Skip to main content

Visitors setup guide for Martyn's Law (UK)

Learn how to configure Envoy Visitors to meet your duties under the Terrorism (Protection of Premises) Act 2025, keep accurate onsite records, and respond effectively in an emergency.


Overview

This guide is for admins configuring Envoy Visitors at UK premises subject to Martyn's Law. It assumes you need to demonstrate documented procedures, maintain accurate records of everyone on site, and produce an audit-ready evidence base for the Security Industry Authority (SIA).

Compliance and Operational Requirements

Martyn's Law places a legal duty on qualifying premises and events to put reasonably practicable protective procedures in place. The duty scales with capacity and applies to any premises used for a qualifying activity — including retail, hospitality, education, healthcare, leisure, and more.

Standard Duty premises (200–799 capacity) must have documented procedures for evacuation, invacuation, lockdown, and communication during an incident, and must notify the SIA of their qualifying status. The core operational requirement is straightforward: you need to know who is on your premises at any given moment and be able to communicate with them quickly.

Enhanced Duty premises (800+ capacity) must meet all Standard requirements and additionally produce a documented terrorism risk assessment, maintain a written security plan, name a senior responsible individual accountable for compliance, and be prepared for SIA inspection. At this tier, the audit trail is not optional. Inspectors will expect to see evidence of procedures, drills, and records.

Recommended Features and Configuration

Know who's on your premises at all times

The foundation of Martyn's Law compliance is an accurate, real-time picture of who is inside your building. A paper sign-in sheet or an access log that only records entry and not presence will not meet the standard the SIA expects.

Visitor sign-in: capture every visitor, contractor, and delivery at the point of arrival, with a live log of who is currently on site (https://eu.envoy.help/en/articles/9944795-how-to-sign-in-visitors)

Visitor types: create separate sign-in flows for contractors, regular visitors, and members of the public, each with appropriate questions and requirements (https://eu.envoy.help/en/articles/9944753-sign-in-flows)

Visitor photos: capture a photo at sign-in so staff can visually verify identity during an incident or evacuation (https://eu.envoy.help/en/articles/9898409-setting-up-visitor-photos)

Control access before visitors arrive

Martyn's Law requires premises to take reasonably practicable steps to protect people from a terrorist attack. For many sites, that preparation starts well before the front door.

Invite approvals: require a review on every visitor invitation before it is sent, so no one arrives unvetted (https://eu.envoy.help/en/articles/9944693-invite-approvals)

Disable walk-in visitors: require all guests to pre-register before arriving, allowing time for any necessary checks (https://eu.envoy.help/en/articles/9944693-invite-approvals)

Document uploads: Ensure contractors and visitors hold relevant safety certifications prior to coming onsite.

Contractor Assessments: require visitors to pass safety and security tests prior to coming onsite (https://eu.envoy.help/en/articles/11883769-visitor-assessments)

Watch list: maintain an internal list of flagged individuals and receive an alert if they attempt to sign in (https://eu.envoy.help/en/articles/14623703-watch-list)

Block list: hard-block banned individuals from signing in across all your locations (https://eu.envoy.help/en/articles/9944758-security-in-your-workplace)

ID scanning: validate government-issued ID at sign-in (https://eu.envoy.help/en/articles/9944756-id-scanning)

Create an audit trail that the SIA can review

The SIA can inspect Enhanced Duty premises and investigate suspected breaches at any tier. Every sign-in, drill, and emergency response should leave a record.

Visitor log: a complete, timestamped record of every entry and exit across your locations (https://eu.envoy.help/en/articles/9899086-using-the-visitor-log)

Exporting visitor data: one-click CSV export of sign-in records, visitor details, and emergency response data for SIA submissions or internal reviews (https://eu.envoy.help/en/articles/10128537-exporting-visitor-data)

Legal document signing: capture acknowledgment of site safety rules, emergency procedures, or any other document at the point of sign-in, with a timestamped record attached to each visit (https://eu.envoy.help/en/articles/10984457-setting-up-legal-document-signing)

Standardise across all your sites

Multi-site organisations: venue groups, NHS trusts, academy chains, and leisure operators need consistent procedures across every location. A site that runs a different process from the rest is a compliance gap.

Global sign-in flows: publish one approved sign-in flow to every location simultaneously, so procedures are identical wherever the SIA looks (https://eu.envoy.help/en/articles/9893942-global-sign-in-flows)

Multi-location management: configure, monitor, and export data across all your sites from a single admin account (https://eu.envoy.help/en/articles/14624997-global-overview)

Did this answer your question?