A small hotel, off-season. The pool and the gym sit empty most weekday mornings once the last guest heads out for the day. The owner decides to sell a Winter Pass to locals: ten visits, weekdays only, 10am to 4pm, so it never touches the weekend crowd paying full rate. Valid through March.
The paper card
Week one. Ten squares printed on a card, sold at the front desk for cash. Whoever's on the desk punches one square per visit and nothing else.
Week two. Two people cover the desk some mornings, and a punch gets missed on a busy one, or made twice on a slow one. By the second week, the squares punched on a card and the visits someone actually took aren't reliably the same number - and there's no way to tell, from the card alone, which of the two it is.
By March, some cards ran out early, some ran past ten, and reconciling any of it means someone remembering back weeks to mornings they weren't necessarily the one behind the desk for.
This winter
Week one. A Winter Pass, set up once in Wardentry: ten visits, weekdays 10am-4pm, valid through March. Sold at the desk exactly the same as before, except what goes out is an email with a QR code instead of a printed card.
Week two. Two people cover the desk, same as before. Each scan logs itself the instant it happens, so a morning with two people at the desk logs exactly as many visits as a morning with one - nobody has to remember whose turn it was to mark the card.
By March, the pass stops itself. The eleventh visit and anything after March both get turned away at the door, without anyone behind the desk having to count squares or check a calendar.
Setting it up
Create. The owner builds the pass once, from the console: a gate at the entrance, an entry limit of ten per guest, and hours narrowed to weekdays, 10:00 until 16:00.

Distribute. Each pass goes out as an email with a QR code, ready to share the moment it's sold.
Scan. Front desk staff scan the code with their own phone. The door opens if the pass has visits left and the time is inside the window.
Enforce. After ten visits, or after March, the same pass stops working on its own. The scan still happens the same way - same phone, same camera - but the screen shows a plain refusal instead of a pass, with a reason attached: no visits left, or outside the pass's hours. Staff don't have to work out why by hand; the phone already did. A season like this - one pass, a few hundred visits over the winter - stays well inside the free tier's caps of 5 events, 500 members and 500 passes per organization.
Questions this raises
How many visits should the pass include?
Ten is close to two visits a week across a month, which matches how most locals actually use a pool and gym pass. A shorter pass suits someone trying it once; a longer one suits a full season sold at a lower price per visit.
What if a guest shares the QR code with a friend?
Nothing stops the code from being forwarded. What the entry limit does is count every scan against the same ten, no matter who presents it - so a shared pass runs out faster. It does not grant extra visits.
Does the scan check who's holding the phone?
No. The scan checks whether the pass has visits left and whether the time is inside the window, nothing more. Matching the person at the door to the name on the pass stays a staff decision, same as it was with a paper card.
Running something with more than one kind of pass, or doors that need different rules? See how it works for visit passes, or sign up and try it against your own front desk.