Access control

«Access Control» connects contractor documentation with the turnstiles and doors of your sites: the access system asks goPrevina whether a contractor may enter, and the answer depends on their document compliance.

1. What is on the screen

At the top, four figures: «Total Verifications», «Allowed Rate», «Active API Keys» and «Active Webhooks». Below, the tabs «Settings», «API keys», «Access Log», «Webhooks» and «Statistics». The screen opens on «Settings».

2. Deciding when access is allowed

Under «Compliance Requirements» set the «Required Compliance Percentage» and whether you switch on «Allow Partial Compliance» (otherwise 100 % is required). Under «Critical Document Types» tick the documents that must always be valid whatever the percentage: if one is missing or expired, access is denied.

Under «QR Code Settings» you decide how many hours a QR code is valid, and under «Verification Settings» whether each worker is verified, whether allowed attempts are also logged and for how many minutes the status is cached. Click «Save».

3. Connecting the turnstile system

In «API keys» click “Create API Key”, give it a “Name” (the reader or the site) and, optionally, an “IP Whitelist”. The access system sends that key in the X-API-Key header when it calls GET /api/v1/access-control/verify/{contractorCIF}, as the “Integration Guide” explains. Create one key per reader, so you can disable just the one that is withdrawn.

In «Webhooks», “Add Webhook” notifies your system when a contractor's compliance changes; the requests carry the HMAC signature in X-Webhook-Signature.

4. Checking what happened

«Access Log» lists every verification; filter by tax ID, access point, result and dates. If someone complains they were not let in, search for their tax ID: the result gives the reason (expired documents, low compliance, contractor blacklisted or not found, invalid or expired QR).

«Statistics» summarises for a date range the verifications, the allowed and denied ones, the average response time, the daily trend, the denial reasons and the busiest access points.

5. Who can do it

Changing the settings and creating or disabling keys and webhooks requires edit permission. CAE Coordination is, by default, visible only to administrators.