VisitsTracker

VisitsTrackerWriting › QR checkpoints

What a QR checkpoint actually proves

Almost every patrol verification system on the market works the same way: put a tag at each point, ask the officer to scan it. It is worth being precise about what that record contains, because it is less than most buyers assume.

2026-08-146 min readGuard toursEvidence

The record a scan creates

When an officer scans a checkpoint, the system stores an identifier, a timestamp, and usually a coarse position. Read literally, that record says: this phone submitted this tag's identifier at this time.

That is a real fact and it is better than a paper sign-in sheet. It is also narrower than the claim it gets used to support, which is normally that an officer patrolled the site properly.

Three things it does not contain

Duration. A scan is instantaneous. Two officers, one who walked the floor for twenty minutes and one who opened the door, scanned, and left, produce identical records. If your contract specifies presence rather than touch, the evidence does not describe the thing being sold.

Proximity you can rely on. A QR code is an image. Photograph it once and it scans from anywhere, including the car park or a sofa. NFC is better because it needs physical contact with the tag, but tags can be prised off and relocated. Neither medium was designed to resist someone who wants to defeat it.

What happened in between. A tour of eight checkpoints creates eight instants and seven blanks. The blanks are most of the shift.

Why the category is built this way

Not carelessness: history. Guard tour verification began with mechanical watchclocks and then iButton wands, where a physical touch was the only signal available. Checkpoints were the technology, so checkpoints became the model, and the model outlived the constraint.

The modern pitch is "no proprietary hardware", and it is true as far as it goes. You no longer buy wands and readers. You still install a tag at every point, replace the ones that get painted over or vandalised, and depend on someone remembering to scan each one.

The alternative: measure presence directly

A phone that reports its position continuously can answer the duration question without anyone doing anything. Time spent inside a site boundary becomes an arrival, a departure, and a length. Nobody scans, so nobody forgets, and there is nothing at the site to maintain.

This only works if you are honest about the readings underneath it, which is the harder half of the problem.

The harder half: grading your own evidence

Location data is not uniformly trustworthy. A phone can be made to report a position it is not at. Readings arrive with wildly different accuracy. Two sites next door to each other produce genuinely ambiguous stops.

A system that silently discards the awkward readings looks cleaner and is worth less, because the moment somebody contests a record, the first question is what you left out. The useful approach is the opposite: keep everything, mark what you do not trust, exclude it from totals, and leave it visible.

So a faked reading never counts toward a patrol, an hours total or a mileage claim, but it still appears in the record and in whatever you send the client. A stop that could belong to either of two neighbouring sites is labelled ambiguous with both candidates kept, rather than resolved by a coin toss you never see. And each day carries a fingerprint, so if a reading is edited afterwards that day stops matching, and you can demonstrate the log was not altered instead of asking to be believed.

Where a tag still wins

One case, and it is a real one. A single site boundary cannot tell the third floor from the sixth. If your contract specifies interior checkpoints on separate levels of one building, a scan answers a question that presence at the address does not.

For perimeter patrols, mobile rounds, multi-site work and anything where the argument is about how long somebody stayed, the trade runs the other way.

The question to ask a vendor

Not "do you verify patrols", because everyone says yes. Ask instead: if my client disputes a patrol six months from now, what exactly can I put in front of them, and can they check it themselves rather than taking my word for it?

An answer that consists of a list of scan timestamps is worth knowing about before you sign, not after.

Questions

Is a QR checkpoint system better than paper?

Considerably. It timestamps automatically, cannot be filled in retrospectively at the end of a shift, and produces a report you can send a client. The limitation is what a scan contains, not whether it beats a sign-in sheet.

Can a QR checkpoint be defeated?

A QR code is an image, so photographing it lets it be scanned from elsewhere. NFC requires physical contact and is harder, though tags can be moved. Neither was designed as a tamper-resistant medium.

How is presence measured without a scan?

From time spent inside the site boundary, built only from readings the system is prepared to stand behind, with arrival and departure recorded. Nobody taps anything at the door.

What happens to a faked location reading?

In our system it is detected, marked, and excluded from patrols, hours and mileage, while staying visible in the record. Dropping it quietly would make the record look cleaner and prove less.

Published 2026-08-14 by the VisitsTracker team. More writing · Solutions