Skip to main content
DoneThat

AI Adoption GuideHospitalityArrive

ID document OCR parser

Vision model extracts passport and ID fields to auto-populate the PMS record at check-in.

Hospitality processBookConfirmPrepareArriveStayDepartReviewReturn

By Don, DoneThat’s AI coach · updated

Treat the extract as a draft, not a guest record

A vision model can read a passport or national ID at check-in and propose fields for the property management system. Those fields are a draft. They are not the guest profile until a front-office agent confirms the write.

The quality bar is operational. Every extracted value must cite the image and the field on that image. If a region is unreadable, that field stays empty. The model does not invent a passport number, a date of birth, or a nationality so the form looks finished. The agent still confirms before anything is written to the PMS.

That distinction matters because PMS and check-in stacks used at the desk, including Canary, Agilysys, Oracle Hospitality, and Mews, will persist whatever you send them. A profile that looks complete and was never confirmed is still a wrong profile.

Load the ID image before any field is filled

Start with the image, not with the reservation form. Capture or attach the passport or ID the same way the desk already captures identity documents at arrival. Run extraction only against that loaded scan.

Do not run extraction against a thumbnail, a photo of a phone screen, last stay's file, or the booking name sitting in the reservation. Those sources are useful for other arrive work. They are not the document in the guest's hand.

Once the image is loaded, the model returns a structured set of fields your property actually maps into the guest profile: given names, surname, document type, document number, nationality, date of birth, expiry. Each value should arrive with a cite: which image, and which printed line, zone, or label on that image.

If the load step fails, stop. Blur, flash glare on the machine-readable zone, a cropped edge, a thumb over the photograph, or a laminate that bounced the light are all reasons to recapture. Do not fill what you can from memory of the booking. Missing booking data is a different problem; send that to incomplete reservation flagging rather than stretching a bad scan into a full identity record.

Kiosk and lobby flows follow the same load rule. A frictionless self-check-in agent can collect the scan and run extraction, but it still needs a readable image first. A guest holding a passport at a bad angle is not a completed identity check.

Cite the field or leave it blank

A field without an image cite is not an extract. Treat it as missing.

Display blanks as blanks. If the UI shows a value with no cite, agents will assume the document was read. Hide uncited values. Do not grey them, do not footnote them in a way nobody reads, and do not keep a best guess behind a tooltip.

Empty stays empty when the scan is unreadable. An unreadable document number is blank in the extract, blank on the confirmation screen, and blank in the PMS until a human re-scans or types from the physical document in front of them. Typing is an override. Log it as typed, not as extracted.

This failure looks like competence. Models complete forms if you let them. A surname from the reservation plus a guessed passport number looks finished. It also creates a profile that cannot be traced back to the scan, which is what you need when a later stay, a police inquiry, or a rate-plan audit asks how the number got there.

Do not invent a passport number. Do not copy one from the OTA booking, a previous stay, or a likely digit string that matches the expected length. Completing an unreadable MRZ is fabrication, even when the invented value happens to be right.

A Wednesday evening arrival shows the correct path. The guest hands over a passport. The visual zone is sharp: surname, given names, and nationality each cite the corresponding printed line. The machine-readable zone has glare. The extract returns document number as empty, with no cite, rather than a plausible string. The agent sees three cited fields and one blank, holds the booklet under better light, and either re-scans or types the number from the page. Nothing is written to the guest profile until that confirmation. If the extract had filled a document number to complete the record, the desk would have no signal that invention happened except by reading the physical passport again, which is the step busy arrivals skip.

Name mismatch is not a reason to overwrite the scan. If the reservation says Jon and the passport cites Jonathan, keep the cited extract and let the agent decide how your property reconciles booking name and legal name.

Confirm before the PMS write

Auto-populate in this workflow means fill the confirmation screen, not write the profile.

Show the agent the proposed fields next to the image cites. The agent checks each cited value against the document in hand, fills any blanks from the physical ID if policy allows a typed override, and only then commits the write.

Do not treat the extract as written. A proposed record in a side panel is still a proposal. If the agent walks away, if a kiosk session times out, or if a queue jump happens, discard or park the extract. Do not flush it into the profile in the background.

Map confirmation to the commit action your stack already uses for a manual ID check. Canary, Agilysys, Oracle Hospitality, and Mews differ in screens and field names, but they share the same operational requirement: there is a moment when a human, or a defined kiosk attest, accepts the identity data. Use that moment. Do not add a second, silent write path for the model.

This still applies when the desk is thin. A kiosk can collect the scan and show cites to the guest, or a remote agent can review cites before keys are encoded. Skipping confirmation is how a wrong date of birth lands in the profile and then in every downstream system that trusts the PMS: door encoding, spa, billing, and the next arrival.

Loyalty status and accessibility needs do not come from the ID scan. After the confirmed write, pull stay context with loyalty context retrieval. Surface access needs with accessibility need trigger from reservation notes or prior profiles, not from OCR of a passport photograph.

Coach the three failures that look like a finished arrival

Walk the shift on three failures that present as a successful check-in.

First, a field with no image cite. If a value is on screen without a cite, the desk will accept it. The fix is product and process together: uncited fields render blank, and agents re-scan or type with an override flag.

Second, treating extract as written. If the guest profile updates when extraction returns, you have already lost confirmation. Keep the extract in a holding state until commit.

Third, inventing a passport number. Completing an unreadable zone from the booking, a previous stay, or model prior is not extraction. A blank document number that an agent fills from the booklet is correct. A generated number that matches the expected digit count is not.

Pre-shift, pick one bad scan: glare, cropped edges, or a legal name that does not match the reservation spelling. The correct action is re-scan or type-with-override, never accept all. The wrong action is sending a complete-looking profile into Canary, Agilysys, Oracle Hospitality, or Mews because the queue is long.

Keep extraction, confirmation, and the PMS write as three steps. The image is loaded, fields are cited or left empty, and a person still confirms the write.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first