The Front Door Gets a Brain
In August 2025, Envoy became the visitor management layer inside Brivo's access control suite, signaling that VMS is now a module inside physical-security stacks, not a standalone app. The reception desk used to be a piece of furniture. Now it's a decision point. The visitor management market is being reshaped by AI-powered biometrics and new critical infrastructure regulations, forcing enterprises to treat the front door as a data-driven security perimeter and creating a new battleground for vendors and the engineers who build them.
The broader workplace management market, valued at $3.6 billion in 2022, per Research and Markets' data, targets $8.4 billion by 2030, as Research and Markets reported, growing at an 11.3% CAGR, with hybrid workplace as the primary catalyst for touchless, cloud-based visitor management. The pandemic accelerated the pivot: hybrid work forced touchless check-in from nice-to-have to baseline requirement.
Regional splits reveal where regulation bites hardest. The U.S. market sat at $1.2 billion in 2022, Research and Markets found. Germany leads European growth at 11.7% CAGR. Japan and Canada track close behind at 9.4% and 11% respectively. China, starting from a smaller base, projects the steepest climb to $809 million by 2030 at 13.6% CAGR, according to Research and Markets. North America dominates overall, driven by stringent security regulations and early adoption across corporate and government sectors.
AI is the new differentiator. Vendors now reserve advanced screening, including facial recognition, predictive analytics, and real-time watchlist matching, for enterprise tiers, creating upsell ladders that support lifetime value. Visitly and other vendors describe the feature set: automated compliance checks, self-sovereign identity frameworks, instant alerts when a flagged individual attempts entry. The front desk doesn't just log visitors anymore. It evaluates them.
NSM-22 Rewrites the Rules
The White House didn't issue a suggestion. In April 2024, National Security Memorandum 22 replaced Presidential Policy Directive 21, the Obama-era framework that had guided critical infrastructure policy since 2013, and moved the federal government from voluntary partnership to regulatory mandate. The Congressional Research Service calls NSM-22 "the first comprehensive high-level policy guidance on critical infrastructure security and resilience in more than a decade." PPD-21 looked inward, focused on maturing a homeland security enterprise barely a decade old. NSM-22 looks outward: nation-state cyber actors, supply chain compromise, malign foreign investment, climate-driven hazards. The threat model changed. The policy had to change with it.
The memorandum keeps the 16-sector structure but rewrites the rules of engagement. The Secretary of Homeland Security now coordinates a national effort backed by statutory authority, not goodwill. Sector Risk Management Agencies, the day-to-day federal interfaces for each sector, must produce sector-specific risk assessments and risk management plans every two years, starting within 270 days. The National Coordinator, housed at DHS, builds a cross-sector risk assessment and a recurring National Infrastructure Risk Management Plan. Most critically, federal agencies with regulatory authority "shall utilize regulation, drawing on existing voluntary consensus standards as appropriate, to establish minimum requirements and effective accountability mechanisms for the security and resilience of critical infrastructure." That "shall" does heavy lifting. The Clinton-era consensus, voluntary public-private partnership as the primary vehicle, is explicitly abandoned. The directive states plainly: "Voluntary approaches to enhance critical infrastructure security and resilience have meaningfully mitigated risk over the past decade, but more must be done."
For operators, the mechanism matters more than the memo. NSM-22 directs SRMAs, in coordination with regulators, to develop sector-specific minimum security and resilience requirements and a plan to implement them using existing authorities — or to propose new authorities where current ones fall short. The National Coordinator reviews those proposals to harmonize across sectors. The National Cyber Director, working with OMB, leads cybersecurity regulatory harmonization. Federal procurement and grant rules become enforcement levers: agencies "shall leverage existing authorities to promote security and resilience… including integrating security and resilience into Federal acquisition programs relating to critical infrastructure" and "utilizing grants, loans, and other Federal Government funding mechanisms to ensure minimum security and resilience requirements and effective accountability mechanisms are incorporated." Where law blocks mandatory requirements, agencies must attach guidance and recommendations to federal funding. The message: compliance buys access to federal dollars; non-compliance risks losing them.
The National Coordinator also maintains a list of Systemically Important Entities — organizations whose disruption would cascade nationally. That list, informed by SRMA input, satisfies the Executive Order 13636 requirement and will inform where regulators apply "adequate risk management requirements." The first SIE list has no published deadline, but the 30-day, 45-day, 180-day, and 270-day clocks for SRMA leadership, strategic guidance, execution plans, and sector risk plans started ticking in April 2024. DNI intelligence estimates on critical infrastructure threats were due within 180 days; annual intelligence sharing reports follow.
What this means for the front door: physical access control is no longer a facilities afterthought. The directive demands "minimum security and resilience requirements" built "upfront, and by-design." Visitor management, including identity verification, audit trails, and real-time visibility into who enters sensitive facilities, sits squarely in that design requirement. Banking regulators already treat visitor logs as compliance evidence. Energy, transportation, water, and communications sectors will follow as SRMAs translate the national framework into sector-specific rules. The compliance afterthought becomes a regulated control point. Vendors that can't produce tamper-proof logs, biometric verification, and API-level integration with access control systems will find their customers unable to meet the new minimums. The regulatory hammer doesn't just hit the operator. It hits the supply chain.
Biometrics, APIs, and the Physical-Data Stack
The visitor management system used to be a database with a receptionist. Now it is a control plane. The shift happens at the integration layer: facial recognition kiosks, access control panels, turnstiles, CCTV, HR directories, and identity providers all speaking the same API language in real time. When a visitor's face matches a pre-approved template at the lobby kiosk, the door releases, the badge prints, the host gets a Slack ping, and the audit log writes itself — no card, no PIN, no clipboard. Vizitor claims 1.8-second verification and an 82 percent reduction in check-in time versus manual processes. The same biometric credential can then clock the visitor in and out, eliminating buddy-punching at manufacturing plants and data centers alike.
Facial recognition has moved out of government facilities and into mainstream enterprise, including offices, healthcare, finance, manufacturing, and data centers, replacing cards, badges, and PINs. The market now lists six specialist vendors: Visitly, SwipedOn, ASIS Technologies, Artec ID, IDEMIA, and Suprema. Visitly positions itself as compliance-first; Depctor AI targets operational intelligence and customer analytics alongside security; Vizitor emphasizes zero-touch check-in and GDPR, CCPA, and PDPA alignment. But the technology alone is not the product. The product is the integration.
A VMS integration connects the reception workflow to the systems that actually control a workplace: access control, turnstiles, barriers, CCTV, employee directories, HRMS, identity platforms, badge printers, notifications, and reporting tools. Vizitor integrates with leading access control systems via API and webhooks; a successful facial recognition match triggers an automatic door release signal, eliminating the need for a separate credential at the entry point. Each kiosk or entry point can carry its own configuration, specifying which visitor types require biometrics, what confidence threshold triggers a secondary check, whether tailgating detection is active, and which watchlist applies. The result is a per-door policy engine, not a building-wide setting.
Architecture is shifting to the edge. Depctor AI and Vizitor both process face recognition locally on the edge device, keeping raw video off the cloud, cutting latency, and reducing infrastructure dependency. Biometric templates are stored as encrypted mathematical representations, not images. Data retention periods are configurable; deletion on request is a standard feature. Vendors now advertise "no vendor lock-in," offering support for existing cameras, standard RTSP streams, open AI model architectures, and flexible deployment hardware. Multi-camera continuity lets the system track a visitor across zones and branches without re-enrollment.
Compliance drives the stack as much as performance. Enterprises now ask: Is biometric data encrypted at rest and in transit? Does the system support GDPR, CCPA, BIPA? Can it produce audit trails and real-time access monitoring? Does it integrate with existing identity platforms? The FTC has signaled significant monetary penalties and increased privacy restrictions on biometric use under its UDAP authority, including disclosure, informed consent, data deletion, and accountability requirements. A responsible deployment combines facial matching with clear visitor registration, approval workflows, liveness detection, human review, secure storage, retention limits, audit logs, and a practical non-biometric fallback. Facial recognition should assist an access decision, not silently become an unrestricted surveillance system.
Before procurement, security teams document the specific purpose, why QR codes or receptionist verification are insufficient, whether the system uses 1:1 verification or 1:N identification, what images and templates are created, where each data type is processed and stored, and who can access, search, export, or delete biometric records. High-intent buyers require consent and lawful basis, biometric data minimization, liveness detection with accuracy benchmarks, fallback check-in, role-based access to biometric data, and integration with QR passes, gates, and visitor records. The stack is no longer a check-in app. It is a real-time security perimeter with an API surface.
Three Bets on the Perimeter
The visitor management market has consolidated around three distinct plays: a workplace platform that treats the front desk as a workflow hub, an access-control company that bolted visitor management onto its hardware stack, and a cloud-identity giant that just dropped a VMS into its marketplace. Each approach reveals a different bet on where the enterprise perimeter actually lives.
Envoy has built its lead on multi-site orchestration. Its system lets onsite teams run check-in, badge printing, and host notifications locally while global administrators enforce policy, pull audit logs, and manage users across every location from a single dashboard. That architecture maps directly to the compliance demands hitting critical-infrastructure operators under NSM-22 — centralized visibility with distributed execution. The company's hiring board shows 18 salaried roles with a median band of $197,000, including a Product Lead for Visitors at $200,000–$400,000 and a SecOps & Threat Detection engineer at $265,000–$300,000. The talent investment matches the product pivot.
Kisi took the opposite route. Founded in 2012 in Brooklyn, it started as a cloud-managed door reader, enabling keyless entry via phone, and expanded upward into visitor management, intrusion detection, and video integration. The hardware-first DNA shows: the Reader Pro (2021) added MotionSense wave-to-unlock, a narrower mullion-mount footprint, and offline functionality so doors stay operational when the cloud drops. Kisi's integration list reads like a physical-security stack: Eagle Eye Cloud VMS, VIVOTEK cameras, Singlewire for facility lockdowns. The company secured $1.5 million from Point Nine Capital in 2015, then a venture-debt round in 2022; Tracxn ranks it fourth among 111 active competitors but first in total funding raised. Headcount grew from 193 to 256 in a year. Estimated revenue: $26.9 million. Kisi's bet is that the perimeter is the door itself — and whoever controls the reader controls the data.
Microsoft entered sideways. At Ignite 2025, the Entra team unveiled Agent ID, extending Zero Trust identity to AI agents, a signal that Microsoft views every autonomous workload as a "visitor" needing verification. Simultaneously, a Power Apps–based Visitor Management System appeared on the Microsoft Marketplace, promising real-time visitor flow, compliance reporting, and Entra ID integration. Microsoft doesn't need to win the front-desk UI; it needs the identity layer underneath it. By embedding visitor management in the Entra ecosystem, it turns every Azure AD tenant into a potential VMS customer without a new contract.
The divergence is instructive. Envoy sells workflow unification for multi-site enterprises. Kisi sells the reader as a platform, monetizing hardware attach and expanding into adjacent physical-security modules. Microsoft sells identity as a service, with visitor management as a feature that deepens Entra lock-in. All three are converging on the same requirement: audit-ready, real-time visibility that satisfies NSM-22 and sector-specific mandates. The vendor that turns the front door into a programmable policy enforcement point — not just a log — wins the enterprise perimeter.
Why Engineers Are Flooding Physical Security
LinkedIn lists more than 10,000 open Physical Security AI roles across the United States as of September 2025. The postings read like a taxonomy of the new perimeter: Senior Product Manager for Security & Urban Operations at FieldAI in Irvine, Director of Datacenter Security Systems at AWS in Seattle, Global Security Video Analytics Project Manager at General Dynamics in Arlington, Principal Staff Engineer for Indoor Location Intelligence & Sensor Fusion at Motorola Solutions in Richardson, Principal Robotics Architect for Physical AI & Autonomous Systems at Analog Devices in Wilmington. Verkada seeks a Product Manager for Perimeter & Intrusion Security in San Mateo. Cobalt AI needs a Physical Security Specialist for overnight shifts in Provo. Okta wants a Principal for its Global Security Operations Center in Washington, DC. The list runs through Nscale, Skydio, Fluidstack, Seagate, Accenture, Fujitsu, Fleet Data Centers, and True Anomaly, each hunting engineers who can fuse computer vision, large language models, and real-time sensor data into systems that guard physical doors.
Three forces drive the surge: NSM-22 compliance deadlines for critical infrastructure, Deloitte's finding that 58 percent of enterprises already use physical AI in some form (rising to 80 percent within two years), and a documented shortage of human guards. The talent market is also reorganizing around augmentation. HBS Working Knowledge reported in 2025 that postings for repetitive, GenAI-replaceable tasks fell 13 percent, while demand for analytical, technical, and creative work grew 20 percent. Deloitte confirms the shift: new titles, such as AI operations managers, human-AI interaction specialists, and quality stewards, signal that AI has become a structural component of work organization, not a feature layer. Meanwhile, 77 percent of companies now factor an AI vendor's country of origin into procurement decisions, and 58 percent build stacks primarily with local providers. Sovereign AI requirements, driven by NSM-22 and parallel mandates, mean the engineers who can deploy on-premises, air-gapped inference pipelines for biometric screening will command the highest value.
Roles cluster into four bands. Platform vendors need full-stack engineers who can ship multi-tenant SaaS with sub-second latency. Hardware-software integrators like Kisi and Verkada hire sensor-fusion specialists. Critical-infrastructure operators, including AWS, General Dynamics, and Nscale, recruit datacenter security architects who understand both NERC-CIP compliance and video analytics pipelines. And a new tier of "Physical AI" consultants has emerged: Fujitsu advertises a Senior Managing Consultant for Physical AI, Accenture a Physical AI Delivery Manager, Fleet Data Centers a Principal for Facilities AI.
| Role Cluster | Representative Title | Company | Location | Salary Band (USD/yr) |
|---|---|---|---|---|
| Platform Engineering | Member of Technical Staff, Full-Stack (Staff) | Envoy | San Francisco, CA | $265,000–$300,000 |
| Security Operations | Member of Technical Staff, SecOps & Threat Detection | Envoy | San Francisco, CA | $265,000–$300,000 |
| Product Leadership | Product Lead, Visitors | Envoy | San Francisco, CA | $200,000–$400,000 |
| Sensor Fusion | Principal Staff Engineer, Indoor Location & Sensor Fusion | Motorola Solutions | Richardson, TX | Not disclosed |
| Datacenter Security | Director, Datacenter Security Systems | AWS | Seattle, WA | Not disclosed |
| Video Analytics | Global Security Video Analytics Project Manager | General Dynamics IT | Arlington, VA | Not disclosed |
| Perimeter Product | Product Manager, Perimeter & Intrusion Security | Verkada | San Mateo, CA | Not disclosed |
| AI Consulting | Senior Managing Consultant, Physical AI | Fujitsu | Dallas, TX | Not disclosed |
Envoy's board, with a median of $197,000 and a band of $109,000–$330,000, added two positions in the past week alone: a Product Lead for Visitors and a Product Lead for Spaces, both carrying $200,000–$400,000 ranges. The company also seeks a Product Designer at $210,000–$230,000 and an Admin Experiences engineer at $205,000–$225,000. These figures sit well above the national medians CNBC reported in January 2025: AI engineer $106,000, AI consultant $114,000. The premium reflects a skill set that blends distributed systems, edge inference, and regulatory fluency — exactly the combination Deloitte identifies as the top barrier to AI integration. "Insufficient worker skills are the biggest barrier to integrating AI into existing workflows," the firm's 2025 State of AI in the Enterprise survey found, noting that education — not restructuring — remains the primary talent response for 53 percent of companies.
The winners will be engineers who can make a vision model talk to an access controller and write the audit log that satisfies a DHS inspector — all before the visitor reaches the turnstile. The front door just became the hardest engineering problem in the building.
Working in frontier tech? Zero G Talent tracks the openings: see every open Envoy role, browse frontier tech jobs, the companies hiring, and the people building the field.