A contractor access management system checks a contractor's documents and authorisation before entry rather than after an incident: trade licence and insurance validity, worker-level induction status, an approved work order or permit to work, and any zone restriction. Workers who pass are issued a time-bounded credential; those who do not are stopped at the gate with a recorded reason.
The system exists for the question asked after an incident: who authorised this person to be here, on what evidence, and can you produce it.
- Licence, insurance and induction checked before entry
- Worker-level, not just company-level, control
- Entry gated on an approved permit or work order
- Time on site recorded per worker and per job
The gap between the contract and the gate
Contractor compliance usually lives in two places that never meet. Procurement holds the trade licence, the insurance certificate and the signed scope in a folder. The gate holds a logbook and a guard who has no way to check any of it. So the control that was negotiated at contract stage is not the control operating at 07:00 when a van arrives, and the site admits whoever turns up in the right branded shirt.
The consequences arrive later and land on the site. An insurance certificate expired four months ago and nobody noticed because expiry was tracked in a spreadsheet with no owner. A worker who never attended induction was injured in a plant room. A crew was working on a live panel with no permit because the permit lived in a different system from the gate. In each case the question is the same — who let them in and on what basis — and the honest answer is that nobody checked.
- Compliance evidence sits in procurement; the decision is made at a gate that cannot see it.
- Company-level approval admits workers who were never inducted individually.
- Insurance and licence expiry tracked in a spreadsheet with no owner will lapse unnoticed.
- Permits live in one system and entry in another, so work starts without one.
- After an incident nobody can produce the evidence the entry was based on.
Solution overview
Swedish Technology puts the compliance check in front of the gate rather than behind it. Each contracting company is registered once with its trade licence, insurance and scope, and each expiry date becomes a live rule rather than a diary note — when insurance lapses, that company's workers stop being admitted, automatically, at every gate.
Below the company sits the worker. Individual workers are registered with their identity, their induction record and any competency the site requires, so a crew of six is six checked people rather than one approved company. Entry is then gated on the work actually authorised: an open work order, an approved permit to work, a time window and a zone. Workers who pass receive a credential valid for that job; the credential expires with it, so nobody carries site access three weeks after the job closed.
How the solution works
- 1Register the company Trade licence, insurance certificates, scope of work and contacts captured once, with every expiry date held as a rule the gate enforces rather than a note.
- 2Register the workers Individual identity, induction record, competencies and any medical or trade certification the site requires — because a company approval is not a person.
- 3Authorise the work Entry is tied to an open work order or an approved permit to work with a time window and a zone. No authorisation, no entry, and the refusal is recorded.
- 4Check at the gate The worker is identified at a kiosk, gate or guard app; the system checks company validity, induction, permit and zone in one step and returns allow, escort or deny.
- 5Work under control The credential grants only the zones the permit covers, for the window it covers. Overstay and out-of-zone reads surface to the supervisor.
- 6Close out Exit closes the visit and returns time on site against the job; the credential expires with the permit rather than waiting for someone to revoke it.
Key capabilities

Reference architecture
The decision is made by a rules engine that reads compliance, authorisation and zone together. Splitting those checks across three systems is the failure this design exists to remove.
Deployment options: Cloud or on-premise. Sites with an existing access-control system keep it as the device that opens the door; this layer decides whether entitlement should exist at all.
Hardware options
What the gate needs depends on how much certainty the site requires about which person is standing there.
| Device | Where it is used | Selection notes |
|---|---|---|
| Contractor kiosk | Contractor gate or FM office | Self-service registration, induction delivery and document capture. Removes the queue at a supervisor's desk on Sunday morning, which is when contractor volume peaks. |
| Guard app on a tablet | Manned gates | Shows the compliance answer as allow, escort or deny with the reason. A guard should never have to interpret an insurance certificate. |
| Turnstile or speed gate | High-volume industrial and construction sites | Enforces one-person-one-credential, which is what makes an on-site headcount trustworthy in an evacuation. |
| Biometric or card reader | Where identity certainty matters | Biometrics prevent credential sharing — the commonest way worker-level control is defeated — but carry their own consent and data obligations under UAE law. |
| Handheld reader | Roaming supervisor checks in zones | Lets a supervisor verify that the people in a plant room are the people the permit names. |
Swedish Technology supplies and integrates equipment from established manufacturers; selection follows the site survey and the certainty the risk assessment requires.
AI capabilities
Applied to documents and to patterns — the two places human checking reliably fails.
- Document extraction — Reads trade licences, insurance certificates and certifications, extracting issuer, number and expiry so validity becomes a date the system enforces rather than a scan nobody opens.
- Expiry forecasting — Flags documents expiring inside the window of work already scheduled, so a contractor is chased before the crew is turned away at the gate.
- Identity resolution — Matches a worker across companies and sites — the same person often works for several subcontractors — so induction and incident history follow the person.
- Behavioural anomaly detection — Flags patterns worth review: entries outside permit windows, repeated out-of-zone reads, or a company whose workers consistently arrive before their permits are approved.
Integrations
This system is only as good as the authorisation data it can read. These integrations can be designed and built within project scope.
| System | Integration point & data exchanged | Direction |
|---|---|---|
| CAFM / CMMS | Entry gated on an open work order, with arrival, time on site and departure written back against that job for verification of works performed. → Facility Management | bi-directional |
| Permit to work system | An approved permit becomes the entry authorisation, and its zones and window become the credential's scope. → Digital Permit to Work | bi-directional |
| Oracle / SAP procurement | Supplier master data and contract status read so a contractor with no live contract cannot be admitted, and so vendor records are not duplicated. → Oracle E-Business Suite | inbound |
| Access control | Time-bounded entitlement written into the installed system and automatically revoked when the permit closes. → Employee & Visitor Access Control Integration | outbound |
| HSE / incident management | Induction records and incident history attached to the worker, so a worker involved in an incident can be flagged across sites. | bi-directional |
| Finance / ERP | Time on site by company and job exported to support payment verification against claimed hours. | outbound |
The integrations above are designed and implemented within project scope using vendor APIs, webhooks or standard connectors. They do not imply partnership, certification or endorsement by the system owner unless stated on that vendor's official pages.
Dashboards & analytics
- On site now — Which contractors and which workers are on site, under which permit, in which zone — the list an evacuation and a supervisor both need.
- Compliance status — Companies with documents expiring or expired, workers with lapsed inductions, and the jobs scheduled against them.
- Gate activity — Entries, refusals and the reasons, escorted entries, and any override with the name attached to it.
- Time and cost — Time on site by company, job and worker, for payment verification and for service-charge allocation.
Security & deployment
Contractor personal data is scoped tightly: a guard sees the compliance answer and the worker's name and photograph, not their identity documents; a supervisor sees their own jobs; FM sees the site. Documents are stored encrypted with access logged, because a trade licence and an insurance certificate are commercially sensitive to the contractor as well as personally sensitive to its workers. Where biometrics are used, templates are stored as irreversible representations rather than images, and a non-biometric path remains available for workers who do not consent.
Data privacy
This system holds more personal data about contractors than most sites hold about their own staff — identity documents, certifications, sometimes biometrics — and those people are not the site's employees. Under UAE Federal Decree-Law No. 45 of 2021 the site operator is controller for what it collects at the gate, while the contracting company remains controller for its own employment records, so the boundary is set in the contract rather than assumed.
The standard position is to collect what the risk actually requires: identity verified and held as an attribute rather than a retained document image, induction and competency held for as long as the site's liability window requires, and biometrics only where the risk assessment justifies them and with a workable alternative for anyone who declines. Retention differs sharply by data class here — an incident-relevant record may need years, while a routine gate entry does not.
Industry use cases
UAE & GCC considerations
The UAE contracting market is heavily subcontracted, which is the operational reality this system has to survive: the company on the contract is frequently not the company whose workers arrive. Handling that honestly means registering the entity actually performing the work and linking it to the principal contract, rather than admitting anyone who says they are there for a named main contractor.
Documents are also specific here. Trade licences are issued per emirate and per free zone with their own numbering and expiry, workers are commonly identified by Emirates ID, and workforces are multilingual — so induction delivery in Arabic, English, Hindi and Urdu is a practical requirement, not a nicety. Where the site falls under SIRA in Dubai, or where biometrics are proposed, both the specification and the consent position need checking at design stage rather than after installation.
Implementation approach
- 1Risk and policy workshop What must be true before someone enters: which documents, whose induction, which permits, which zones need escort. This is an HSE decision the system then enforces.
- 2Contractor data migration Existing supplier and contractor records consolidated, documents captured and expiry dates extracted — usually the point at which the number of expired certificates becomes visible.
- 3Induction design Site induction content built and translated, with a validity period and a re-induction trigger agreed.
- 4Integration CAFM, permit, procurement and access-control connections built and tested against real work orders before go-live.
- 5Pilot at one gate Run at the contractor gate with the old process alongside, measuring refusal reasons — that list is the honest picture of current compliance.
- 6Rollout and review Extended to remaining gates and sites, then reviewed on refusal rate and document validity, which are the two numbers that show whether compliance is actually improving.
Why Swedish Technology
- We put the compliance check in front of the gate, because a folder in procurement has never stopped anyone walking in.
- Worker-level, not company-level — approval attaches to the person who actually enters.
- Entitlement expires with the permit, so nobody keeps site access three weeks after the job closed.
- Induction is delivered in the languages the workforce actually speaks.
- The same team integrates with your CAFM, permit, procurement and access-control systems, so the gate reads live authorisation rather than a copy.
Limitations & prerequisites
- The system enforces what it can verify. A forged document that passes extraction will be accepted; periodic manual verification against issuing authorities remains a process control.
- Worker-level control depends on registering workers, which subcontractors resist until refusal at the gate makes it necessary. Expect an adoption period with elevated refusals.
- Permit gating requires a permit system with usable data. Where permits are paper, that has to be addressed first or the gate is enforcing an empty rule.
- Biometrics reduce credential sharing but add consent, storage and equipment obligations, and are not always appropriate — the alternative path must remain workable.
- Time on site measures presence, not productivity, and should not be presented as a measure of work performed.
- References to SIRA, PDPL and licensing requirements are general guidance, not legal advice.
FAQ
A system that checks a contractor's compliance and authorisation before entry rather than after an incident: trade licence and insurance validity, worker-level induction, an approved work order or permit, and zone restrictions. Workers who pass get a time-bounded credential; those who do not are stopped with a recorded reason.
Because a company does not walk through a gate — a person does. Company approval admits workers who were never inducted, whose competency was never checked, and who may not even work for that company. Worker-level registration is what makes an induction record and an on-site headcount mean anything.
Expiry dates are extracted from the documents and held as live rules, not diary notes. When a certificate lapses, that company's workers stop being admitted automatically at every gate, and the system flags documents expiring inside the window of work already scheduled so the contractor is chased before a crew is turned away.
Yes, and it is the strongest form of this control. An approved permit becomes the entry authorisation, and its zones and time window become the credential's scope — so a crew cannot be inside a plant room without a live permit covering that work, and the credential expires when the permit closes.
Only where the risk assessment justifies them. Biometrics prevent credential sharing, which is the commonest way worker-level control is defeated, but they add consent, storage and equipment obligations under UAE law. Where they are used, a non-biometric path must remain available for workers who do not consent.
By registering the entity actually performing the work and linking it to the principal contract. UAE contracting is heavily subcontracted, so a system that only knows the main contractor will admit anyone claiming to work for them — which is the failure mode this design exists to close.
Yes. Entry and exit are recorded per worker and attributed to the job, so hours claimed can be checked against hours present. It measures presence rather than productivity, and should be presented that way — but presence is usually the disputed figure.
The evidence pack: who was on site, under which permit, in which zone, what was checked at their entry and what it returned, who approved any escorted or overridden entry, and the induction and competency records current at that time.
Discuss your site with an engineer
Tell us the venue, the expected visitor volume and the systems you already run. We reply with a technical view, a realistic scope and the next sensible step — a site survey, a working demonstration, or a full technical and commercial proposal.
Sources & evidence
- UAE Federal Decree-Law No. 45 of 2021 — Personal Data Protection Law — Governs collection, retention and cross-border transfer of visitor personal data in the UAE.
- ICP — Emirates ID — Issuing authority for the Emirates ID credential read at registration.
- UAE Ministry of Human Resources and Emiratisation — Context for workforce and contractor labour requirements in the UAE.
- Dubai SIRA — Security Industry Regulatory Agency — Regulatory context for security systems and personnel at Dubai sites.
Vendor and product names are trademarks of their respective owners; references are for technical context and do not imply partnership, certification or endorsement.