ThreadWare is built from modules. An administrator gives you a role in each module, for each company you work in, and your menu is built from those roles.
Booking a visitor is the exception. Every approved user can use Add New Visitor and My Visitor Cards without being granted anything. Security, the on-site list and the register need a Visitor Cards role.
Can I use it?
| Who | What you can do |
|---|---|
| Any approved user | Book visitors, send them their pass, see visitors coming to see you, and sign off your own visitors. |
| Visitor Viewer | The Visitors On Site list, and All visitors under My Visitor Cards → Visiting me (to look, not to sign off) - for safety officers and reception. No phone numbers, ID digits or number plates. |
| Security | Manage Visitors: visitors at your company's sites - today or any dates you choose - check in and out, walk-ins, induction, asking the host to sign off, and the emergency evacuation check-out. Security cannot sign off a visit - that is the host's job. |
| Visitor Sign-off | The "senior person": may sign off any visitor in the company, for example when the host has already gone home. |
| Visitor Admin | Settings, the Visitor Register, revealing a stored phone number or number plate (recorded in the audit log), finding visits by number plate, legal hold, corrections and erasure. |
Security guards each need their own ThreadWare account - every check-in and check-out records who did it. An administrator gives the guard the Security role in the company, and ticks the site(s) the guard works on their user record. Those are the guard's My sites, shown by default. A guard can still choose All sites to see - and check in or out - a visitor booked at any site in the company, for example one booked against the wrong site. A guard with no site ticked sees every site.
Where to find it
| Menu item | What it is for |
|---|---|
| Visitor Cards → Add New Visitor | Book one or more visitors. |
| Visitor Cards → My Visitor Cards | Visitors coming to see you (and signing them off), and visitors you have booked (passes, edit, cancel). |
| Visitor Cards → Manage Visitors | The security gate. |
| Visitor Cards → Visitors On Site | Everyone checked in and not yet checked out, per site. |
| Visitor Cards → Visitor Register | Search, investigate, correct, legal hold (Visitor Admin). |
| Administration → Visitor Cards → Settings | Retention, induction, sign-off and the privacy notice (Visitor Admin). |
Booking a visitor
- Open Visitor Cards → Add New Visitor.
- Choose the site and the dates. For a one-day visit the arrival date and last day are the same. A booking can cover several days (up to the limit your company sets).
- Enter the purpose of the visit.
- Choose who they are visiting. It is you by default. Type two letters of a colleague's name to pick them instead, or switch on not a ThreadWare user and type the name. Always give a contact number - security phones it if there is a problem.
- Tick Requires induction before allowing access if the visitor needs the site safety induction, and Require host sign-off if security must not let them leave until you have confirmed the visit. Your company may already require either; the box is then ticked and locked.
- Add each visitor: name and company, and optionally their phone, e-mail (only used to send them the pass) and vehicle registration if they drive in. Use Add another visitor for a group.
- Leave Remember this site and my contact number ticked, and next time they are filled in for you - on the web and on the phone app.
- Press Book visitors. Security at that site is told straight away, and so is the person being visited if it is not you.
Visitors' personal information is protected by POPIA. Phone, e-mail, the last digits of an ID and number plates are stored encrypted, and everything is deleted automatically after the retention period (normally 6 months; 12 months at sites your company marks as high-risk, for theft discovered late). Leave a field blank if you do not need it.
The visitor pass
Every visitor gets their own pass: a picture sized for a phone screen, and a printable PDF. It shows the
visitor's name and company, the site, the dates, who they are visiting, a large QR code and
an 8-character pass code (for example ABCD-2345). The pass never shows a phone
number, ID number, e-mail address or number plate.
The top of the pass - and of the Add New Visitor screen - shows the company's logo. An administrator
puts it on the web server in the companylogos folder, named with the company's ID number: for example
companylogos/1.png or companylogos/1.jpg for company 1. Use a PNG or JPG at least 600
pixels wide (SVG files are not used). If there is no logo, the pass prints without one. A new or replaced logo can
take up to 12 hours to appear.
For the server administrator: the companylogos folder is set up once, as described in
the installation manual. It must contain the web.config file supplied with ThreadWare - without it the
logo address shows the ThreadWare app instead of the picture, and passes print without a logo. To check a logo, open
its address (for example https://your-server/companylogos/1.png) in a private browser window:
you should see only the picture. An ordinary window that has used ThreadWare before shows the app for any address,
so it cannot tell you.
There are three ways to get it to the visitor. Use the buttons next to each visitor after booking, or later under My Visitor Cards → Booked by me:
- E-mail - if you gave their e-mail address and left E-mail each visitor their pass ticked, it was sent when you booked, with the pass in the message and the picture and PDF attached. The envelope button sends it again.
- Share - the share button opens your phone's share menu so you can send the pass picture by WhatsApp, SMS or any other app. On a computer it downloads the picture instead.
- Download or print - the picture and PDF buttons, or print all passes on a booking with the printer button.
The visitor shows the QR code on their phone - or on paper - together with their ID when they arrive. A forwarded pass gets nobody in on its own: security still checks the ID.
At the gate (Security)
Open Visitor Cards → Manage Visitors. The list shows today's expected visitors, everyone still on site - however long ago they arrived - and who left today. It refreshes itself every minute.
- Site - My sites (the sites ticked on your user record, if any), All sites (every site in your company), or one site. In an emergency choose All sites: a visitor booked against the wrong site still appears. A visitor at a site that is not one of yours is marked Other site - check the booking is right. You can check them in and out as normal.
- From / To - look ahead at the visitors booked for any dates, up to 62 days at a time. A visitor booked for a later day cannot be checked in until their visit starts. Press Today to go back. Everyone still on site is listed whenever the dates include today.
Checking a visitor in
- On the phone app press Scan pass and point the camera at the QR code. On a computer, type the pass code and press Find. You can also press Check in on the row.
- Choose the type of ID they showed, look at it, and tick ID sighted. Never copy or photograph it. You may record the last 4 characters of the number.
- Record the vehicle registration if they drove in, and their phone number if the booking has none.
- If the pass says Induction required, complete the induction and tick that it is done - check-in is refused until it is.
- Press Check in. The host is told their visitor has arrived.
Walk-ins
Press Walk-in for a visitor nobody booked. Enter their name, company and phone number (required, so they can be traced in an emergency), who they are visiting and that person's number, the purpose, and the ID check. Show them the privacy notice and tick the box. They are checked in immediately and given a pass code - print the pass from the row's menu if they need one.
Checking a visitor out
- Scan or type their pass, or press Check out on the row.
- If the visit needs host sign-off and the host has not signed it off, you are told so, with the host's name and number. Press Ask host to send them a notice, or phone them.
- If the visitor genuinely must leave now, tick must leave without host sign-off and give a reason. This is recorded and reported to the Visitor Admin.
- If they left earlier and nobody recorded it, switch on left earlier, enter the real time and say why it is late.
A visitor stays on site - and on the emergency list - until security checks them out. If you forget, they stay listed and security and the host are sent one "still on site" notice after the visit's cut-off time. That is deliberate: in a fire it is safer to look for someone who has gone than to miss someone who is still there.
Emergency evacuation
Press Emergency evacuation. The list is loaded fresh, so the site and dates chosen on the screen can never hide anyone. Leave the site on All sites to list every visitor on site at all your company's sites, grouped by site, or choose one site. Tick each visitor as they are accounted for at the assembly point, then confirm with a short note of the incident. Host sign-off is not needed. Anyone not ticked stays on the on-site list.
Signing off your visitor (hosts)
When your visit is finished, open My Visitor Cards → Visiting me and press Sign off next to the visitor - or press Scan pass and scan their QR code, or type their pass code. Security can then let them out. This replaces signing the paper card.
You are sent a notice when your visitor arrives, and again if security says they are waiting at the exit. A Visitor Sign-off user can sign off any visitor in the company - use it when the host is not available.
A Visitor Viewer, Security, Visitor Sign-off or Visitor Admin also has a Show choice at the top of Visiting me: All visitors (all sites) lists every visitor booked or on site in your companies - for peace of mind in an emergency - and, with more than one company, all visitors at one company. Only the host, a Visitor Sign-off user or a Visitor Admin can sign a visit off.
Visitors on site and the emergency muster
Visitor Cards → Visitors On Site lists every visitor checked in and not yet checked out, per site, with who they are visiting and that person's number. Print it or export it to Excel.
Visitors also appear on the Time and Attendance → Emergency Muster, in their own list under each muster point, with their own count. Never add the visitor count to the employee count - employees come from the clocking readers, visitors from security's check-in and check-out, and the two are not equally reliable. See the Time and Attendance guide.
Asking the AI Assistant
If you hold a Visitor Cards role (Visitor Viewer, Security or Visitor Admin), you can ask the AI Assistant questions such as:
- "Which visitors were on site yesterday?" or "Who visited the factory on 3 September?"
- "When was John Smith last on site?"
- "How many times has ABC Plumbing visited us this year?"
- "How many visitors did we have at the depot last week?"
The assistant only answers for companies where you hold the role, and it never shows a visitor's phone number, e-mail, ID digits or number plate. Records older than the retention period have been deleted, so it cannot find them. See the AI Assistant guide.
Visitor Register and settings (Visitor Admin)
- Search by visitor, company or host, a date range and a site (or All sites), or show only visitors on site, visitors still on site after their visit, visitors who left without sign-off or were evacuated, or records on legal hold.
- Find by vehicle registration - an exact match, for example in a theft investigation. Every lookup is written to the audit log.
- Reveal a stored phone number, e-mail address, ID digits or number plate. Each reveal is recorded (who looked at whose record, never the value) and limited to a few per hour.
- Legal hold keeps a record past the retention period, for example while an incident is investigated. Give the incident or case number. Remove the hold when it is over - if the retention period has passed, the record is deleted within 15 minutes.
- Correct a movement adds a correcting check-in or check-out with your reason. History is never edited.
- Erase deletes a visitor's record completely, for a POPIA request from the visitor.
- Settings (Administration → Visitor Cards → Settings), per company: retention (30 to 183 days; 183 to 366 at the high-risk sites you choose), whether every visitor needs an induction or host sign-off, whether sign-off is checked on every exit or only when leaving on the last day, the overdue time, the longest booking, the privacy notice and the Information Officer's contact details.
Something is not right
| What you see | Why, and what to do |
|---|---|
| No Visitor Cards menu | Your account is not yet approved, or Visitor Cards is switched off for your company. Ask your administrator. |
| Phone, e-mail and number plate boxes are missing | Encryption is not set up on the server, so those details cannot be stored. Book with names and share the pass. Tell your administrator. |
| "No current visit matches that pass" | Check the code. A pass only works around its visit dates, at the sites you look after, and not once the booking is cancelled. Record a walk-in if needed. |
| Check-out says the host has not signed off | Press Ask host or phone the number shown. Override with a reason only if the visitor must leave. |
| The guard was not told about a booking | The guard needs the Security role in that company, and either that site ticked on their user record or no site ticked at all. |
| A visitor is on the muster but has gone home | Security forgot to check them out. Security checks them out with the real time, or a Visitor Admin corrects the movement in the register. |
| Scan pass does nothing on the phone | Allow ThreadWare to use the camera in your phone's settings, or type the pass code. |
Related guides
- Time and Attendance - the emergency muster for employees.
- AI Assistant - asking about visitors.
- Administration - giving people roles and sites.
- All guides