All resources
Operations
30 June 2026 · 6 min read

Visitor management: what actually improves society security

Why the gate register fails, what approval flow actually works, and the privacy obligations a society takes on when it starts recording visitors.

Written by the Societly team

Last verified 28 July 2026


Almost every society has a visitor register at the gate. Almost none of them would help after an incident. The handwriting is illegible, the phone numbers are invented, nobody verifies anything, and the one page you need is in a book that was replaced in March.

The register is not the problem, though. The problem is that it records entry after the decision to admit has already been made by a guard with no information.

What the gate actually has to handle

A workable system has to cover five quite different cases. Most fail on the last two.

CaseVolumeWhat "good" looks like
Expected guestLowResident pre-authorises; guard confirms and admits
Unexpected guestMediumGuard notifies resident, waits for approval
DeliveryVery highFast, low-friction, no resident interruption where possible
Domestic help / staffHigh, recurringRecognised on arrival, attendance recorded, not re-approved daily
Cab / service vehicleMediumLogged with vehicle number, time-boxed

A system that handles guests beautifully and treats forty daily deliveries as forty approval requests will be abandoned within a month — by the guards first, then by everyone. Delivery volume is the load-bearing case.

The approval flow that works

For an unexpected visitor:

  1. Guard enters the visitor's name and the flat being visited.
  2. The resident is notified immediately, on their phone, with the visitor's

name and photo.

  1. Resident approves or denies in one tap.
  2. If there is no response within a set window, the guard follows a written

fallback rule — not their own judgement.

Step 4 is the one societies forget to define, and it is where every dispute originates. Write the rule down: what does the guard do at 11pm when a visitor claims to be the resident's brother and the resident does not answer? "Use discretion" is not a rule; it is how a guard ends up personally blamed.

For an expected guest, the resident generates a pass in advance — ideally a code or QR the guest shows at the gate. This is the flow that actually reduces gate friction, because it moves the decision to before the visitor arrives.

Deliveries: optimise for throughput

Treat deliveries as a distinct category with its own rules, decided by the general body:

  • Delivery to the gate, collected by the resident. Highest security, most

friction, generates parcel-storage load.

  • Delivery to the door, logged at the gate. Lower friction, requires

recording who entered and when.

  • Approved partners to the door, others to the gate. A reasonable middle

position that most societies converge on.

Whichever you choose, log the delivery agency, the flat, and the time in and out. The value is not preventing anything — it is being able to answer, three days later, who came to flat B-704 on Tuesday evening.

Parcel handling deserves its own decision. A gate that accepts parcels on behalf of residents has taken on custody of them, and "the guard lost my package" is a grievance that lands on the committee. Either record parcel receipt and handover properly, or do not accept them.

Domestic help and staff

Recurring staff should not go through visitor approval every single day. They should be registered once — with the resident's authorisation — and then simply recognised at the gate, with entry and exit times recorded.

That record has a second use: it becomes an attendance log, which resolves the most common household dispute in an apartment building without anyone having to take a side.

Verification of staff — police verification, ID on file — is a matter for the society's own policy and the applicable local rules. Two things are worth noting: the obligation to verify usually sits with the employer, which is the resident and not the society, and a society that collects verification documents has taken custody of sensitive personal data and must protect it accordingly.

The privacy obligations you take on

The moment a society starts recording visitors' names, phone numbers, photos and vehicle numbers, it is processing personal data about people who are not its members and who had little practical choice about it. Under India's Digital Personal Data Protection framework, that carries real obligations.

Practical minimums:

  • Collect only what you need. A visitor's name, the flat visited, and time

in/out is usually sufficient. A photograph of every delivery agent is harder to justify.

  • Set a retention period and honour it. Visitor logs kept forever are a

liability, not an asset. Decide — 90 days, 12 months — and delete automatically after.

  • Restrict who can read them. A guard needs today's log. A committee member

investigating an incident needs a specific window. Neither needs the full history of who visited every flat, and residents should certainly not be able to browse each other's visitors.

  • Say what you do. A notice at the gate stating that entries are recorded,

why, and for how long, costs nothing.

  • Treat CCTV separately. Camera footage has its own retention, access and

signage considerations, and is frequently the subject of member requests.

Societies rarely think of themselves as data processors. Legally, once they run a digital gate, that is broadly what they are — and the access-control question ("who in this society can see which resident's visitor history?") is the one most systems answer badly.

What to measure

If you want to know whether the gate is actually working:

  • Median approval time for an unexpected visitor. If it is over two minutes,

guards will start bypassing the system.

  • Percentage of entries logged against a manual count on a sample day. This

is the honest adoption number.

  • Unresolved entries — visitors logged in with no exit recorded. A high

figure means the exit flow is broken, which makes the whole log unreliable.

  • Deliveries per day. Usually far higher than committees estimate, and the

number that should drive the design.

The uncomfortable conclusion

Most gate security failures are process failures, not technology failures. A society with a written escalation rule, a guard who has been trained on it, and a log that can be searched will outperform a society with better software and none of those things.

The software's job is narrow: make the fast path fast enough that nobody works around it, and make the record searchable when it matters. Everything else is the committee's decision to make and write down.

Related: what transparent society accounts look like — the same access-control question applies to financial data, and choosing society management software for the data-handling questions worth asking any vendor.

Run your society on Societly

Billing, UPI collections, visitors, complaints and accounts in one place. Free forever for societies up to 25 units — no contract, no setup fee.