Full-Stack + Zero-Trust Security + Platform
Multi-Site Visitor Management Platform
Architected and built a visitor management platform for a multi-site organization, replacing manual sign-in with a governed approval workflow, fast unattended kiosks, and a complete audit record.
Sub-second kiosk check-in and checkout
Manual sign-in replaced with a governed approval workflow
Complete auditable record of visits and data access
Personal data collection scoped to what each classification requires
The problem
Visitor tracking across several sites was manual and inconsistent, which caused two separate problems at once. Operationally, whether a visitor got in depended on finding the right person to approve it, and afterwards nobody could say with confidence who had been where. Legally, the organization was collecting personal information on paper with no control over who could read it and no reliable way to dispose of it. Any replacement had to route each visit to the correct approver based on how sensitive it was, protect the data it collected, and still be fast enough that a visitor standing at a kiosk is not left waiting.
What I built
Built a three-tier system where the public kiosk surface, the application logic, and the data are separated by trust level rather than only by layer. Visits route to an approver based on classification, and the classification also decides what personal information gets collected in the first place, so the system holds less data instead of merely guarding more of it. Approved visitors receive a credential the kiosk verifies on its own, which is what keeps check-in fast, since the kiosk confirms the credential locally rather than asking a server whether it is still good.
Technical approach
- The application tier is stateless, so serving more kiosks and more concurrent approvers is a matter of running more instances rather than redesigning anything
- Kiosk credentials are verified cryptographically on the device, which takes a network round trip out of the critical path and is what makes check-in feel instant
- The public kiosk surface is rate limited and treated as untrusted, since by definition it is reachable by people who have not authenticated yet
- Personal information is encrypted at the field level and collected conditionally by classification, so exposure scales with sensitivity rather than with volume
- Tokens are scoped so a credential issued for one surface cannot be replayed against another, which matters most for the surfaces that are physically accessible to anyone walking past
- Every visit and every access to visitor data is recorded, because an audit trail retrofitted later is never complete
- Schema changes ship without downtime, which was a hard requirement given kiosks that are in use during business hours