Manav.id
Compliance · 4 min read

Visitor access and insider threat programs: the escort who was never assigned

Visitor access and insider threat programs: the escort who was never assigned

Visitor management systems record intent at the front desk. What happens over the following four hours — who actually walked the visitor where — is a verbal arrangement between colleagues.

Who escorted the visitor, and can you prove it?

An escort is assigned in a visitor management system and handed over informally on the floor. The record names whoever was assigned at check-in, not whoever was actually walking with the visitor at 14:20 — which is the question an insider threat programme needs answered.

Key takeaways
  • Visitor systems capture check-in intent. Escort handover is verbal, which means the escort of record and the escort present diverge routinely.
  • Insider threat programme obligations put facility access governance in scope without prescribing how escort responsibility is evidenced.
  • This is graded C: incident data is not public, and the cost case has to be built from a facility's own investigation time.

The gap between the badge and the afternoon

Visitor checks inescort assignedrecordedEscort has a meetinghands over informallyunrecordedSecond escort continuesnot in the systeminvisibleIncident reviewnames the first escortwrong person
The handover is the normal, necessary part. The record simply does not follow it.

A visitor arrives at 09:15. Reception verifies identity, checks the visit request, prints a badge, and records the sponsoring employee and the assigned escort. All of that is captured accurately.

At 10:40 the escort is pulled into a meeting and asks a colleague to cover. At 13:00 the visitor moves to a different building with a third person. At 15:30 they leave, and the system records departure against the original escort.

Nobody did anything wrong. The record is now a description of the morning's intent rather than of the day.

What the obligations require

Insider threat programme requirements for cleared contractors address programme establishment, training, reporting and access governance. Facility security requirements address visitor control and the escort of uncleared persons in limited and closed areas.

The requirements assume escort responsibility is known. They do not prescribe how a transfer of that responsibility is recorded, because in a paper-and-logbook environment the transfer was rare and visible.

Why this is graded conservatively

Three honest limitations, and they are the reason this record sits in the frontier set rather than the core portfolio.

What a facility can do is measure its own: over one month, ask escorts to report handovers informally. The number will be higher than the security office expects, and it costs nothing to find out.

The Escort Handover Receipt

Make the transfer of responsibility a signed act rather than a verbal one.

{
  "type": "manav-stmt/1",
  "action": "escort_handover",
  "visit": "[visit id]  Visitor: [name]",
  "from_escort": "[credential assertion]",
  "to_escort": "[credential assertion]",
  "location": "[area]",
  "at": "[timestamp]"
}

Two gestures, a few seconds, on phones the escorts already carry. The record now reflects who held responsibility at each point rather than who was assigned at 09:15.

The friction test

This lives or dies on whether escorts will do it. So measure before deploying:

  1. Time the handover gesture on the devices staff actually carry, in a corridor rather than at a desk.
  2. Estimate handovers per day from the informal survey above.
  3. Multiply. If the total is minutes per day across a facility, it is negligible. If it is materially more, the design is wrong.
  4. Check whether phones are permitted in the areas where handovers occur. In many cleared facilities they are not, which may make this undeployable — and that is worth discovering before procurement rather than after.

That last point is a genuine blocker in a meaningful share of facilities, and any vendor who has not raised it has not thought about the environment.

What it would improve

Investigation time, primarily. A security incident involving a visitor currently begins by establishing who was with them, which means interviewing people about a Tuesday three weeks ago.

It also improves the position of the escorts themselves, who are currently named in a record describing a responsibility they may have handed over in good faith and cannot demonstrate handing over.

Why handover is the gap, not assignment

What each record actually establishes
RecordEstablishes
Check-in entryA visitor entered and an escort was nominated
Badge swipesDoors opened, by whichever badge
Check-out entryA visitor left
Escort at a given momentNothing

Objections and honest limits

“Our escort policy prohibits informal handover.” It does, and handovers happen because escorts have other work. A policy that operations must violate to function produces no record of the violation.

“Badge data reconstructs it.” It shows which badges opened which doors. In an escorted visit both parties move together, so the data is consistent with several different escorts.

Making escort custody continuous

  1. Treat handover as a first-class event. Rather than something the policy pretends does not happen.
  2. Sign the handover, both parties. Outgoing and incoming escort, one gesture each.
  3. Bind it to the visitor and the area. So the record answers who, with whom, where.
  4. Reconcile at check-out. An unclosed custody chain is the signal.

Terms used here

Escort
A cleared individual responsible for an uncleared visitor's movement and conduct within a controlled area.
Custody chain
The unbroken sequence of responsible individuals over a period, each handover recorded.
Insider threat programme
The required programme for identifying and mitigating risk from trusted individuals, which depends on being able to attribute presence and action.

Frequently asked questions

Why is this graded C? Because prevalence and harm data are unavailable, and in cleared environments they are frequently unshareable. The mechanism is simple; the business case must be built locally.

What if phones are prohibited in the area? Then this is undeployable there, and that should be established before any procurement. It is a common condition and it is a genuine blocker.

Does this replace the visitor management system? No. It records handovers the system does not capture, alongside it.

How would a facility justify it? From its own investigation time and its own handover frequency, both of which it can measure this month at no cost.

Why isn't the check-in record enough? It names who was nominated at the door. Handovers happen during the visit and are the thing an incident review needs to reconstruct.

Can badge data reconstruct escort custody? No. In an escorted visit both parties move together, so the badge trail is consistent with several possible escorts.

What should the handover record contain? Outgoing escort, incoming escort, the visitor, the area and the time — signed by both parties.

Where this fits in Manav

Manav binds the authorising individual to the exact access or release being authorised, and produces a receipt a prime, a government customer or an investigator can verify without access to the contractor's systems.

See access receipts →

Sources and further reading