The people who see it first
don't work for you.
A contractor notices a fire exit chained shut. A visitor watches someone try three car doors in a row. Neither has your number, your app, or any idea who to tell. So they tell nobody, and the first you hear of it is afterwards.
Most of what goes wrong is seen by someone with no way to tell you.
Every site has a reporting gap. Staff have a radio, a room and a supervisor. Everybody else has nothing: contractors, visitors, delivery drivers, stallholders, the crowd. On the days that matter most they outnumber your team by a wide margin, and they are the ones standing next to the problem.
The usual answer is a generic email address on a sign, which works about as well as you would expect. Nobody has their laptop, nobody remembers the address, and what does arrive is a paragraph of prose that somebody has to read, interpret, chase and remember to close. A reporting channel that costs effort to use gets used after the fact, by which point it has stopped being a report and become an incident review.
So reporting now lives on the page you already point people at. The QR sign-up link that puts somebody on your alert list can carry a second, entirely independent section: Report an issue. Scan the code, answer your questions, send.
The two halves of that page do not depend on each other in either direction. Somebody who never enters a phone number can still report. Somebody who signed up ten minutes ago can report without doing it again. And when the recipient list behind the link reaches the end of its date window and stops taking sign-ups, reporting carries on regardless. A list window decides who gets texted. It has no business deciding whether a hazard can be reported.
From a code on a gate
to a named owner.
Six things the reporting page does between somebody noticing a problem and your team closing it.
The Code Is Already On The Wall
Your Questions, Not Ours
Where, Precisely
A Queue, Not An Inbox
Someone Owns It
A Record That Holds Up
The triage principle
A public form where anybody can tick “urgent” sorts by confidence.
Yours sorts by risk.
Reporters describe what they saw. Priority, ownership and status are set inside Security Ops, by people who can see every other report on the site that day. It is the one decision that keeps a public queue usable past its first busy afternoon.
Open to everyone. Not open to everything.
A page that anyone on the internet can post to needs its limits designed in rather than bolted on. Access is the unguessable link itself, a CAPTCHA challenge, and rate limiting on both the reporter's connection and the link. Generous enough for a whole venue sharing one network, tight enough that a queue cannot be buried.
It is also, deliberately, not an emergency channel. Your own wording sits at the top of the form telling people what to do if somebody is in danger right now, and the queue describes itself the same way to the team working it. Emergencies belong on the alert path, where the response page, the roster and the incident map are waiting.
More from the blog
and what else shipped.
One scan to join.
One scan to report.
Author your question set, attach it to a sign-up link, and the next person who scans the poster can tell you what they have just seen. Start a free trial and have it live this afternoon.