policy
Visitor Policy Template: 9 Sections Every Office Needs
The nine sections a workplace visitor policy needs, a copy-paste skeleton you can drop into your own document, and the parts most offices leave out.
By InstaCheckin Team Updated August 22, 2026
Most offices have a sign-in iPad and no visitor policy. The kiosk captures names all day, but nobody’s written down who’s allowed to be escorted, who can be left alone in a conference room, what the receptionist does when an unannounced contractor turns up at 6pm, or how long the log gets kept before it’s deleted.
That gap is what this post fills. Below are the nine sections a workplace visitor policy needs, a skeleton you can paste straight into your own document, and an honest note on the sections most offices skip.
One caveat up front. A policy nobody enforces at the door is worse than no policy, because it creates a written standard you’re visibly failing to meet. Write the version your front desk will actually follow on a busy Tuesday.
This post describes general practice and product capabilities. It is not legal advice — your obligations depend on your industry, jurisdiction, lease, and contracts. Verify with counsel before relying on any of it for a compliance decision.
Your sign-in log and your policy are two different controls
A sign-in system records what happened. A policy decides what’s allowed to happen. Auditors, insurers and landlords ask for the second one, and a screenshot of your visitor log doesn’t answer them.
Federal security frameworks treat the two as genuinely separate. NIST SP 800-53 Rev. 5 lists PE-8, “Visitor Access Records,” as its own control, sitting next to PE-2 and PE-3, which cover who’s authorised to enter a facility and how that authorisation gets verified at the door. The log is evidence. The authorisation rules are policy. Losing one doesn’t help you produce the other.
CISA’s Interagency Security Committee best practice on facility access control draws the same line for federal buildings: entry requirements are defined in advance, then applied consistently to everyone who shows up. That’s the shape you’re copying, scaled down to one lobby.
The 9 sections every visitor policy needs
| # | Section | The question it has to answer |
|---|---|---|
| 1 | Scope and definitions | Who counts as a visitor? Contractors, vendors, interview candidates, delivery drivers, staff from another site, family — name them or you’ll argue about it at the desk. |
| 2 | Pre-approval and pre-registration | Which visits need a host to register them in advance, and which can walk up? |
| 3 | Identification at sign-in | Name, company, host, purpose — and whether photo ID gets checked, and by whom. |
| 4 | Badges | Who issues them, whether the badge must be visible, and — the one everyone forgets — how it’s returned. |
| 5 | Escorts and restricted areas | Which zones require a named escort, and who’s accountable if the visitor wanders. |
| 6 | Agreements signed at the door | NDA, safety briefing, site rules, photography ban. What gets signed, by whom, and where it’s stored. |
| 7 | Emergency procedure | How visitors are included in the headcount at the assembly point. |
| 8 | Data retention | How long visitor records are kept, who can see them, and when they’re deleted. |
| 9 | Enforcement and review | Who owns the policy, how exceptions get logged, and the review date. |
Sections 4, 7 and 8 are the ones offices skip, and they’re the three most likely to be tested. Badge return is a physical-security gap; the emergency headcount is a life-safety gap; retention is a privacy gap. Our guide to building an emergency evacuation plan goes deeper on the headcount piece.
Copy-paste visitor policy template
Drop this into a doc, replace the bracketed parts, and delete what doesn’t apply. Keep it to two pages — nobody reads four.
[COMPANY NAME] VISITOR POLICY
Owner: [role] | Effective: [date] | Next review: [date + 12 months]
1. PURPOSE AND SCOPE
This policy governs all non-employees entering [site]. "Visitor" includes
guests, contractors, vendors, delivery personnel, interview candidates,
auditors, and employees visiting from another location.
2. PRE-APPROVAL
Hosts must pre-register visitors at least [24 hours] in advance for
[restricted areas / group visits / contractor work]. Walk-in visitors are
permitted in [lobby, meeting rooms] only, subject to host availability.
3. SIGN-IN
Every visitor signs in at the front desk on arrival and records name,
company, host, and purpose of visit. [Photo ID is checked for: ___.]
Visitors who decline to sign in are not admitted past reception.
4. BADGES
Visitors are issued a badge showing name, [photo,] host, and date. Badges
are worn visibly at all times and surrendered at sign-out. A badge not
returned by [end of business] is reported to [role].
5. ESCORT AND ACCESS
Unescorted: [lobby, reception, meeting rooms].
Escorted by host: [general office floors].
Escorted, host named on the log: [server room, production floor,
controlled-technology areas].
6. AGREEMENTS
Visitors of type [___] sign [NDA / safety acknowledgement / site rules]
before a badge is issued. Signed documents are retained with the visit
record for [retention period].
7. EMERGENCY PROCEDURES
On an alarm, visitors evacuate with their host to [assembly point].
[Role] pulls the current on-site visitor list and confirms every signed-in
visitor is accounted for before reporting all clear.
8. DATA AND RETENTION
Visitor records are stored [where] and accessible to [roles]. Records are
retained for [12 months] and then deleted. Visitors may request a copy of
their record by contacting [email].
9. ENFORCEMENT AND EXCEPTIONS
[Role] owns this policy. Exceptions require approval from [role] and are
logged. Failure to follow it is addressed under [HR / contractor policy].
This policy is reviewed annually.
What regulators actually require in writing
No single US rule says “publish a visitor policy.” Several rules require pieces of one, which is why the finished document usually stitches together obligations from three or four places.
Section 7 exists because of OSHA’s Emergency Action Plan standard, 29 CFR 1910.38, which requires written procedures to account for everyone after an evacuation. Section 3 and section 4 get sharper teeth at logistics and manufacturing sites: CBP’s CTPAT Minimum Security Criteria require visitors to present photo identification on arrival, be logged, be issued temporary identification, and have procedures covering badge removal. California employers picked up another one on July 1, 2024, when Cal/OSHA’s workplace violence prevention requirements for general industry took effect and made a written prevention plan mandatory for most workplaces — front-desk procedures land squarely inside it.
Section 8 is where privacy law shows up. The ICO’s guidance on the data minimisation principle is blunt that you must not collect or keep personal data on the off-chance it becomes useful later. Applied to a lobby, that’s an argument for asking fewer questions at sign-in and setting a real deletion date — not for keeping every badge photo forever because storage is cheap. Retention obligations vary by jurisdiction and industry; this is not legal advice.
Three mistakes that make a visitor policy useless
Writing it for the auditor instead of the receptionist. If the person on the desk can’t apply a rule in four seconds while someone’s standing in front of them, the rule doesn’t exist. Escort tiers beat prose paragraphs.
No named owner. A policy with a committee behind it goes stale in about two reorganisations. Put one role in the header and a review date twelve months out.
A policy the sign-in process contradicts. This is the common one. The policy says every visitor signs an NDA and wears a photo badge; the paper sign-in sheet at the desk has six columns and no way to do either. Either soften the policy or change the process — leaving them out of sync means the written standard is the one you lose on. If you’re still deciding what the process should be, our explainer on what a visitor management system does covers the mechanics.
Make the policy the thing that actually happens at the door
A written policy is only as good as the sign-in flow enforcing it, and that’s the part software is genuinely good at. On an iPad sign-in kiosk, InstaCheckin captures the visitor’s details and photo, shows the NDA or safety waiver on screen and takes a signature before the badge prints, prints an adhesive badge with the visitor’s name, photo, host and date on a Brother QL label printer, and emails and texts the host the moment their guest arrives. Sections 3 through 6 of the template stop depending on whether anyone remembered.
Section 7 gets easier too: every visit is stored in the cloud with timestamps, so the current on-site list is a filter away rather than a binder someone has to run outside with. Exports to CSV or PDF handle the audit request.
Start a free trial and set the kiosk up against your own policy — you’ll find the sections that don’t survive contact with a real front desk faster than any review meeting will.
Frequently asked questions
What should a visitor policy include?
Is a written visitor policy legally required?
How long should we keep visitor records?
Do visitors have to be escorted at all times?
Who should own the visitor policy?
Related reading
Emergency Evacuation Plan: The 8 Essential Elements (2026 Guide)
A practical guide to building an emergency evacuation plan: the 8 elements OSHA expects, evacuation types, roles, routes, and how to account for every visitor and employee during a drill or real event.
Visitor Sign-In Sheet Template (Free Word + PDF Download)
Free visitor sign-in sheet template in Word and PDF, the columns it should include, and an honest read on when paper works vs. when to upgrade to digital.
What Is a Visitor Management System? Plain-English Guide
A plain-English explainer of what a visitor management system is, its 8 core features, the common deployment patterns, and what it is not.