Compliance Scanner
Run compliance scans, interpret GREEN, AMBER, and RED results, and assign missing training
What the compliance scanner does
The compliance scanner reads a worker's compliance passport QR (from their Profile) and evaluates global and site-specific rules: mandatory training, external certificates, risk assessments, and assigned course completion. The result tells gate staff whether to allow site entry, allow with conditions, or deny entry until gaps are closed.
Open it from Site Management → Open compliance scanner or directly at /admin/compliance-scan. If you open the scanner from Site Management with a site selected, the site dropdown is pre-filled via ?siteId=….
Who can scan
The scanner requires Site Management access. Typically this includes:
- Tenant administrators (full Site Management)
- Users assigned as compliance scanner or site administrator for one or more sites
Standalone Site Management nav
Non-admin staff with site permissions may see Site Management in the main sidebar (not under Admin). They can open the compliance scanner if their role includes scanner or site admin rights. Tenant admins also reach the scanner from the Site Management dashboard header.
Permission and role assignment: Scanners, Permissions & Settings.
Run a scan
Select site
Choose the Site from the dropdown. This determines which per-site requirements are evaluated and is required to log a scan or open presence on site.
Select No site (global passport lookup only) when you only need to inspect compliance without recording a site visit — you cannot log entry or open presence without a site.
Scan the worker QR
Tap Scan passport QR to use the device camera, or paste the token manually. The QR may be a raw token or a full URL containing workerToken (as generated from Profile).
Tip
Review the result modal
The Compliance scan result modal shows the worker's name, the overall decision, mandatory completion percentage, and per-requirement checklists split into global and site-scoped rules.
Decision outcomes: GREEN, AMBER, RED
The API returns GREEN, AMBER, or RED. The UI labels RED as Entry Denied.
| Decision | UI label | Typical meaning | Scanner actions |
|---|---|---|---|
| GREEN | GREEN | All global and site requirements satisfied; mandatory assigned courses complete | Log scan + open presence, or log scan only |
| AMBER | AMBER | Non-blocking gaps — review breakdown; manager may allow entry with conditions | Allow with conditions, Deny for now, or assign missing training |
| RED | Entry Denied | Blocking gap — expired certs, incomplete mandatory training, missing approved risk assessments, etc. | Log scan only — presence cannot be opened until compliant |
Warning
AMBER: allow or deny entry
For AMBER results, administrators and managers see explicit site-entry buttons:
- Allow with conditions — logs the scan and opens presence on the selected site (worker signed in with documented partial compliance)
- Deny for now — logs refusal and explains what is still required
What appears in the breakdown
The modal groups gaps so gate staff can give clear instructions:
- Global requirement checks (tenant-wide rules)
- Site-specific requirement checks
- Missing mandatory and optional assigned courses
- Expired mandatory external certificate summaries
- External certificate evidence already on file
Assign missing training
When gaps are assignable, the result modal shows Assign missing training. This posts missing LMS modules (including linked external-certificate catalogue courses), optional assignments, and draft risk assessments or questionnaires for rules still marked missing.
Run scan and review gaps
Confirm the worker identity and note which requirements show as Missing.
Assign missing training
Click the button and wait for confirmation. The passport lookup refreshes with updated status.
Re-scan or send worker to complete
The worker completes new assignments on their dashboard. Re-scan when ready to confirm GREEN before opening presence.
Tip
Logging scans and opening presence
| Action | When to use |
|---|---|
| Log scan + open presence (if allowed) | GREEN result — worker entering site normally |
| Log scan only | Audit trail without signing worker in, or RED when entry denied |
| Allow with conditions | AMBER — documented partial compliance, manager approves entry |
| Deny for now | AMBER — worker turned away until gaps closed |
Scan logging requires a selected site and appropriate role (admin or manager for operational buttons). Presence opening respects site rules and existing open presence records.
Bulk passport QR pack (admins)
Tenant administrators may see Download all worker passport QR codes (ZIP) on the scan page. The ZIP contains the same profile passport links for every worker in the organisation — useful for printing sticker sheets (see manifest.csv inside the archive).
Capability-gated
This download appears only when your tenant has bulk passport QR export enabled.
Related configuration
Scan results depend on rules configured elsewhere:
- Global Compliance Rules — tenant-wide requirements
- Per-Site Compliance Rules — requirements for the site selected in the scanner
- For Learners & Contractors — how workers open their passport QR
FAQ
Why must I pick a site before logging?
Per-site rules and presence records are site-scoped. Without a site, you can look up the passport globally but cannot record entry or open on-site presence.
The worker is GREEN on one site but not another.
Per-site compliance rules differ. Always select the site they are physically entering before interpreting the decision.
Can contractors use the scanner?
No — temp-staff accounts cannot access the compliance scanner. Gate staff need scanner or site admin permissions (or full admin access).
Opening a profile link with ?workerToken=
Profile passport QRs encode a URL with workerToken. If opened on the scan page while signed in as a scanner, lookup runs automatically after site selection.