Muster every expected arrival against the host who approved it, apply the escort and induction rules the visit category carries, and hold the badge for the person on the desk.
2Arrival context assembledThe visitor, the host who approved, the category the visit carries and the areas it reaches
3Badge proposal draftedThe expectation, the match against it, the escort rules and completeness
4Controls appliedApproval checks, category checks, access-profile checks and match confidence
No human action required
Stages 1 to 4 run unaided, and nobody is admitted at any of them — the agent is matching, and the security lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Match sufficient
Goes to the person on the desk to admit.
Anything unmatched
Adds a security officer read first.
Security review
The arrival is held with its expectation, its category and the areas a badge would reach.
Admit · Append evidence · Send to security
Admitted — by the person on the desk▼
6Visit and access records updatedOnly where write access and records policy allow it
7Outcome evaluatedMatch accuracy, category coverage, desk corrections and what the review found
Corrections
Each desk correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Admitting a visitor the host has not approved.
Setting the category a visit is run under.
Refusing entry on a screening match.
Holding a biometric your own policy does not provide for.
Automation boundaryAgent acts unaided
✓Match each arrival to one expectation and the host who approved it.
✓Apply the escort and induction rules the visit category.
✓Hold an unmatched arrival for the named person on the desk to work.
✓Write the sign-out so a roll-call can read true.
Nothing is admitted or escorted except by a named person, inside the agreed boundaries.
Judging whether a visit is what it was booked as.
Telling a caller which floor a visitor is on.
Setting the areas a badge profile may reach.
Changes to hosts, categories or access profiles.
Example output
One visit, annotated
Our workplace safety copilot answers to a duty-holder on a site; this record is what one arrival at a lobby desk carried.
Visit record · single arrivalIllustrative example
Visit
Recorded as
Category
Evidence of record
Confidence
Held for
Contractor attendance, escorted
Matched to one expected arrival
Contractor, escorted
Host approval, 3 August 2026
Badge held unissued
The person on the desk, by name
As receivedTaken from the host invitation and the contractor booking — it reaches as far as those sources do.
What the record holdsHost invitationContractor bookingInduction record
Why no admission hereWhether this arrival may come in is a desk decision, not a model output.
ActionAdmitAppend evidenceSend to security
What the score decidesBelow the configured threshold an arrival picks up a security read before the desk sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every arrivalFrom the host who expects it
03Evidence
Where the evidence is used
Our hotel check-in agent prepares a guest arrival and holds the key for the front office; this is a corporate lobby, where a host approves and a roll-call must be right when the building empties.
01Approved path
A visitor is a record
A visit record is personal data about somebody who is not an employee, so the retention period is configured with you and never inferred by the agent.
02Human review
What was checked, and not found
No statute was located that fixes how long a visit record is kept, what a badge must show or what a roll-call must contain, and none is claimed here: the retention period, the badge profile and the escort rule are all things the customer sets.
04Build an evidence trail
The visit, the host who approved it and the badge issued stay on one record.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Visitor and host sourcesHost invitations · diary Contractor bookings
Access controlBadge printers · readers Access profiles and doors
People and sitesHR system · site roster Host and escort records
Agent
Front desk and visitor
Reads the expectation Matches the arrival Holds for the desk
Visit and case systemsVisitor platform · tickets Visit and sign-out records
Integration availability depends on the client's existing systems and API access.
Agent controls
Six doors between the model and the desk
Six doors in a row, the last one narrowest. Whoever comes through them all is drawn in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to arrival matching when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and category rules; changing what a category requires changes who must be escorted.Track
L4TraceabilityRecord each visit, the host behind it, the category it ran under and every read of that file.Record
L3Desk admissionHold the badge for a named person at the desk; the hold governs issue, not whether a visit should happen.Gate
L2Category guardrailsTest each arrival against the escort, induction and access rules configured for that category; no biometric is held unless your own policy provides for one.Restrict
L1Confidence thresholdsRoute a weak match to a security read before anybody at the desk is asked to admit a stranger.Require review
Model coreArrival matched — the expectation, the host, the category and completeness
L1 – L2Test whether an arrival may stand
L3Puts the admission in a person's hands
L4 – L5Keep the visit and the host behind it
L6Holds the badge unissued when signals degrade
How Nestack evaluates it
Evaluate the whole arrival — not only the badge that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the badge a visitor wears
Depth of coverage ▼
E1Final-output evaluationDid the badge carry the category the visit was actually booked as?
E2Step-level evaluationDid the agent read the right expectation, the right host and a live profile?
E3Tool evaluationDid it read and write the correct visit record and the correct badge?
E4Confidence calibrationDo weak matches actually attract more desk corrections?
E5Slice evaluationHow does performance change across specific visit categories?
E6Business outcomeHow many arrivals needed a correction before anyone was admitted?
Floor — the lobby the site answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each pinned to the stage where it first shows.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
KF-03
Stale profile read
The access profile read is not the one now in force.
Stage gathersThe visits, the hosts, the badges and the areas
02 · Reasoning2 modes
KF-04
Category read too narrow
A works attendance is run as a guest visit.
KF-06
Screening match self-answered
A flag is closed without a named person seeing it.
Stage proposesThe expectation, its category and completeness
03 · Tool / write2 modes
KF-02
Weak match passed forward
An arrival moves on without the security read.
KF-05
Bound to the wrong host
A visit is filed against somebody who invited nobody.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
KF-01
Admitted, approval unrecorded
The record shows an admission but not who approved it.
Stage returnsThe badge a desk issues and a roll-call reads
05 · Change / Version1 mode
KF-07
Silent category regression
A configuration change moves the category, not the escort.
Stage tracksModel, prompt, category rules and visit fields
Sev-1 · an unescorted contractor insideSev-2 · wrong category reaches the badgeSev-3 · source degrades, badge held unissued
A host-level approval-currency figure can read clean while contractor and works visits carry most of the rework. Nestack reports the correction rate by visit category, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Contractor and works visits
11.2%
3.7×
Review
Multi-day and recurring visits
8.0%
2.6×
Review
Interview and candidate visits
5.0%
1.6×
Watch
Client and meeting visits
2.4%
0.8×
Normal
Bar: correction-rate lift vs. client-visit baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a wrong category costs
A cycle shuts when the unescorted contractor is a regression case. That suite is what the next arrival handled is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on contractor and works visits.
02Diagnose
The contractor who signed in as a guest and walked to the plant room alone is read back until one cause remains.
03Improve
The change ships numbered, and the visits that forced it ride with it.
04Verify
Nothing releases while one touched arrival case is still red.
05Learn
It is retained for good, and the visit rules are amended in that same commit.
Learn → DetectThe return edge. The next arrival is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, arrival matching, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Visit-category and automation-boundary discovery.
02Host, contractor and roster sources.
03Arrival-to-expectation and escort-rule mapping.
04Expectation and arrival ingestion.
05Visit, host and category binding.
06Match scoring and review routing.
07Desk admission workflow.
08Access-control system integration.
09Approval and escort cases.
10Guardrails and issuance controls.
11Visit-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne lobby, one yearProductionProduction visitor workflowAdvancedMultiple sites / lobbies
Introduced at Pilot
Arrival matching to your categories✓✓✓
Desk admission release✓✓✓
Expected-arrival baseline✓✓✓
Introduced at Production
Reporting by host—✓✓
Admission workflow in your systems—✓✓
Approved write-back—✓✓
Access-system integration—✓✓
Introduced at Advanced
Multi-site category rules——✓
Cross-site escort packs——✓
Large arrival volumes——✓
Multi-site badge controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, arrival volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your visit categories and what each one requires→Category mapping and expectation captureWeek 1
02Representative host, contractor and induction records→Record binding, category logic and the matching baselineWeek 2
03Your access profiles and who may widen one→Category mapping, host binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Host, contractor and access-source assessment, then integration setupWeek 2
05Arrivals you would not want audited→Escort cases and failure-mode testingWeek 4
06What no visitor record may establish→Match scoring, review routing, guardrails and release controlsWeek 3
07Named desk staff who admit and escort→Desk admission workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Every band below is worked time and not drawn space, which is why the fifth of them holds a pair.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Lobby workflow discovery, category mapping and the automation boundaryW2Source integration and the arrival-matching baselineW3Arrival matching, category logic and release controlsW4Evaluation suite, escort cases and failure-mode testingW5Access-system integration, pilot arrivals and targeted correctionsW6One occupancy year run under the site lead, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth holds a pair because the work does.
At the end of W6Validation closes on live arrivals, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Facilities AI agent
Build a visitor agent around the arrival whose category was wrong before anyone reached a door.
Show us one arrival and the expectation it was matched to. If contractors at your sites are booked by the people who host them and inducted by somebody else, then the category on a badge is carried on trust, and the roll-call is the unannounced moment that trust is tested.