How it works
From the moment the tower is placed to the moment the report is sealed and signed. No overstatement, and no accuracy figures that have not been measured.
One column, at the front, facing the people.
A 2.00 m column with a square 20 × 20 cm section, matte dark gunmetal, with a thin green light seam where the head meets the body.
It stands at the front of the room facing the audience — where a speaker stands. No screen, no cables run through the crowd, nobody holding a device.
Four steps before the doors open.
Name it
The event, and one measurement you actually want. The question is fixed first, so the report answers something specific.
Walk it
One lap in front of the tower in defined head poses. This sets the stage direction and measures the real read range in this particular room.
Confirm it
Draw the room and mark the attention zones — stage, screens, sponsor area. Coverage rings are sized from the room's true width, so you see what is inside coverage before you start.
Start
The live dashboard comes up and measurement runs.
Two read tiers — and the difference is stated, not hidden.
IRIS does not claim to read everything at any distance. The room is divided into tiers, and both are visible to the operator during setup:
Close to the tower: the face is clear enough to contribute to the unique count, to attention, and to aggregate emotion.
Further out: the face is not clear enough, so the person is counted from their silhouette. They count as present; they do not contribute to readings that need a face.
Outside coverage entirely. This is said plainly at setup so you can move the tower or add a second one — it is not quietly absorbed into the report.
Where each tier ends is measured in your room during the walk — it is not a catalogue number. Camera, lighting and room shape all move it.
Two readings: one while you're standing there, one after everyone leaves.
The live pass runs on the tower during the event and gives you what you can act on in the moment: who is present now, where attention is going, how the mood is moving.
When the event ends, a second, deeper pass runs over everything captured, all at once. That pass produces the final unique count — grouping a person to themselves is more accurate with the whole session in view than it can be as it happens.
The number in the report is the second pass's number. The gap between it and the live figure is not hidden; it is itself information about the room.
Sealed, signed, and checkable without coming back to us.
The final report is cryptographically signed and sealed, and carries a verification id. The signature covers the report's own content, so changing one number after issue breaks the seal.
Verification runs against the file, locally. You do not need to contact us, or trust us, to confirm it.
The whole lifecycle — and every step of it recorded.
Every transition below is written to a hash-chained audit log, so a step deleted or altered afterwards shows up as a break.
Images and the data derived from them are held on encrypted local storage — the only stage at which raw data exists at all.
A re-grouping pass across the whole session produces the true unique count and the final metrics.
A signed report plus aggregate numbers. This is the only thing that can leave the room.
All images and derived data are deleted. What remains is aggregates and the signed report.
Automatic purge on export is the default. If an operator enables footage retention, the tower says so on its own screen and changes the notice it displays — deliberately: the worst outcome is a screen asserting something the configuration contradicts.