Visitor Management and Access Control Integration Doing It Right Across Multiple Sites
You've got three office locations. A visitor shows up at the downtown site. Front desk prints a badge. That badge works at that building. Visitor drives to the suburban campus an hour later. Badge doesn't work. Front desk at site two has no idea who this person is. IT gets a ticket. Facilities calls you.
This happens because visitor management and access control live in separate worlds at most companies. The badge printer doesn't talk to the cloud access system. The visitor database doesn't sync with the door controller. Mobile credentials sit unused because nobody trained anyone on them.
When you're integrating visitor management with a multi-site access control platform like Brivo, UniFi Access, or even a simpler Schlage XE360 setup, the problem isn't the software. It's the network, the process, and the fact that nobody agreed on what "visitor" means.
The Real Cost of Siloed Systems
Let's start with what you're probably running now. Site A has badge stock from 2019. Site B switched to a newer reader three years ago but never migrated the database. Site C is still using proximity cards because nobody documented which system is which.
Visitor logs exist in three places: a spreadsheet at the front desk, a cloud platform that syncs once a day, and a badge printer that keeps its own count. When you need to audit who was in the building during an incident, you're manually cross-referencing.
Network bandwidth isn't the killer here. Visitor check-in happens maybe 20-30 times a day per site. Real-time lookups are small packets. The problem is latency and failover. If the cloud sync hiccups, does a visitor's badge work or not? If the WAN link to site two goes down, can the local door controller fall back to cached credentials? Most integrators don't ask this question until it breaks.
Your IT team also isn't equipped to troubleshoot visitor credential expiration, badge printer connectivity, or why a mobile credential revoked at 9 AM still worked at 9:15 AM. That's a facilities and access control problem. But when the door reader can't reach the cloud, IT gets blamed.
What a Multi-Site Visitor Workflow Actually Needs
Start with the network layer. Each site needs a local PoE switch with enough power budget for door controllers, readers, and potentially mobile credential readers. Brivo and similar platforms push credential updates via HTTPS to each site's local gateway or controller. That's outbound traffic, so firewalls usually allow it, but you need to account for it in your bandwidth planning.
A typical multi-site setup with 3-5 sites and 15-20 doors per site generates about 5-8 Mbps of consistent access control traffic (credential sync, video verification feeds, audit logs). Not huge, but if your WAN link is already saturated, adding this layer matters.
Next, VLAN segmentation. Visitor management devices (badge printers, check-in kiosks, mobile credential provisioning apps) should sit on the same VLAN as your access control readers and controllers. This keeps traffic local and reduces cloud latency. Don't put them on the general guest network. Your IT team will want them isolated anyway, so use a dedicated access control VLAN (VLAN 40-50 is common). That VLAN routes outbound to the internet for cloud sync, but inbound traffic from guest WiFi can't touch it.
Visitor data flow looks like this:
- Front desk checks in visitor in the cloud platform (Brivo, Salto, Genetec, etc.)
- System generates a temporary badge number or mobile credential
- Badge is printed or QR code is sent to visitor's phone
- Credential is pushed to all door readers at all sites (or just the sites the visitor needs)
- Reader caches the credential locally in case the cloud connection drops
- At end of shift or next day, credential auto-revokes
The catch: step 4 requires real-time sync across your WAN. If site two's link is congested, that credential might not reach the reader for 30 seconds to a minute. If you're relying on mobile credentials, the visitor's phone has to connect to WiFi or cellular to download the credential. Not all platforms handle offline mobile credentials well.
Badge vs Mobile Credentials at Multiple Sites
Physical badges are still the safest bet for visitor workflows. They don't require a smartphone, they're hard to lose accidentally, and they're instantly revoked when you collect them at checkout. Problem: you need badge stock at every site. A multi-site operation with poor inventory management ends up with 50 extra badges at site A and none at site C.
Mobile credentials (Apple Wallet, Google Wallet, proprietary apps) are faster to provision and easier to track. Visitor gets a text, taps a link, credential appears on their phone. No printing, no physical return. But your WiFi has to work, the credential server has to be responsive, and the door reader has to support it. Older Schlage XE readers don't. Newer ones do. Brivo supports it. UniFi Access is rolling it out.
For multi-site, the hybrid approach wins: mobile credentials for known, repeating visitors (contractors, consultants, delivery services). Physical badges for one-off visitors. Your front desk decides at check-in which method to use.
Network and Security Checkpoints
Firewall rules: Access control platforms need outbound HTTPS to their management cloud (typically port 443 to specific IP ranges published by the vendor). Inbound, you need nothing from the internet. Restrict inbound access to your local network only. Use your firewall's application-layer filtering to block unknown destinations from your access control VLAN.
UPS and failover: Each site should have a small UPS (1-2 kVA) backing up the PoE switch and local gateway. If the power dies, doors should remain in fail-safe mode (usually locked, or open, depending on your fire code). When power returns, the system re-syncs from the cloud in about 60 seconds.
Bandwidth per site: Budget 2-3 Mbps for baseline access control sync plus another 2-3 Mbps if you're pulling video verification feeds from integrated cameras at the door. If you have five sites, you're looking at 10-15 Mbps aggregate WAN traffic. Most companies have enough headroom here, but check your actual WAN utilization before committing.
Visitor data retention: Cloud platforms typically keep visitor logs for 90-365 days. Make sure your access control contract specifies this. If you need longer retention for compliance, you're looking at local NAS storage or a second backup system. That's an extra cost and another device to manage.
The Process Piece Nobody Talks About
Technology is the easy part. Process is where multi-site visitor management breaks.
Define a visitor lifecycle: check-in (who, when, which sites), credential provisioning (badge or mobile), credential revocation (end of shift, end of day, manual recall). Write it down. Train the front desk at all three sites the same way. Don't let site A make up their own rules.
Set up audit triggers. If a visitor credential is used after hours or at an unexpected location, log it. Review logs monthly. This isn't paranoia; it's compliance. If someone later claims they weren't in the building during an incident, you have proof.
Create a vendor escalation path. If the Brivo platform is down, who calls Brivo support? Not your front desk. Not your IT team alone. Assign one person per site who knows how to log into the vendor portal, check status, and communicate back to the team.
Quick Integration Checklist
- Audit current badge stock and reader types across all sites. Document which systems talk to each other and which don't.
- Map your WAN links. Note bandwidth, latency, and any known congestion points.
- Assign a VLAN for access control devices. Don't reuse a guest or general-purpose VLAN.
- Test mobile credential provisioning on your WiFi and cellular networks. Confirm readers support it.
- Set up local credential caching on door controllers so they work even if the cloud is unreachable for 5-10 minutes.
- Document the visitor check-in process and train all front desk staff the same way.
- Create a monthly audit report that pulls visitor logs, credential usage, and failed access attempts.
What Happens When You Get It Right
A visitor checks in at site A on Monday. Their temporary badge works at all five sites without delay. Tuesday morning, it auto-revokes. If they need access again Wednesday, the process takes two minutes instead of a phone call and a new badge print.
Your IT team doesn't get access control tickets every time the WAN hiccups because the system degrades gracefully. Your facilities team has one source of truth for who's in the building. Your compliance audit takes an afternoon instead of a week.
Integrating visitor management with multi-site access control isn't a one-time project. It's a network design problem, a process problem, and a training problem. Get the network layer right first. Then worry about the features.
If you're planning a multi-site rollout or inheriting a broken system, start by mapping your current state. Know your WAN, know your readers, know your process gaps. Then pick a platform (Brivo, UniFi Access, Genetec, Salto) that fits your scale and your IT team's comfort level. The platform matters less than the foundation.
Need help scoping a multi-site access control refresh? We can walk through your network, your sites, and your current pain points. Get in touch.