Every principal contractor runs on a number: how many people are on site right now. Emergency plans depend on it, WHS duties assume it, hoist scheduling and deck sequencing are constrained by it, and at least one site meeting a week argues about it. The industry's standard answers, turnstile cards and biometric readers, solve identity, which is a different problem, and they bring enrolment friction and a privacy load that has grown sharper since Australia's statutory privacy tort arrived. This post is the case for solving the count as a count: anonymously, per zone, live.
01 · WHY SITES COUNT, AND WHERE THE CURRENT TOOLS STRAINWhy sites count, and where the current tools strain
The hard requirement is the emergency case. Australian WHS regulations require an emergency plan, and Safe Work Australia's guidance is blunt about what it must handle: evacuation procedures and a way of accounting for everyone on site. "Accounting for everyone" is a counting problem under time pressure, and paper sign-in sheets plus a warden with a clipboard is the technology most sites still bring to it.
The daily requirements are softer but constant: knowing which decks are congested before the hoist queue proves it, whether the weekend crew actually matched the approved manifest, and whether anyone is in the structure after hours. Access systems answer these badly for one structural reason:
A turnstile counts entries at the gate. A site needs to know where people are, three hours and four levels after the gate.
Ins-minus-outs from the gate decays through the day: tailgating, gates propped open during deliveries, cards shared or forgotten, crews exiting through the loading bay. By 2 pm the "on site" figure is folklore, and it says nothing about distribution, forty people could be one comfortable spread across six levels or one dangerous crowd on Deck 3.
02 · THE BIOMETRIC DETOUR, AND WHY SITES ARE BACKING OUT OF ITThe biometric detour, and why sites are backing out of it
Fingerprint and facial readers arrived on sites to kill card-sharing, and they do. They also bring three costs that have worsened:
- Enrolment friction against subcontractor churn. A commercial site turns over dozens of subbies a week. Every one needs enrolment, consent paperwork and template deletion on exit, an administration program bolted to your gate, scaling with churn.
- A biometric honeypot. Templates of workers' faces or fingerprints are sensitive information under the Privacy Act at its strictest setting, and a breach is unfixable for the people in it; nobody re-issues a face.
- Live legal exposure. Since June 2025, individuals can sue directly over serious privacy invasions, and unions and workers know it. Biometric gate systems are exactly where that conversation starts on site, and consent extracted as a condition of working is contested ground.
The awkward truth is that most of what the site actually needed day-to-day was never identity. It was the count.
03 · WHAT ANONYMOUS ZONE COUNTING DOES ON A SITEWhat anonymous zone counting does on a site
An edge sensor over each deck, laydown area and muster point emits one thing: how many people are in the zone, updated continuously. On our architecture the frames are processed and discarded on the device, nothing biometric is ever created, so there is nothing to enrol, nothing to consent-manage, nothing to breach. What that buys operationally:
- A live site total that does not decay. Summed zones, refreshed every few seconds, robust to tailgating because it counts people where they are, not transactions at a gate.
- Muster verification with arithmetic instead of clipboards. Counts at muster points climbing while structure zones fall to zero is evacuation progress, live. A stubborn non-zero on Deck 3 tells wardens exactly where to look. The same logic we apply to stadium egress math applies to a site evacuation, scaled down and made rugged.
- Congestion before the incident. Density thresholds on the right zones, the loading deck, the hoist lobby, page the site manager when crowding builds, not after the near-miss report.
- After-hours intrusion as a count, not a camera. Any non-zero count in the structure at 2 am is an alert, with no footage of anyone to govern.
04 · DEPLOYMENT REALITY: A SITE IS NOT AN OFFICE CEILINGDeployment reality: a site is not an office ceiling
We are honest about where the engineering effort lives, because accuracy claims mean nothing without site truth. Sites are hostile: dust films over optics, vibration loosens mounts, power arrives from temporary boards, and the building you are sensing changes shape monthly. The practical answers are unglamorous, sealed enclosures, PoE off the site network, mounting plans that move with the deck cycle, and recalibration as part of the monthly site rhythm rather than a support ticket. High-vis, hard hats and partial occlusion are model problems, not deal breakers, but they are exactly what the ground-truth audit in a pilot exists to verify, on your site, not a showroom.
05 · THE PILOT THAT PROVES ITThe pilot that proves it
One structure, four zones, four weeks: gate lobby, two active decks, one muster point. Run the anonymous counts parallel to the existing sign-in process, then compare three numbers at the end: the 2 pm site total (count versus decayed gate figure), one muster drill timed with both systems, and the after-hours zero. If the count does not beat the clipboard on all three, you have lost four weeks and gained an audit of your gate data. If it does, the safety case writes itself. The vertical overview is on our construction page, and if you have a structure worth the four weeks, that is a conversation.
