0% found this document useful (0 votes)
5 views3 pages

BionnSec: Biotech Visitor Management System

Uploaded by

dekumalditonerd
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views3 pages

BionnSec: Biotech Visitor Management System

Uploaded by

dekumalditonerd
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

BionnSec – Smart Visitor Management Solution

Teamwork – Problem Description

THE CONTEXT
The USA and UE regulations related to biotech, pharma and agro-food industries demand strict procedures when
dealing with visitors. On any given day, there may be many people in the facilities who aren’t employed by the
company — technicians servicing equipment, vendors, auditors, visiting guests, etc. If a technician requests
access to a manufacturing area, that’s probably reasonable. If a guest does, that might be a problem.

GENERAL PURPOSE
Visitor management systems track the movement of
visitors within an organization facilities, provide visual
identification and access control. It is an innovative
approach that allows organizations to achieve greater
control over visitor behaviour at their locations (see here).

As consultants at Brighthead IT, we are working on a software-based solution, named BionnSec, for visitor and
access management for the company Gilead Biotech Inc. This solution will ensure legal compliance, safety and
security requirements and speed up emergency evacuations. A special feature of this solution is the screening of
visitors before granting them an appointment. Visitors will be checked against internal watchlists and an external
identity and background check service (through our partnership with Visual Compliance -
[Link] before getting an appointment

INITIAL PROBLEM DESCRIPTION


Notes from an interview with Ari Vasileiou, Head of Global Security & Facilites at Gilead Biotech Inc.

Access to different departments within the company must be carefully regulated (consider the name of the
department and the name of the building). For safety reasons, only a limited number of visitors are granted access
to each department per day. Each department is staffed with qualified employees (name, email, phone number,
and other details). While all these employees can host visitors, there is a small group of employees in each
department responsible for escorting visitors who do not have a specific employee to visit, but still must access the
facilities (disinfection specialists, for example).

In summary, some visitors are guests (auditors, researchers, institutional guests, etc.) who will request
appointments to meet with specific employees; other visitors simply wish to access and visit the department
facilities, such as vendors or visiting students. Additionally, third-party technicians, suppliers, etc. who require
access to the facilities, are also considered visitors and will be escorted by an employee while inside the facilities.
Regardless of the situation, one employee will always be involved during a visit.

For security and compliance reasons, the visitor’s name, an official identification, email, and mobile number are
registered; in addition they must provide details regarding their institution or company, including its name, address,
and the visitor’s position in it. Due to the critical security environment, access to departments is not granted to all
visitors. However, there is a special group of visitors who are granted special access under different conditions
and an additional feature is appended to them: their security clearance level (from level 1 to 5).

Some details about Functional Requirements


All visitors who wish (or must) access a department must undergo a pre-approval process before requesting an
appointment, mostly if it is their first interaction with the company. They will need to provide their personal

1
BionnSec – Smart Visitor Management Solution
Teamwork – Problem Description

information, company details, department to visit and date, expected duration and the purpose of their visit, as well
as the host employee (if there is one). The host employee will be also allowed to provide all these information on
behalf of the visitor.

Once the pre-approval details are submitted, the head of


Global Security & Facilities will receive a notification. The
head is in charge of conducting a screening process on the
visitor. The fist step will involve checking the internal
watchlist (which means revising if the visitor has been tagged
to be banned in the past). Based on this information, the
head may choose to perform a background check using
Visual Compliance (see figure).

If the head does not authorize the visitor’s request, the


visitor’s personal information will be updated in the internal
watchlist (with notes added to provide key details). An
informative message will be sent to both the host employee
(if there is one) and the visitor, explaining the decision.

On the other hand, if the visitor is green-lighted, their


personal and company details will be formally registered.

In addition, during the screening process, considering the professional importance of the visitor, the employee
hosting the visitor, and the purpose and department to visit, the manager may grant the visitor a security clearance
level from 1 to 5.

In any case, a positive screening process does not guarantee that the requested appointment can be granted, as
there are additional business rules to consider. As a matter of fact, after the screening, the workflow for granting
the appointment must be fully completed, as described in the next section.

Depending on the department, visitor and visiting date, the appointment request can be accepted or rejected.
Granting conditions must be checked, such as the availability of spaces in the department that day (the number of
accepted appointments is lower than the maximum visitors allowed). If there are available spaces, the appointment
is accepted, details are recorded, and both the host employee (if there is one) and the visitor receive a positive
notification via email (attaching safety instructions documents and data privacy consent). If no spaces are
available, they are both informed that they may request an appointment on another date. However, there is one
exception to this policy: if the visitor has security clearance level of 5, they will be granted an appointment, even if
there are no places available.

Visitors can request a one-time appointment, but they can also request recurring appointments (such as for training
sessions or routine repair work). Once they have passed the screening process, they can request as many
appointments as necessary. However, it is important to note that granting conditions must always be checked, and
requests may be accepted or rejected accordingly.

2
BionnSec – Smart Visitor Management Solution
Teamwork – Problem Description

When the appointment day arrives and the visitor arrives on-site, the
receptionist will verify their identity, validate the appointment and register
the entry time; if the appointment is not linked to a specific host employee,
the visitor will be assigned the first available employee from the set of
department employees responsible for escorting visitors. In both cases,
the host employee will get a notification informing that the visitor has just
checked-in. A smart identification and access card will be provided to the
visitor (see figure).

However, if an unwelcome visitor arrives on-site, the reception desk staff can send alert notifications to the security
team and relevant individuals, preventing potential future issues. The visitor will be denied entry and the internal
watchlist will be updated.

When the visit ends, the visitor returns the card and the
visit is “checked-out”; this means that the exit time is
recorded, along with any observations or unexpected
events that may have occurred during the visit (in some
cases, this may include adding the visitor to the internal
watchlist – see figure).

Finally, due to quality service concerns, contractors and


suppliers often request information about the services
provided by their technicians (such as duration of the visit
and evaluation of the task by the responsible employee).
They tipically make this request via email (to the address
[Link]@[Link]). In these companies, there
will be a designated contact person, with a registered
email address, who will be the only recipient of this
information.

Other requirements to explore are related to reporting and creating a dashboard for metrics and trends (visitors
currently in, expected visitors, denied entry, busiest hosts, visitors not checking-in, end-of-day reports, etc).

Challenges
The suggested solution must integrate with the company's emergency system, even though the exact method of
integration is not clearly defined and there is no guarantee it can be achieved. On the other hand, while smart
cards are supplied at a reasonable price by a reliable supplier from Taiwan, they are the sole supplier; occasional
supply difficulties may arise.

Finances
According to Maya Evans, the Chief Digital Officer at Gilead Biotech Inc, the allocated budget is 500.000 €.
However, we are tasked with delivering a robust, highly customized product with advanced features, including pre-
approval processes, background checks and complex integrations.

You might also like