department.

Status colours: green = Checked In slate = Checked Out amber = Expected red = Cancelled

Visitor detail

Click View on a visit to open the visitor's detail page. It shows:

  • Their photo, name, phone, email.
  • A Download Visitor Pass button (prints a PDF pass, e.g. for badges).
  • Their visit history — every check-in with zone, host, and status.

Checking a visitor out

  1. On the Visitors list, find a visitor with status Checked In.
  2. Click the amber Check Out button next to their row.
  3. Their status changes to Checked Out and the time-out is recorded.
You can also check out from the visitor's detail page.

Visitor pass (PDF)

When a visitor is currently checked in, you can generate a printable pass:

  1. Open the visitor detail page.
  2. Click Download Visitor Pass.
  3. A PDF opens/downloads — print it as a badge for the visitor.

Returning visitors & privacy

  • When a returning visitor enters their phone, the kiosk shows only a masked hint (initials + masked email) — not their full details.
  • The visitor confirms "Yes, that's me" and only then sees their prefilled info.
  • A new photo is always captured even for returning visitors.
This masking is a privacy safeguard — a bare phone number never reveals full personal information on its own.

Zones & QR Codes

Zones represent entrances/locations. Each zone has its own QR code that opens its check-in form.

What is a zone?

A zone is a physical check-in point — e.g. "Main Entrance", "Reception", "Delivery Bay", "Car Park". Each zone has a unique QR token. Visitors scan that zone's QR to check in at that location.

Create a zone

  1. Sidebar → Zones+ New Zone.
  2. Fill in:
    • Zone Name (required) — e.g. "Main Entrance".
    • Zone Code (optional) — an internal code like ABC-MAIN.
    • Location (optional) — e.g. "Ground Floor".
    • Description (optional).
    • Status — Active (accepts check-ins) or Inactive (QR disabled).
  3. Click Create Zone. The QR token is generated automatically.

Get the QR code

  1. Go to Zones and click the QR link on the zone's row (or open the zone).
  2. On the zone page you'll see:
    • The QR code URL (the web address it encodes).
    • Download PNG — saves the QR image to your device.
    • Print — opens a printable "WELCOME — Please scan this QR" page.
  3. Place the printed QR at the zone's entrance.
Visitors open the URL (by scanning) and complete the check-in. No QR scanner app is needed — the phone's camera reads it.

Regenerate a QR

If a QR is lost, printed on the wrong thing, or you want to rotate it:

  1. On the zone page, click Regenerate.
  2. Confirm. The token changes and the old QR stops working.
  3. Download/print the new QR and replace the old one.
Use with care: regenerating invalidates the old QR immediately. Only do this when you're ready to replace the printed code.

Edit / disable / delete a zone

  • Edit — change name, location, description, or status.
  • Delete — remove the zone. The system asks you to confirm.

Setting a zone to Inactive disables its QR without deleting it — useful for temporarily closing an entrance.

Reports & Exports

Export visitor records for records, analysis, or compliance.

Export a visitor report

  1. Sidebar → Reports.
  2. Set your filters:
    • Date From / Date To — limit the period.
    • Format — CSV, Excel (.xlsx), or PDF.
    • Status — All, Checked In, or Checked Out.
  3. Click Export Report. The file downloads.

The report includes: date, visitor name, phone, email, host, department, zone, time in, time out, status, and purpose.

Emergency export (currently inside)

For fire drills or evacuations — export everyone currently inside the building in one click.

  1. On the Reports page, scroll to the Emergency Export box (highlighted in red).
  2. Click Export Currently Inside (CSV).
  3. A CSV downloads with every checked-in visitor: name, phone, host, zone, and time in.
Tip: Exports are logged in the audit trail, so export activity is visible to Super Admins.

Settings

Configure your company profile and how the visitor kiosk behaves.

Company Profile

  • Company Name — required.
  • Address, Phone, Email — company contact details.
  • Logo — upload an image; it appears on the kiosk and sidebar.

Visitor Settings

Toggle which fields are required in the visitor kiosk:

SettingWhen ON
Require EmailVisitor must enter an email to check in.
Require PhotoVisitor must take/upload a photo.
Require HostVisitor must select a host (employee).
Require PhoneVisitor must enter a phone number.
Allow Returning Visitor Auto-fillReturning visitors get their details prefilled after confirming "that's me".
Capture Purpose of VisitVisitor must state their purpose (e.g. Meeting, Delivery).

Data Retention (months) — how long to keep visitor data before the optional purge process anonymizes it.

Privacy Notice — the text shown to visitors on the consent step (e.g. your PDPA/privacy statement).

Notification Emails

Extra email addresses (besides the host) to notify on every visitor arrival. Multiple addresses supported — one per line or comma-separated. The host's own email is always notified.

Use Send test email to verify email delivery — it sends a real message to the configured inbox.

Two emails are sent per check-in: (1) the arrival notification to the host + everyone listed here, and (2) a separate "Your visit is confirmed" confirmation to the visitor's own email.

Saving

Click Save Settings to apply changes. A green confirmation banner appears briefly.

FAQ & Tips

Common questions

QuestionAnswer
How do visitors check in without an app?They scan the zone QR with their phone's camera. The mobile web form opens — no app install needed.
Why does the kiosk ask for a phone number first?To detect returning visitors (privacy-masked) and speed up repeat check-ins.
Can one company's admin see another company's data?No. Data is strictly isolated per company.
How do I notify multiple people of arrivals?Add their emails under Settings → Notification Emails. The host is always notified.
What happens if I regenerate a QR?The old QR stops working immediately. Print and place the new one.
How do I get everyone currently in the building?Reports → Emergency Export → Export Currently Inside (CSV).
A visitor forgot to check out. Can I fix it?Yes — find them in Visitors (status Checked In) and click Check Out.
Can visitors see others' photos or details?No. The kiosk only shows the visitor's own info (and only after they confirm their identity).
How do I handle a suspended/closed entrance?Set the zone to Inactive — its QR stops working but the zone stays for later.
What should I do if I suspect a security issue?Check the Audit Log (Super Admin) and change passwords. Contact your Super Admin.

Quick tips

  • Keep host emails accurate — that's where arrival alerts go.
  • Set a clear privacy notice in Settings so visitors know how their data is used.
  • Test a check-in before launch — scan your own QR on a phone and complete the flow.
  • Use Emergency Export during drills — it's one click and lists everyone on site.
  • Suspend, don't delete — prefer Inactive zones/employees over deleting them, to keep history intact.
  • Log out on shared devices — protects your company's visitor data.
Need help? Contact your system administrator. For platform-level issues (companies, admins, audit), a Super Admin handles those.