In build with a launch customer

A sailing is not a visit.

Visitor management assumes people arrive one at a time. A voyage does not work that way: a manifest lands weeks out, thousands of names need screening before anyone reaches the terminal, and the ship leaves whether or not the exceptions were resolved.

We're building this now with a cruise operator who has the problem in front of them. What follows is honest about what exists and what is still being designed.

The problem

Volume, deadline, consequence.

Three things make embarkation different from a lobby, and each one breaks a tool designed for one person at one door.

01

Volume

Thousands of passengers and crew per sailing, across a fleet with several ships in the water at once. Screening has to run against the manifest as a batch, on a schedule — never as a per-person action at a desk.

02

Deadline

A ship sails on the hour it sails. A match found at the terminal is a match found too late. Screening happens weeks out, so an exception still has time to be resolved by a person.

03

Consequence

Refusing boarding is a serious act, and so is failing to. Both directions demand a record: what matched, on which list, at what confidence, who reviewed it and what they decided.

In build with a launch customer

Screening a whole manifest before the gangway opens.

A visitor is one person at one door. A sailing is a manifest — thousands of names arriving at once, on a date that does not move. Upload the manifest or sync the booking feed, and every passenger is screened against the check set you enable, weeks before embarkation.

  • Sanctions and global watchlists, criminal records, sex offender registries, PEP, adverse media and identity — enabled per account
  • Matches carry a source, a list, a confidence score and a note, so a reviewer can judge rather than guess
  • No passenger is denied boarding automatically. The highest outcome automation can reach is Escalated
Visit+ passenger screening — background check set with sanctions screening always on, and a completed manifest import showing cleared, needs-review, escalated and denied counts
Manifest import2,561 passengers screened on upload

The queue

Every passenger, banded by how strong the match is.

Severity is scored from the match itself, so a phonetic near-miss never sits in the same pile as an exact hit on name, date of birth and document number. Filter, sort, act in bulk where it is safe to — and export the view you are looking at.

Visit+ passenger screening queue — 2,561 passengers with cleared, needs-review and escalated counts, each row showing sailing, date of birth, passport, licence, severity score and status
Screening queueWorking prototype · passenger details anonymized

Getting the manifest in

Two ways in, one screening pipeline.

Whichever route a passenger arrives by, the same enabled check set runs against them and the results land in the same queue.

CSV manifest uploadDrag in a manifest and it screens on import. A header row with name, date of birth, passport, licence, sail date and ship is all it needs — licence and passport are optional per passenger. Upload history is kept so you can see which file produced which results.
Booking-feed APIPoint your reservation system at the endpoint and passengers are screened as bookings land, rather than in one batch at the end. Same checks, same queue, same audit record.
Visit+ API feed configuration — connected booking system, endpoint, API key and poll interval, with the same background check set applied to every ingested record
Booking feedConnected system · poll interval · shared check set

The check set

You decide what gets screened.

Checks are enabled per account and apply to every passenger ingested afterwards, by upload or by feed. Sanctions screening is mandatory; everything else is a policy decision that belongs to you, not to us.

Sanctions & global watchlistsAlways on

OFAC, UN and EU consolidated lists, Interpol notices and no-fly sources.

National criminal records

National criminal file, county and federal court records.

Sex offender registry

State registries and territories, consolidated.

PEP screening

Politically exposed persons and close associates.

Adverse media

Negative news tied to financial crime, violence or fraud.

Identity verification

Name, date of birth and document numbers against identity records.

Adjudication

The machine narrows it down. A person decides.

Every match carries the source, the list it came from, the name it matched, a confidence score and a note explaining the basis. A reviewer sees why something surfaced before choosing what to do about it.

Clear · Medium · High · CriticalRisk is banded from the strength of the match, so a 28% phonetic near-miss never sits in the same pile as a 99% exact match on name, date of birth and address.
Reviewer and notesEach passenger carries a note history — what automation found, who looked at it and what they concluded. That is the record an inspection asks for.
Bulk where it's safeClear, flag or escalate a selection at once when the queue is mostly false positives. Denial is never a bulk action.
ClearedNo match, or a match a reviewer has dismissed with a reason.
Pending reviewA low-confidence hit is waiting on a human. Most of these are false positives.
Flagged for reviewA partial or fuzzy match that needs verification before sailing.
EscalatedA strong match. The on-duty security officer is notified and the review reopens.
Denied boardingOnly ever set by a person. Automation cannot reach this state.

This is the part we will not compromise on. Automated screening produces evidence, not verdicts — the highest state it can reach on its own is Escalated, and a human being is required to go further.

Beyond the passenger

The gangway is one of several doors.

A cruise operation runs shoreside offices, terminals, dry docks and crew rotations. The platform that screens passengers is already the platform that manages the rest.

  • Terminal kiosks — the same kiosk product that runs a corporate lobby runs a gangway check-in
  • Crew — rotations and returning-crew records under the same identity model
  • Shipyard contractors — hundreds of trades across a dry dock window, each with their own prerequisites
  • Shoreside offices — ordinary visitor management for the operation behind the operation

Handling the data

Screening data is the most sensitive thing we hold.

Passenger names, dates of birth and document numbers, matched against criminal and sanctions sources. It is treated accordingly.

Yours to clearLoaded passenger data can be cleared from the dashboard — imported records alone, or everything — with an export first if you need to keep the record elsewhere.
ExportableAny filtered view exports to CSV, so your own retention and reporting systems stay the system of record.
Scoped accessScreening is a role. The people who adjudicate matches are not automatically the people who administer sites and kiosks.

How we build

This started as somebody's problem, not a market study.

Everything on this page traces back to an operator describing what actually breaks. If you run a cruise, port or shipyard operation and your version of the problem is different, that difference is the useful part of the conversation — we would rather hear it now, while the design is still moving.

Cruise & maritime

Bring us a manifest and a sailing date.

Spreadsheets included. We'll show you the screening pipeline against your own structure, and be straight about what is built and what we'd build for you.