This integration is installed 'per-location'
Overview
Genetec Security Center is the unified security platform from Genetec that blends IP security systems within a single intuitive interface to simplify your operations. From access control, video surveillance, and automatic license plate recognition to communications, intrusion detection, and analytics, Security Center empowers your organization through enhanced situational awareness, unified command and control, and connectivity to the cloud.
PREREQUISITES
A license will be required from Genetec (additional purchase may be necessary).
Genetec will need to activate the following product part number: GSC-1SDK-ENVOY-Visitors.
We recommend reaching out directly to Genetec for assistance with activating the license.
The following IPs must be whitelisted for inbound and outbound communication:
18.204.164.109
52.6.210.64
52.86.90.108
The following ports must be whitelisted for inbound and outbound communication:
4590
443 (if you plan to use HTTPS) - HTTPS requires an SSL Cert
Validate the port configured within the Genetec WebSDK and confirm the port is whitelisted alongside the IPs above.
Create an admin user in GSC with the following limited set of permissions:
Create entity User with username "envoy"
Choose Privilege template: Operator
Once saved, update the following permissions:
SDK Log on using the SDK: Allow
View Cardholder Properties: Allow (for all operations below)
View Door Properties: Allow (view only necessary)
Door activities: Allow (REQUIRED for Auto Check-in)
Envoy does not support self-signed SSL/TLS certificates. Envoy requires a certificate that chains to a public root CA
How does this integration work?
Envoy will send a record of every visitor who signs in on your kiosk to Genetec as a visitor to automatically create an identity within the Security Desk. You can configure Envoy to apply a certain Cardholder group for your visitor types. You can then use all of Genetec’s features for your visitors, such as badge provisioning, security alerts, and more.
Enabling Envoy + Genetec
You’ll need sufficient permissions on your Genetec account to manage visitors and complete this installation. Either become an administrator or ask your administrator for help before completing these steps.
Step 1: API Access
Search for and click on Genetec Security Center. Select Install.
Two static IPs will automatically load on the page. Be sure to whitelist these two IPs before proceeding with the configuration:
18.204.164.109
52.6.210.64
52.86.90.108
Next enter your on-prem IP and port, or URL under Genetec Web SDK URL.
Under Username and Password type in your Genetec admin login credentials and select Next Step.
Step 2: Partitions
Follow the instructions for Step 2 only if you are using Genetec SaaS or on-premises partitions. On-prem installations without partitions can skip this step and proceed.
Click Next Step.
Step 3: Visitors
(Optional) Decide if you want to register your visitors in Genetec's Visitor Management solution.
Genetec Visitor Management has its own record type with visitor-specific features (escort field, visitor name update via actOnEntity), whereas cardholder mode treats the visitor like any regular access-control cardholder.
Assign Envoy Visitor type(s) to a predefined Cardholder Group.
This allows certain Envoy visitor types to have predefined access to specific doors and/or elevators once you assign the visitor a hard badge.
Only invited guests will be synced to Genetec (Optional).
Only sync invited guests into Genetec.
Signing out via Envoy checks out the visitor in Genetec (Optional).
Check out the visitor in Genetec when the guest signs out of Envoy.
Access Duration
Choose the duration for which signed-in visitors will have valid credentials.
Advanced Access (Optional)
If you would like invited visitors to get credentials in advance, please select a time period here.
Select if you would like QR Code Credentials and fill out min and max card number fields
Minimum and Maximum card ranges in addition to Facility Code, are required to issue credentials.
These are card ranges are created and added to the user. The QR code is generated from the card #. The ranges follow the Genetec format, such as Wiegand 26-bit, which gives you a range of 0 to 65,535.
An email will be sent with the QR CODE for access.
Optional check-box for PIN Code Credentials
Click Next Step > Complete Setup to save the configuration.
Note: Invite records are added to Genetec upon creation, with a credential expiry period set to the expected arrival time.
For physical cards, visitor information is pushed to Genetec from Envoy, a user record is created in Genetec with the appropriate cardholder group, and then there are two options for handing over badges:
1. There are pre-numbered cards and the Visitor's user record in Genetec is assigned a card number. Then, the card can be handed to the Visitor for access.
2. If there are not pre-numbered cards, a card number will not be automatically assigned to the Visitor. Instead, a blank card on a reader hooked up to Genetec can be scanned which will then capture that card's number and assign it to the visitor's record.
Please contact Genetec for setting up card access if not configured.




