The visitor guestbook
Turn a screen into a reception sign-in book: visitors sign themselves in, hosts are told, a badge prints, and when the alarm goes everyone who needs it is sent the list of visitors who are still signed in.
Part of the business plans, like menu boards — no home plan reaches it, however high it sits. Reception staff get an account that reaches this and nothing else.
What it is for
A screen in your reception becomes a sign-in book. Visitors say who they are and who they have come to see, the person they are visiting is emailed, and the visitor is given a badge number on the screen. The badge itself prints at the desk, or at the booth if you have switched that on. Your admins can see who is in the building at any moment.
That last part is the point of the whole thing. When an emergency broadcast starts, everybody who needs it is sent the list of who is signed in — automatically, without anybody having to find a button while an alarm is sounding.
It is worth being plain about the limit of that list, because it is the difference between useful and dangerous. Mirra knows about visitors who signed in. It does not know about your staff, who come in through a door it cannot see. Every copy of the list says so.
Setting it up
Under Settings, in the Reception section. Five things, and only the first is required.
Switch it on
"Use this account as a reception book", under Settings. Off means nobody can be signed in and no evacuation list is sent.
Name the building
It goes on badges and at the top of the evacuation list, and it is often not the same as the company name.
Set a close-out time
Read the next section before you leave this one alone — it is the setting that decides whether any of this stays true.
Give a screen its own email address
Open a screen from the dashboard and look for Forward meetings here in the right-hand column. Press the button and the screen gets an address of its own; forward a meeting invitation to it and it appears on that screen alongside everything else. No calendar to connect and no administrator to ask, which is the point of it — it is the one way of getting a meeting onto a wall that needs nobody's permission. Treat the address like a password: anyone who has it can put a meeting on that wall, so it is fine on a room's contact card inside the building and not fine on a public page. New address replaces it, and anything already forwarding to the old one stops arriving.
Set the building's timezone
Directly beneath the close-out time, and it decides whose clock that time is on. Our servers run on UTC, so a site outside it needs to say where it is: without that, a British building set to 18:00 closes out at 19:00 over the summer, and a building west of here closes out hours EARLY — marking visitors as gone while they are still inside, which is the one direction an evacuation list must never be wrong in. Written the way timezones are named — Europe/London, America/New_York — and the box suggests the common ones as you type. New sites start on Europe/London.
Keep a register of permits, including finished ones
Permit register on the reception page lists every permit this building has issued — the signed-off ones as well as the open ones, with who authorised it, who it was for and how it was closed. That history is what an insurer or an inspector asks for, and until now a permit disappeared the moment somebody signed it off. You can also raise a permit before the contractor arrives rather than only for somebody already signed in, which is what planned work needs, and attach the signed permit, the method statement for that job or an isolation certificate to it. A permit raised in advance shows as "not arrived yet" rather than "they have left" — two different things, and only one of them means go and look.
Fixing something entered wrongly
Nothing is deleted, and that is deliberate — a certificate that was on file when somebody was let in is part of why they were let in, and a permit is a record of an authorisation given. Removing either would rewrite what was believed at the time. Instead you withdraw it: press withdraw beside a document or a permit, say why, and it stays on the record struck through with your name and your reason against it. What changes is that it stops counting — a withdrawn certificate no longer satisfies the check at the booth, and a withdrawn permit leaves the evacuation list. That matters more than tidiness: one in-date document of a kind is all the check wants, so an expiry typed as 2027 instead of 2026 will keep letting somebody in until it is withdrawn. Withdrawing a permit is not the same as signing it off — signed off means the work is finished and the area is safe, withdrawn means the permit should never have existed.
Chase paperwork before the day, not at the desk
The reception page has a Contractors & documents section listing everybody with insurance, method statements or competence cards on file — and, by default, only the ones about to run out or already expired. Open somebody to see what they hold and to record a new certificate the moment it arrives, rather than waiting until they are turned away at the booth. It matches what the booth actually checks: a renewal recorded beside last year's certificate clears the row, because one in-date document of a kind is all the check ever wanted. Somebody appears here once they have a document on file — for a contractor who has never been, send them an invitation first and the paperwork can go on before they arrive.
Add anybody else who should get the evacuation list
Fire wardens are very often not Mirra users, so this takes plain email addresses, one per line. The page counts them back, so a typo is visible rather than silent.
Rename the kinds of visit
A builders' merchant and a law firm do not want the same four words. The colour you choose is the band printed across the top of the badge, and the expected length decides when somebody shows as due to leave.
Only an owner can change these. A reception account can sign people in and out all day and cannot alter the retention window or remove a fire warden from the list.
Visitors do not sign out — so plan for it
This is the thing that decides whether a visitor book is worth having, and almost every one ever made gets it wrong.
People sign in reliably: a screen is in front of them and somebody is watching. They do not sign out. They leave through a different door, or in a hurry, or with the person they came to see. Left alone, within a fortnight your "who is in the building" list is a list of everybody who has ever visited — and the fire marshal knows it, so they stop trusting it, so it fails on the one morning it mattered.
Mirra assumes this will happen rather than nagging about it. At your close-out time, anybody still signed in is marked believed to have left. That is deliberately not the same as signed out: nobody watched them go. They stop counting towards the building, they appear in their own section on the reception page, and an evacuation list still mentions them separately so somebody looks.
The rule behind all of it: Mirra will never tell you a confident number it has not earned. Where it is guessing, it says so.
Check the timezone beneath it while you are here. The close-out time is a wall-clock time, and our servers are on UTC — so a site that has not said where it is will close out at the wrong hour. Too early is the one that matters: it marks people as having left while they are still in the building.
Leaving the close-out time empty means never closing out. That suits a site with a night shift and almost nothing else.
The reception page
Who is in the building, first thing on the page, with how long each person has been in and a flag when somebody is past the time their visit was expected to take. That flag is a prompt to ask, not a claim about where they are.
Every row has three buttons. Sign out is the realistic one: the moment somebody actually leaves is a receptionist noticing, not a visitor remembering. Badge opens the badge, and reception prints it from there. Opening it is what gets recorded — a receptionist checking one counts the same as a reprint — which makes it the honest thing to record, because how many badges exist for one person today is a security question. Permit issues a permit to work against that visit. A sign-in belonging to one company in a shared building does not have that third button, because permits are the building's.
Below that is a short form for signing somebody in by hand. One required field. A visitor waiting while a receptionist fills in eight boxes is a queue.
Inviting somebody before they come
Book a visitor in and they get an email with the time, who they are seeing, and a six-character code. On the day they type that code at the booth and are signed in — no queue, no spelling a company name at a receptionist.
The email also carries a link. It fills in their details in advance and does nothing else: it cannot sign anybody in. That separation is deliberate and worth knowing about, because invitations get forwarded — that is what invitations are for. If one value did both jobs, forwarding an invitation would hand a colleague the ability to arrive as that person and take a badge in their name.
Today's expected arrivals appear on the reception page with their codes beside them, so somebody who has lost the email can be read theirs at the desk.
The code is in the body of the email rather than the subject line, because subject lines show on a locked phone.
The booth
Add the Reception booth widget to a scene and that screen becomes a self-service kiosk. Visitors tap Sign in, choose what brings them in, type their name, pick who they are seeing, and get a badge number.
Give it a screen of its own. A booth with the weather in the corner is a booth somebody will tap the weather on — that is why the widget defaults to filling the panel.
It returns to Welcome on its own after a short pause, from any screen. That is not tidiness: a booth left half-filled means the next visitor adds their details to somebody else's, and a booth left showing a name is telling the lobby who just arrived.
- Signing out is by badge number, never a list of names — a list on a lobby wall says who is in the building
- The booth never shows who else is in, and cannot search for a visitor
- It works alongside the desk: some people will always prefer to speak to somebody
When the building's internet goes down
The booth keeps working. A sign-in it cannot send is kept on the screen and sent as soon as the connection is back, so nobody has to queue at the desk with a pen and a notebook — which was the whole reason for the booth.
The visitor is told they are signed in, because they are: the record exists and will reach reception. What they are not given is a badge number. Those are allocated by the server in order, and a screen inventing one would hand two people the same number.
While any are waiting, the welcome screen says so quietly at the bottom — so somebody from facilities walking through the lobby can see the building has been offline without opening anything.
If a roll call happens during the outage
There is not one. The roll call is a page served from the portal, so a building with no internet has no digital roll call whether or not the booth queues anything — which is exactly why a printed list is still worth keeping behind the desk.
If a screen is replaced or reset mid-outage
Anything it was holding goes with it. The queue lives on that screen, so leave a booth alone until the pending count on its welcome screen has cleared.
- The time recorded is when the person actually signed in, not when the connection came back.
- Reception's live list marks those rows "signed in offline".
- A sign-in still waiting after twelve hours is dropped rather than sent. By then the person has gone home, and adding them as present would be worse than not having the record.
- If the checks would have turned somebody away, the visit is still recorded and the row says so. They were already in the building; refusing the record an hour later would only lose the fact that they were.
- Sign-outs are not queued. During an outage a visitor who has left is picked up by the end-of-day close-out, exactly as one who forgets to sign out is.
A visitor signed in offline was not checked against the blocked list or their paperwork at the moment they walked in — the screen could not reach the server to do it. Those checks run when the sign-in is sent, and if one of them would have turned the person away, the visit is recorded anyway with a note saying so. If your building relies on those checks, the honest answer during an outage is that a person at the desk is doing the checking.
Badges
Badges print from the desk, and from the booth if you ask it to. Reception opens a badge and prints it; a booth can print one on sign-in once you have switched that on and the machine is set up to print without asking. Either way it is the same page and the same card — a reprint at four o'clock is the same thing the visitor was handed at nine. They print at 62mm, the common label width for a desktop label printer.
The coloured band across the top changes with the day of the week. That is more useful than it sounds: nobody reads a printed date on a badge clipped to a lapel, but everybody notices a badge that is the wrong colour from across a lobby. Yesterday's badge is obvious without anybody inspecting it.
A badge is not a key. Nothing on it opens a door, and nothing on it works as a credential — it says somebody came through reception, which is what a badge is for.
Kiosk printing is off until you turn it on, in the booth widget's own settings. Leave it off unless that machine is set up to print silently: a print box on an unattended lobby machine is something a visitor has to dismiss, and eventually something a visitor uses to get out of the kiosk.
When the alarm goes
Starting an emergency broadcast sends the roll call. Nobody has to remember to do anything, and it does not matter which way the broadcast started — the button in the portal, the panic button on a screen, or a fire panel wired to the API.
The building's copy goes to every owner, every reception account, and every address you added. In a building let to more than one company, each company is also sent its own copy of its own people, and a company's own sign-ins receive that one and never yours. It is a snapshot taken at that moment and it says the time it was taken, because a list that quietly updates is a list two marshals in a car park will disagree about while both believe they are reading the same thing.
It is plain text on purpose. This is read on a phone, outdoors, possibly in the rain, by somebody who is not calm.
Somebody who has unsubscribed from Mirra's emails still receives this one. An unsubscribe is not a request to be left out of an evacuation.
Parcels behind the desk
A courier is one visit and often several parcels for several people, so a parcel is its own record rather than a note on a visit — and it outlives the visit by however long it sits on a shelf.
Log who it is for, the carrier, how many and where you have put it. If the name matches one of your sign-ins, that person is emailed to say it has arrived; a name off a label that matches nobody is still logged, still findable, and still answers "has anything come for me". Mark it collected when somebody takes it.
The waiting list is oldest first, which is the opposite of everything else here and deliberate: a new parcel is on the desk in front of you, and the one that needs attention has been there three weeks. Anything waiting a week or more is flagged.
Numbers, and taking a copy
Reception → Reports shows what a period looked like: how many visits, how many people, when they arrive, which day is busiest, who is most visited and where visitors come from. Pick any two dates.
The figure worth understanding is the typical visit length, because of what it deliberately leaves out. A duration is counted only where somebody actually signed out. Everything closed by the end-of-day sweep has no duration at all — that timestamp is when the record was closed, not when the person left — and the page says how many visits it excluded on that basis. In most buildings that is a third of them, and an average drawn from the other two thirds is worth having as long as nobody reads it as the whole picture.
A search over a very large period is capped, and the report says so on its first page rather than quietly returning less than you asked for.
Reception accounts
Front-desk staff get their own kind of account. They see one thing — Reception — and nothing else: not screens, not scenes, not billing, and not these settings.
It works the way the menus-only account does, and for the same reason. Somebody on the desk needs to sign visitors in and print badges; they do not need the keys to the display system, and giving them out because it was easier is how a lobby screen gets redesigned during a lunch break.
They can still raise a support ticket, because the person standing in front of a booth that has stopped working is very often the person who needs to tell somebody about it.
Reception is one of two restricted accounts here. The other is "One company only", for a tenant in a building let to several — that is a different article.
What a reception account cannot do is worth naming, because the page does not advertise its own edges. They cannot change these settings, alter the retention window, edit the fire-warden list, put somebody on the blocked list or take them off it, or unpair a screen. They can see the visitor numbers — busy hours are how somebody decides when to put two people on the desk — but not download the visitor list itself, which is a named record of people and belongs to whoever is accountable for it. They can see that somebody is blocked and why — they could not decide sensibly otherwise — and that is where it stops.
Visitor details and how long they are kept
Visitor records are personal data about people who never signed up for Mirra, so they are treated differently from the rest of the product. Your organisation decides what happens to them; we hold them on your behalf.
The retention setting resolves a genuine tension rather than picking a side. Keeping a stranger's name and mobile number for years because they once came to a meeting is more than you need. Throwing the record away entirely destroys the evacuation history you may have to produce after an incident. So after the window you set, a visit keeps its times, its type and its outcome, and loses the person: enough to answer how many people were in the building at twenty past two, without answering who.
Somebody still signed in is never touched, however long ago they arrived — taking their name off the record would remove them from the roll call by the back door.
What it does not do yet
Worth knowing before you plan around it, because these are the things people assume are there.
There are no QR codes. Invitations carry a six-character code instead, typed at the booth — which needs no camera on the screen, and works from a phone with no signal.
There is no face recognition for visitors, and it is switched off rather than missing. A face used to identify somebody is treated differently in law from a name and a company, and somebody arriving for a job interview is not in a position to refuse a reception system — which makes their agreement worth very little. If your building genuinely needs it, talk to us rather than expecting a switch.
A building with several companies in it is understood now — there is an article on it. What is still true is that one Mirra account is one building. A managing agent with two buildings has two accounts, because the site name, the screens, the desk and the fire wardens are different in each.
The booth needs its connection. Every tap is a call to Mirra, so a kiosk that has lost the network cannot sign anybody in or out, and nothing is held back to catch up later. The desk is the fallback.
A broadcast takes the booth over completely — an emergency, and a warning or a notice just the same. While one is running, that screen shows the broadcast and nothing else, including to somebody halfway through signing in. Mostly right, and better known in advance than discovered.
Nothing asks a host whether their visitor has left. An overrun shows as a pill on the reception page and goes no further.
There is a muster tick-off now. The roll-call email carries a link to a page marshals work through at the assembly point, ticking people off as they find them — no login, because a fire warden is often not a Mirra user at all. The email stays the snapshot of the moment the alarm went; that page is the live one, and each says which it is. When you end the emergency the list closes, and everybody who got the roll call is sent what it ended up saying: how many were accounted for, who was reported not found, and who nobody ever got to.
None of the above is a gap in what is here — signing in, badges, occupancy and the evacuation list all work today.
Related
- Contractors, permits and site rulesMake a building's own rules part of signing in: site rules a visitor accepts, insurance and method statements that have to be current, permits to work that get signed off, and a blocked list with a reason and an end date.
- Buildings with more than one company in themOne reception desk, several companies upstairs: name the occupiers, give each their own sign-in that sees only their visitors, and the evacuation roll call goes out to each company's own fire wardens as well as to you.
- Emergency broadcastHow to take every screen on the account at once with one message, using a template and a two-step confirmation — and how to wire a physical button to a screen to do the same thing.
- Sign-ins and rolesHow to give somebody their own password for your Mirra account, and exactly what each of the two roles — full access and menus only — can reach.
- Screen types, and what a screen can doWhat hardware can act as a Mirra screen, what each display reports about itself, and exactly what the capability record does and does not cover.
- The scene editorThe scene editor is where you arrange a screen's widgets on a twelve-column grid, watch the real widgets render behind them, and push the result to the wall.
- Your dataSet how long Mirra keeps assistant transcripts, presence and the activity log, take a copy of everything held about your household, and close the account for good.
- Plans and allowancesWhat each Mirra plan includes — screens, household members and assistant credits — how credits are metered, and what happens when you reach a limit.