Who is on site right now – and why? Purpose sessions with check-in
An access log shows that a door was opened. It does not show who is still inside. See how check-in and check-out with a stated purpose give you presence data for evacuation, lone working and contractor visits.
A fire alarm goes off at a district heating plant. The incident commander needs to answer one question immediately: is anyone in there?
The access log can say the gate was opened at 09:14. It cannot say whether that person left at 09:20 or is still standing in the boiler room.
That is the difference between access and presence. Most systems only record the first.
Where the difference hurts
Evacuation
An alarm demands a list of who is inside. An access log is not a roll call.
Lone working
A technician alone at a remote pumping station. If she never checks out, nobody notices.
Contractor visits
Who was here, for how long, and doing what? "They had a key" is not an answer.
Documentation
CER requires preventive measures and training. Both assume you know who has actually been on site.
The solution: check in with a purpose
In SnapKey, presence is recorded as a session: a check-in, a purpose, and a check-out.
Purposes are defined up front
You create the purposes that make sense for your operation — Maintenance, Inspection, Delivery, Repair. For each purpose you can switch on require note, so the person has to state what the visit is actually about. Only active purposes are shown to users, so the list does not sprawl.
It sounds trivial. But it is the difference between a log saying "The door was opened" and a log saying "Jens Madsen, maintenance, valve replacement in pump house 2, 09:14–11:40".
Check-in happens at a QR code
Each location has two QR codes: an ENTRY code at the entrance and an EXIT code at the exit. You print them and put them up. No app navigation, no training — scan on arrival, scan on departure.
Arrival
│
├─ Scan ENTRY code
├─ Choose purpose ──► (note required?) ──► write note
└─ Session active
│
│ Now visible on the active sessions overview
│
Departure │
│ │
└─ Scan EXIT code ──► Session completed
When someone forgets to check out
It happens. Which is why there are four ways a session can end:
| Method | When |
|---|---|
| QR scan | The norm – the person scans the EXIT code on the way out |
| Manual | The person ends the session themselves in the app |
| Automatic | The session expires on its own after the set duration |
| Administrator | An administrator ends the session and marks it completed |
Sessions that end as expired are worth watching. One is forgetfulness. A pattern is either a badly placed EXIT code or a workflow that does not match reality. Both are things you want to know.
The day-to-day overview
The active sessions view is the screen worth leaving open in a control room: who is inside, at which location, for what purpose, and how long they have been there.
Alongside it, figures accumulate over time:
✅ Total sessions for the period
✅ Active sessions right now
✅ Completed today
✅ Average duration – used to spot a visit that falls well outside the normal
✅ Sessions by purpose – what the site is actually used for
Average duration is more useful than it sounds. When a routine inspection normally takes 25 minutes and one session ran four hours, that is worth asking about — whether the answer turns out to be a problem or just a forgotten scan-out.
The link to incidents
Check-in and check-out are also recorded as incidents, alongside access and sensor events. That supplies the context that is otherwise missing:
- A forced open event on a door where a session with purpose Maintenance was simultaneously active is probably a technician who used the wrong door.
- The same forced open event with no active session is something else entirely.
That distinction is what decides whether an incident gets escalated to a regulatory case or closed with a note.
What it means for compliance
The CER regime requires preventive measures, resilience planning, and training and exercises. All three assume you can account for who moves around the site.
NIS2 sets requirements for human resources security and supply chain security — which also covers how external parties are handled while physically present.
Purpose sessions produce the documentation for both as a by-product of something people do anyway: go in, and come out again.
FAQ
Does everyone need the app installed?
The entry and exit QR codes are the primary flow and are designed to work for visitors and contractors. Employees with the app can also end a session manually.
What if someone scans in but never out?
The session expires automatically after the set duration and is marked as expired, or an administrator can end it. Expired sessions are worth following up – they usually show where the workflow does not fit.
Is this the same as an access log?
No. An access log records that a lock was opened at a point in time. A session records a period with a purpose – from arrival to departure – and can therefore answer who is inside right now.
Can we require people to state what they are doing?
Yes. On each purpose you can switch on require note, so the person must describe the visit before the session starts.
Contact us
Want to know who is on site – including when the alarm goes off? Contact SnapKey.
Related articles
The access control was perfect – the door stood open for six hours
Access control knows who opened the door. It does not know whether the door was closed again. See how alarm sensors, alarm zones and auto-disarm catch forced entries, doors left open and jammed locks without false alarms.
CER Directive – Complete Guide to Critical Infrastructure Compliance
Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.
The CER Directive after 17 July 2026 – designated as a critical entity? The clock is running
The deadline for designating critical entities expired on 17 July 2026. If your organisation has been notified, you have 9 months for the risk assessment and 10 months to comply. Here is what CER requires of your physical security.