Kinds of device
Your own list — a laptop, a memory stick, an external disk, a camera, a phone, or whatever else your sites actually see declared. Each kind carries:
Retiring a kind leaves everything already filed under it untouched.
A kind that requires a signature but is left with no default period authorises for ever — right for
an employee’s own laptop, rarely what anyone means for a contractor’s disk. Any kind in that state is
named directly on this screen; whoever signs can still set a date on the device itself.
Rules that decide first
A kind of device can only say “a camera” or “a phone” — it cannot say “anything over a terabyte”, “anything a contractor brings”, or “everywhere except head office”. A rule can, and rules are checked before the kind’s own default, in order, with the first match deciding. Where none matches, the kind of device decides as normal. Each rule can be scoped to one site or to every site, and states plainly whether a match means a manager signs or waved through. A rule the gate’s context cannot answer — because it asks about something this device does not have — is skipped rather than guessed at, and the device register shows which rule actually decided each row.Checking a rule
Check a device replays the whole walk against a real declared device: which rules were asked, whether each matched, and which one — a rule or the kind of device itself — made the final call. A rule that never matches looks exactly like a rule that is working right up until you check, which is why this exists rather than trusting the rule list to read correctly on its own.Visitors and devices
Where a declared device is authorised, and where this configuration takes effect.
The gate
The scan screen these rules and defaults are read by, in real time.

