Counting people out is the hard part
Gateless entry gives a perfect entry count and no exit count, so live occupancy is an estimate that drifts up all day. Show the drift, and let it decide when to count exits.
A QR ticket scanned at the gate is a perfect record of one thing: a person came in, at this time, on this ticket. It records nothing about when they left, because nobody scans out. So the number every venue wants from a scan-in system, how many people are inside right now, is not a count. It is an estimate, built from a count of arrivals and an assumption about how long people stay, and it drifts upward all day, because every arrival is certain and every departure is a guess. The honest dashboard does not hide that. It shows the estimate with its drift, resets it at close, and uses the size of the drift to decide when counting exits becomes worth the door.
The scale of the problem
Arrival counts at real venues are large enough that the drift matters. The Association of Leading Visitor Attractions publishes annual visitor figures for its members: in 2025 the Natural History Museum recorded 7,116,929 visits, the British Museum 6,440,120, Tate Modern 4,514,266 and the Science Museum 2,640,417. Spread over opening days, the largest of those is on the order of twenty thousand arrivals a day, and a museum that wants to hold a gallery under a safe occupancy needs to know how many of the morning's arrivals are still in the building at two in the afternoon, which no scan at the door can say.
Little's law, pointed the right way
The tool for turning arrivals into occupancy is Little's law, which says that in any stable system the average number inside equals the average arrival rate times the average time spent inside. For a venue, occupancy equals arrivals per hour times the average dwell time in hours. If people arrive at two thousand an hour and stay two hours on average, there are about four thousand inside. The arrival rate is measured exactly by the scans. The dwell time is not measured at all; it is assumed, from surveys, from past exit counts, or from a guess, and the occupancy estimate inherits that assumption whole.
What makes the estimate usable rather than dangerous is that its error has a known direction. If the dwell assumption is too long, the estimate is too high, and a venue that acts on it holds people at the door earlier than it needs to, which costs revenue and goodwill. If the assumption is too short, the estimate is too low, and the venue admits people into a space that is fuller than it thinks, which is the failure that safety limits exist to prevent. So the assumption is set long, deliberately, and the estimate is a figure that is wrong in a predictable direction. That is better than a count that is wrong in an unknown one, and it is the standard a dashboard can be honest about.
The exit deficit
The number that expresses the honesty is what I call the exit deficit: at any moment, the gap between scanned entries and inferred exits. It is the error bar on the occupancy figure. Early in the day it is small, because few people have been inside long enough for the dwell assumption to matter. By mid-afternoon it is large, because the estimate of who has left is entirely a product of the assumption and the assumption has been compounding since opening. The dashboard shows the occupancy estimate and the deficit side by side, and resets both at close, when the building is empty and the count is known.
The reset at close is not a formality. It is the one moment in the day when the estimate can be checked: the building is empty, so the true exits equal the day's entries, and the model's cumulative exits can be compared against them. A model that predicted the building would be empty an hour before close was assuming dwell times too short; one that still predicted people inside at close was assuming too long. That comparison, done daily, is how the dwell assumption gets calibrated without ever installing an exit counter, and it is why the dashboard's error bar narrows over weeks even though the data it runs on does not change.
The dwell assumption itself deserves to be a distribution rather than a number, because visitors do not all stay the same time. A school group stays ninety minutes and leaves together; a tourist stays three hours; a member drops in for twenty minutes. Little's law works with the average, but the deficit is better computed from the spread, since a wide spread means the modelled exits are uncertain even when their average is right. In practice the model I use assumes a distribution shaped by past sampled counts where they exist and by the venue's own judgement where they do not, and the deficit is the range of occupancy figures the plausible dwell distributions produce, not a single subtraction.
When to start counting exits
The deficit is also the trigger for the next investment. A venue has a tolerance: the amount of uncertainty in the occupancy figure it can live with, set by how close it runs to its safe limit. While the deficit stays inside that tolerance, entry-only counting is enough and the exit door stays unstaffed. When the deficit exceeds it, regularly, at the times that matter, the venue needs measured exits, and the cheapest version is not a scanner on every exit. It is a sampled count at one door, a person or a sensor counting departures through the busiest exit for an hour at a time, which measures the actual dwell distribution and replaces the assumption with data for that day.
The third architecture, scanning out at every door, is the one venues imagine they want and almost never need. It produces a true count only if every exit is gated, which for a museum with fire doors and a garden and a cafe is not a property the building has, and a single ungated door turns the count back into an estimate with an error that nobody is tracking. The sampled exit is honest about being a sample, and it costs one person for one hour rather than a turnstile on every door.
What the dashboard says
The live visitor view in the ticketing system I built counts scan-ins at the gate, and the design decisions above are how the occupancy figure on that view is meant to be read. It is labelled as an estimate. It carries the deficit beside it. It resets at close, and the close-of-day comparison feeds the next day's dwell assumption. When the deficit crosses the venue's tolerance, the view says so, and the recommended response is a sampled exit count rather than a change to the software. A number with its error bar is a number an operations manager can act on. A number without one is a number they will either over-trust or ignore, and neither is what the gate was scanning for.
Get new posts by email
Occasional essays on engineering, AI, and building for the people technology leaves behind.
Subscribe with RSS