The lobby becomes one more system you already run. Sign-on uses your existing IdP. Admin accounts sync from your HRIS. Visitor events flow into the SIEM your team already watches. Webhooks and a REST API cover anything off-the-shelf doesn't. Pre-built apps for Slack, Teams, Webex, Calendar, document storage, and ticketing keep your stack intact.
SAML 2.0 and SCIM 2.0 are standard. Bring your own IdP if it's not on this list; custom OIDC and SAML are supported.
Standard SAML 2.0 SSO with SCIM 2.0 user-lifecycle provisioning.
Enterprise SSO via SAML 2.0 with SCIM and group sync.
Google SAML 2.0 with SCIM 2.0 user lifecycle.
SAML 2.0 SSO with SCIM 2.0 provisioning.
PingFederate-backed SAML with SCIM provisioning.
Generic OIDC and SAML 2.0 SSO.
On-prem Active Directory federation through ADFS.
Bring your own IdP. Generic SAML or OIDC supported.
SAML SSO ships on every plan. SCIM provisioning, on-prem AD, and HRIS sync scale with deployment depth. See pricing for the per-tier map.
The payload your IdP sends, the event your SIEM receives, and the metadata your IdP needs to trust us. Production examples, ready to copy.
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"userName": "elena.rivera@firework.com",
"name": {
"givenName": "Elena",
"familyName": "Rivera"
},
"emails": [
{ "value": "elena.rivera@firework.com", "primary": true }
],
"active": true,
"groups": [
{ "value": "site:sf-hq", "display": "San Francisco HQ" },
{ "value": "role:security-lead", "display": "Security Lead" }
]
}{
"id": "evt_4438A_2026-05-10T18:42:11Z",
"type": "visitor.watchlist_match",
"data": {
"visitor": { "id": "vis_2P39", "name": "[REDACTED]" },
"site": { "id": "site_sg_marina", "label": "Singapore · Marina office" },
"match": {
"list": "internal_blocklist",
"confidence": 0.94,
"handler": "auto_page_gsoc"
},
"host": { "id": "usr_8112", "email": "host@firework.com" },
"kiosk": { "id": "kio_03", "ip": "10.42.18.7" }
},
"delivered_at": "2026-05-10T18:42:13Z"
}<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://app.visitly.io/sso/saml/acs/<tenant>">
<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://app.visitly.io/sso/saml/acs/<tenant>" index="1" />
<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat>
</SPSSODescriptor>
</EntityDescriptor>Reviewer commentary on G2 and Capterra cites low training burden and quick reception adoption. Visitor management isn't a frequent IT ticket source. The kiosk is self-serve and host notification hits the channel the host already works in: Slack, Teams, SMS, or the MyVisitly app.
Trust badge published at every tier. Full report available under NDA via Trust Center request.
ISMS certified. Statement of Applicability available under NDA via Trust Center request.
Self-attestation across all 297 controls. Available under NDA via Trust Center request.
DPA template published. Sub-processor list published with change-notice cadence. 72-hour breach notification.
Standard Contractual Clauses and privacy program data-handling commitments.
BAA available for execution for covered-entity deployments. Encryption at rest and in transit.
Distinct from the Trust Posture above. These are documents, references, and tooling Visitly provides to support the compliance programs you own (HIPAA, ITAR, CMMC, NISPOM, OSHA, FERPA). Your auditor / C3PAO / OCR submission / counsel reviews your program; we provide visitor-side records.
Control-mapping reference to support your CMMC Level 2 evidence package. Available under NDA via Trust Center request. Visitly provides the mapping; your C3PAO assessor reviews your program.
Visitor-side controls (citizenship gating, escort workflow, audit trail) and per-tenant evidence export feed your regulated-area program.
Configurable retention windows, audit log search and export, SIEM event streaming, and legal hold when counsel asks.
BAA executed at contract. ePHI access controls and retention configurable to HIPAA Privacy Rule. Your covered entity owns the program.
.webp)
.png)
live across North America, Europe, and Asia
deployment time across all locations, moved off Envoy
Or talk to sales. We'll route you to a human who knows multi-location enterprise deployments, not a BDR running a script.
