Hauliers and delivery drivers
A few minutes, usually confined to the yard or the dock, rarely any need to enter production. Speed is what counts: a handful of essential fields, the reference for the load, done.
On an ordinary working day, far more people walk through your gates than appear in anyone’s calendar: the technician servicing a compressor, the crew rewiring a line, the driver unloading at the dock, the manufacturer’s engineer updating a machine. These are not courtesy visits — these are people working inside your premises. This guide covers what to record at the gate, what stays outside the log, and how to keep a searchable record without slowing the front desk down.
In short
A contractor and supplier access log answers one very practical question at any moment: who is on site, on behalf of which company, working with whom, and since when? Reception needs it daily, the health and safety lead needs it in an emergency, and operations needs it when an access has to be reconstructed months later.
Signing in an external company is not the same as receiving a guest: different fields matter, different people need to be told, and the length of stay is entirely different. In IRIGuest the registration questions are configurable, so contractors and guests can follow different paths from the very first tap on the tablet.
In manufacturing companies the flow of external firms is almost always heavier than genuine visitor traffic — and far less governed. A guest is expected: somebody invited them, somebody greets them. The technician called in on a Friday afternoon, by contrast, arrives when they arrive, and finds a sheet of A4 at the gate with four columns, filled in by whoever happens to be passing.
Anyone who has tried to reconstruct an access knows the result: unreadable names, company names abbreviated at random, exit times that were never written down. As long as nothing happens, the sheet is fine. When it genuinely matters — an evacuation, an audit, a dispute — it answers none of the questions being asked of it.
This page is a practical guide to the access process, not health and safety advice. If the question you actually have is the one upstream — whether a visitor log is legally required — we have covered that in a dedicated guide, alongside the rest of our visitor log guides.
The convenient label “external companies” covers very different groups: they stay for different lengths of time, come in through different gates, and need to be told different things. Separating them is the first step towards deciding what is worth asking at the gate.
A few minutes, usually confined to the yard or the dock, rarely any need to enter production. Speed is what counts: a handful of essential fields, the reference for the load, done.
They arrive on call, sometimes outside working hours, and work on plant or machinery. What matters is who called them in, what they are working on, and how long they stay.
The most sensitive group: several people, several days, defined work areas. Here access traceability meets the coordination duties that apply when firms share a workplace.
They come often and, over time, become familiar faces. That familiarity is precisely the risk: people stop signing them in, and the log stops telling the truth.
Four groups, four different needs. A single form that asks everyone the same questions ends up asking too much of the person in a hurry and too little of the crew that stays a week.
The difference is not a formality. A guest is greeted, escorted and walked back out: somebody is responsible for them for the whole visit. An external company, by contrast, works — often unaccompanied, in technical areas, with its own equipment, sometimes at hours when reception is not staffed at all.
That changes three very concrete things. First, who needs to know the person has arrived: not a generic “host”, but the manager who commissioned the work. Second, how long the presence counts as open: a visit lasts an hour, an intervention can last three days. Third, what you need afterwards: nobody goes back looking for a guest, but technical accesses do get looked up, often months later.
And then there is the reason nobody enjoys discussing, which is the real purpose of a log in the first place. If the evacuation alarm goes off tomorrow morning, the assembly point has to be able to account for people who are not on your payroll. A list that leaves them out is not an attendance list — it is half a list, and in an emergency half a list is worth very little.
This connects to a second question we handle elsewhere: how to keep these records separate from your own employees’ attendance. The guide on visitor logs and employee attendance explains why the two tools should stay apart instead of forcing one to do both jobs.
There is no list that works for every company: it depends on the site, on the work carried out there and on internal procedures. One simple principle always applies, though, and it is also a data protection principle: collect what serves a defined purpose, not what “might come in handy”. Every extra field costs time at the gate and creates one more record to look after.
| Field | What it is genuinely for | How common |
|---|---|---|
| Full name | Knowing which person is inside, not just which company sent someone | Essential |
| Employer / company | Linking the person to the contract and to the right internal contact | Essential |
| Internal host or requester | Knowing who inside the company commissioned or authorised the work | Essential |
| Time in and time out | Reconstructing actual presence — the field that paper almost always misses | Essential |
| Reason for access | Telling a delivery apart from a service call apart from a site job | Common |
| Destination area | Knowing where to look for the person in an emergency | Common |
| Vehicle registration | Useful wherever vehicles enter the yard or loading is involved | Common |
| Acknowledgement of site rules | Documenting that safety information was handed over | Judgement call |
| Identity document | Rarely necessary: ask only where an internal procedure genuinely requires it | Judgement call |
Once the fields are chosen, the real battle is consistency: the same data, in the same format, at every entry and at every gate. That is exactly what a sheet of paper cannot guarantee and a tablet can, because required fields stay required at six o’clock on a Friday too.
It is worth putting the three situations side by side: the differences become obvious, and they suggest three distinct sign-in paths on their own, rather than one form that half suits everybody.
| Aspect | Guest / visitor | Contractor | Delivery driver |
|---|---|---|---|
| Why they come | They were invited | To carry out work | To deliver or collect goods |
| How long they stay | An hour, a few hours | Hours, days, sometimes weeks | A few minutes |
| Where they go | Meeting rooms, offices | Production, plant, technical areas | Dock, yard |
| Who is responsible | Whoever invited them | The manager owning the job | The warehouse |
| Most important field | Who they are meeting | Company and internal requester | Reference for the load |
| Check-out | Useful | Indispensable | Often automatic or untracked |
| History | Rarely read again | Read again months later | Matters to logistics |
Setting up three separate paths does not make reception’s job harder — it makes it simpler. Someone dropping off a parcel answers three questions; someone opening a work site answers a few more, and neither fills in fields that do not concern them. For how this plays out on a production site with several gates, the subject is picked up on the page about visitor management in factories.
Here is something software vendors usually prefer not to say. An access log records who comes in and when: it is one component of the process, not the whole process. Before the gate opens there are checks and obligations that live elsewhere — in contracts, in coordination documents, in health and safety procedures — and no visitor log replaces them.
That said, the part the log does cover is the one that works worst in practice: the trail of who came in. It is also the only part you will be asked to produce when somebody says “who was in the plant on 12 March?”
The paper contractor sheet has one undeniable quality: it costs nothing and works during a power cut. It also has three weaknesses, and they all show up together at the worst possible moment — which is to say, when it is actually needed.
The first is legibility: a hurried signature at the end of a shift is unreadable forever. The second is incompleteness: on paper, the exit time is missing from every other row, because nobody walks back to the gate to announce that they are leaving. The third, and the most serious, is that the sheet shows every signatory the details of everyone before them — names, companies, times, reasons for the visit, on display to anyone passing the gate.
What works on paper
What stops working
This is not an argument against paper as such — we devoted a whole guide to the comparison between paper, Excel and software, and for a small site paper may still be enough. It is an argument about volume: above a certain number of technical accesses, the sheet stops being a log and becomes a pile of sheets.
Setting this up takes half a day of thinking and a few minutes of configuration. The real work is deciding who gets asked what — the technical part comes afterwards.
The registration questions are configurable: a short path for deliveries and a fuller one for technical work, so each person only fills in what concerns them.
Notices and consents are customisable and signed directly on the screen, so there is a record of what was shown and to whom — with no sheets left to file.
A temporary badge with name and company makes external personnel identifiable at a glance. Our visitor badge guide covers what to print on it; the free generator produces them ready to print.
In the Cloud version the person who commissioned the work is notified on arrival: nobody is left waiting at the gate, and nobody comes on site without someone knowing.
The full flow, step by step, is described on the page about how visitor registration works. For external companies the content of the questions changes, not the mechanics: a tablet at the gate, self-service sign-in, everything else automatic.
On production sites the problem is rarely one gate: it is three. The office entrance, the goods gate, the vehicle access to the shop floor — each with its own story and, almost always, its own sheet. When someone asks who was on site on a given day, the answer has to be reassembled from three sources that do not talk to each other.
The Cloud version of IRIGuest shares registration across several devices and sites: each gate carries on working independently, but the history is a single one and is consulted from one place. That is also where automatic notifications to internal requesters and centralised access reporting come from.
It is worth pausing on how long these records should be kept: holding them forever is not a cautious choice, it is a risky one. We wrote about it in the guide on how long to keep visitor logs. And if the first question on your mind is the budget, the answer is on the page about visitor management software cost.
Regulatory and institutional references for further reading. This page is informational and does not replace legal advice or the guidance of a competent health and safety adviser. Requirements differ by country: check what applies where your site is.
The structure is the same; what changes is which fields matter and how long the presence lasts. A visitor is invited, escorted and stays a few hours; an external company carries out work, often over several days and unaccompanied. That is why it pays to split the two paths at the gate: the first asks who the person is meeting, the second asks for the employer and the internal requester who commissioned the job.
It depends on where they go. If they stay at the dock or in the yard without entering production, many companies opt for a stripped-down sign-in or let the warehouse handle it directly. If they cross production areas, then yes: in an evacuation they have to be accounted for like everyone else. The practical rule is simple — anyone who could be inside the perimeter during an emergency belongs in the log.
No, and be wary of anyone who promises otherwise. The log documents in an orderly way who came in, on behalf of which company and when: it is a record, not a complete set of duties discharged. Verifying the contractor’s competence, producing coordination documents and instructing external workers are separate obligations, to be handled with the employer and a competent adviser.
This is the structural weakness of paper, and it does not disappear entirely with software either: no system can physically force someone to pass the gate on the way out. What changes is that in a digital log the presences still open are visible at a glance, can be closed manually at the end of the day, and stay in the history. On paper, a row with no exit time simply stays incomplete forever.
Yes: notices and consents are customisable and signed on screen, so there is a record of what was shown and to whom. Note the boundary, though: this is acknowledgement of information, not induction training for external workers. Induction requires content and comprehension checks that IRIGuest does not offer and does not aim to offer.
In many companies a visible badge for external personnel is part of site rules, and in some sectors and countries it is explicitly required. Regardless of the rule, a temporary badge showing name and company has an immediate practical benefit: anyone on the shop floor can see at a glance who is external and who they answer to. Our visitor badge guide covers what to print on one, and includes a free generator for producing them.
You do not need them and you would not want them. With the Cloud version several devices share the same log: each gate carries on working independently, but the history is a single one, consulted from one place, with no manual reassembly of three separate lists. That is the difference between knowing who came through the goods gate and knowing who is on site.
There is no single figure that fits everyone: it depends on the purpose you collected them for. The GDPR principle is that data is kept only as long as it is needed for that purpose and then deleted, so you need a defined retention period, stated in your privacy notice and actually applied. Many companies set different periods for visitors and for technical accesses, precisely because the latter can stay relevant longer.
For a single gate it may well be: the free version of IRIGuest works offline with no time limit, with configurable questions, on-screen signature and CSV export. It falls short once there is more than one gate, once the internal requester needs to be notified automatically on arrival, or once the history has to be consulted centrally — those are Cloud version features.
No. IRIGuest records accesses: who comes in, on behalf of whom, when and why. Tracking document expiry — insurance, certifications, competency records, pre-qualification checks — needs a dedicated system or an internal procedure, and it is a different field. We would rather say so upfront: an access log that also promised that would end up doing both jobs badly.
Try IRIGuest free on one gate, or take two minutes to see how an external company signs in. Nothing to install, no commitment.