Visitors setup guide for Energy & Utilities
This guide is for admins configuring Envoy Visitors at energy, oil and gas, and utility companies subject to NERC CIP, FERC, PHMSA, or regional regulators. Visitors can be deployed across corporate offices, substations, control rooms, and field assets.
Compliance and operational requirements
NERC CIP-004 (personnel and training) and CIP-006 (physical security) require background-checked, trained personnel to access critical cyber assets with full visitor audit evidence. Outages and turnarounds bring contractor surges. Many assets are unmanned, so the sign-in experience must work without a receptionist or even an iPad.
Recommended features and configuration
Personnel screening and training proof
Identity Screening: background-check posture aligned with CIP-004 expectations
Visitor assessments: critical infrastructure training and acknowledgement
Global visitor assessments: apply the same training proof at every substation
Sign in without a kiosk
Static QR code display: sign in from a phone at unmanned sites, no need for an iPad
Lockdown restricted areas
Visitor types: create different sign-in requirements for the control-room, substation, yard, office
Sign-in flow rules: auto-deny or escalate based on responses
Access control integrations like Kisi, Brivo, AMAG, or Avigilon Alta: specific credential provisioning based on designated access
Emergency response
Using Visitors for evacuation: real-time roster for incident commanders
Emergency notifications: create incidents and send messages to all visitors and employees to maintain visibility across all on-site parties
Single pane of glass across sites
Global overview and global analytics for Visitors to provide at-a-glance insights on personnel traffic

