Skip to content

policy

Visitor Policy Template: 9 Sections Every Office Needs

The nine sections a workplace visitor policy needs, a copy-paste skeleton you can drop into your own document, and the parts most offices leave out.

By InstaCheckin Team Updated August 22, 2026

Most offices have a sign-in iPad and no visitor policy. The kiosk captures names all day, but nobody’s written down who’s allowed to be escorted, who can be left alone in a conference room, what the receptionist does when an unannounced contractor turns up at 6pm, or how long the log gets kept before it’s deleted.

That gap is what this post fills. Below are the nine sections a workplace visitor policy needs, a skeleton you can paste straight into your own document, and an honest note on the sections most offices skip.

One caveat up front. A policy nobody enforces at the door is worse than no policy, because it creates a written standard you’re visibly failing to meet. Write the version your front desk will actually follow on a busy Tuesday.

This post describes general practice and product capabilities. It is not legal advice — your obligations depend on your industry, jurisdiction, lease, and contracts. Verify with counsel before relying on any of it for a compliance decision.

Your sign-in log and your policy are two different controls

A sign-in system records what happened. A policy decides what’s allowed to happen. Auditors, insurers and landlords ask for the second one, and a screenshot of your visitor log doesn’t answer them.

Federal security frameworks treat the two as genuinely separate. NIST SP 800-53 Rev. 5 lists PE-8, “Visitor Access Records,” as its own control, sitting next to PE-2 and PE-3, which cover who’s authorised to enter a facility and how that authorisation gets verified at the door. The log is evidence. The authorisation rules are policy. Losing one doesn’t help you produce the other.

CISA’s Interagency Security Committee best practice on facility access control draws the same line for federal buildings: entry requirements are defined in advance, then applied consistently to everyone who shows up. That’s the shape you’re copying, scaled down to one lobby.

The 9 sections every visitor policy needs

#SectionThe question it has to answer
1Scope and definitionsWho counts as a visitor? Contractors, vendors, interview candidates, delivery drivers, staff from another site, family — name them or you’ll argue about it at the desk.
2Pre-approval and pre-registrationWhich visits need a host to register them in advance, and which can walk up?
3Identification at sign-inName, company, host, purpose — and whether photo ID gets checked, and by whom.
4BadgesWho issues them, whether the badge must be visible, and — the one everyone forgets — how it’s returned.
5Escorts and restricted areasWhich zones require a named escort, and who’s accountable if the visitor wanders.
6Agreements signed at the doorNDA, safety briefing, site rules, photography ban. What gets signed, by whom, and where it’s stored.
7Emergency procedureHow visitors are included in the headcount at the assembly point.
8Data retentionHow long visitor records are kept, who can see them, and when they’re deleted.
9Enforcement and reviewWho owns the policy, how exceptions get logged, and the review date.

Sections 4, 7 and 8 are the ones offices skip, and they’re the three most likely to be tested. Badge return is a physical-security gap; the emergency headcount is a life-safety gap; retention is a privacy gap. Our guide to building an emergency evacuation plan goes deeper on the headcount piece.

Copy-paste visitor policy template

Drop this into a doc, replace the bracketed parts, and delete what doesn’t apply. Keep it to two pages — nobody reads four.

[COMPANY NAME] VISITOR POLICY
Owner: [role] | Effective: [date] | Next review: [date + 12 months]

1. PURPOSE AND SCOPE
This policy governs all non-employees entering [site]. "Visitor" includes
guests, contractors, vendors, delivery personnel, interview candidates,
auditors, and employees visiting from another location.

2. PRE-APPROVAL
Hosts must pre-register visitors at least [24 hours] in advance for
[restricted areas / group visits / contractor work]. Walk-in visitors are
permitted in [lobby, meeting rooms] only, subject to host availability.

3. SIGN-IN
Every visitor signs in at the front desk on arrival and records name,
company, host, and purpose of visit. [Photo ID is checked for: ___.]
Visitors who decline to sign in are not admitted past reception.

4. BADGES
Visitors are issued a badge showing name, [photo,] host, and date. Badges
are worn visibly at all times and surrendered at sign-out. A badge not
returned by [end of business] is reported to [role].

5. ESCORT AND ACCESS
Unescorted: [lobby, reception, meeting rooms].
Escorted by host: [general office floors].
Escorted, host named on the log: [server room, production floor,
controlled-technology areas].

6. AGREEMENTS
Visitors of type [___] sign [NDA / safety acknowledgement / site rules]
before a badge is issued. Signed documents are retained with the visit
record for [retention period].

7. EMERGENCY PROCEDURES
On an alarm, visitors evacuate with their host to [assembly point].
[Role] pulls the current on-site visitor list and confirms every signed-in
visitor is accounted for before reporting all clear.

8. DATA AND RETENTION
Visitor records are stored [where] and accessible to [roles]. Records are
retained for [12 months] and then deleted. Visitors may request a copy of
their record by contacting [email].

9. ENFORCEMENT AND EXCEPTIONS
[Role] owns this policy. Exceptions require approval from [role] and are
logged. Failure to follow it is addressed under [HR / contractor policy].
This policy is reviewed annually.

What regulators actually require in writing

No single US rule says “publish a visitor policy.” Several rules require pieces of one, which is why the finished document usually stitches together obligations from three or four places.

Section 7 exists because of OSHA’s Emergency Action Plan standard, 29 CFR 1910.38, which requires written procedures to account for everyone after an evacuation. Section 3 and section 4 get sharper teeth at logistics and manufacturing sites: CBP’s CTPAT Minimum Security Criteria require visitors to present photo identification on arrival, be logged, be issued temporary identification, and have procedures covering badge removal. California employers picked up another one on July 1, 2024, when Cal/OSHA’s workplace violence prevention requirements for general industry took effect and made a written prevention plan mandatory for most workplaces — front-desk procedures land squarely inside it.

Section 8 is where privacy law shows up. The ICO’s guidance on the data minimisation principle is blunt that you must not collect or keep personal data on the off-chance it becomes useful later. Applied to a lobby, that’s an argument for asking fewer questions at sign-in and setting a real deletion date — not for keeping every badge photo forever because storage is cheap. Retention obligations vary by jurisdiction and industry; this is not legal advice.

Three mistakes that make a visitor policy useless

Writing it for the auditor instead of the receptionist. If the person on the desk can’t apply a rule in four seconds while someone’s standing in front of them, the rule doesn’t exist. Escort tiers beat prose paragraphs.

No named owner. A policy with a committee behind it goes stale in about two reorganisations. Put one role in the header and a review date twelve months out.

A policy the sign-in process contradicts. This is the common one. The policy says every visitor signs an NDA and wears a photo badge; the paper sign-in sheet at the desk has six columns and no way to do either. Either soften the policy or change the process — leaving them out of sync means the written standard is the one you lose on. If you’re still deciding what the process should be, our explainer on what a visitor management system does covers the mechanics.

Make the policy the thing that actually happens at the door

A written policy is only as good as the sign-in flow enforcing it, and that’s the part software is genuinely good at. On an iPad sign-in kiosk, InstaCheckin captures the visitor’s details and photo, shows the NDA or safety waiver on screen and takes a signature before the badge prints, prints an adhesive badge with the visitor’s name, photo, host and date on a Brother QL label printer, and emails and texts the host the moment their guest arrives. Sections 3 through 6 of the template stop depending on whether anyone remembered.

Section 7 gets easier too: every visit is stored in the cloud with timestamps, so the current on-site list is a filter away rather than a binder someone has to run outside with. Exports to CSV or PDF handle the audit request.

Start a free trial and set the kiosk up against your own policy — you’ll find the sections that don’t survive contact with a real front desk faster than any review meeting will.

Frequently asked questions

What should a visitor policy include?
Nine things: scope and definitions, pre-approval rules, what identification is required at sign-in, badge issue and return, escort and restricted-area rules, any agreements signed at the door, emergency headcount procedure, data retention, and who enforces and reviews the policy. The sections most often missing are badge return and retention — both are the ones an auditor asks about first.
Is a written visitor policy legally required?
There's no single federal rule that says 'you must publish a visitor policy.' Several rules require pieces of one. OSHA's Emergency Action Plan standard requires written procedures to account for everyone after an evacuation, CBP's CTPAT Minimum Security Criteria require visitor identification and logging for participating importers and carriers, and California's SB 553 requires a written workplace violence prevention plan for most employers. This is product and general information, not legal advice — check your own obligations with counsel.
How long should we keep visitor records?
Long enough to answer 'who was in the building on this date,' and no longer. A common default for a general office is 12 to 24 months; regulated sites usually retain longer under a specific obligation. Under UK and EU data protection rules the ICO's data minimisation guidance says you shouldn't retain personal data on the off-chance it becomes useful, so pick a period, write it in the policy, and delete on schedule.
Do visitors have to be escorted at all times?
That depends on the area, not the person. Most offices run a tiered rule: lobby and meeting rooms unescorted, everything past the badge-controlled door escorted, and specific zones — server rooms, production floors, controlled-technology areas — escorted with a named host who signs for the visit. Write the tiers into the policy rather than leaving it to whoever's on the desk that morning.
Who should own the visitor policy?
One named role, not a committee. In most offices it's facilities or office management, with security and legal as reviewers. The owner's real job is the annual review and the exception log — a policy with no owner drifts out of date within about two reorganisations and nobody notices until an incident.

Related reading

Ready when you are

Try InstaCheckin on your iPad — free