Galleries & Watchlists
Traveler Identity Service (TIS) is the orchestration layer for galleries. Integrators work in business terms — Watchlist, Sanctions, VIP, Zone — and TIS maps those onto the matching scope inside the embedded biometric engine. Integrators never configure the matching engine directly.
Why galleries exist. A border deployment needs to scope identification narrowly — per gate, per zone, per active window, per watchlist — instead of searching the full national database on every check. Narrow scope means faster searches and fewer false positives, while the business language (Watchlist, VIP, Sanctions, Zone) stays separate from the technical matching scope underneath.
Two kinds of gallery
The distinction that matters is who defines a gallery, and when.
Primary and system galleries — managed by TIS
- Primary gallery — holds all active travelers and is the default scope for identification; always maintained by TIS.
- System galleries — internal groupings (for example inactive or archived travelers) that TIS manages for lifecycle and orchestration. These are not exposed to, or configured by, integrators.
Overlay galleries — defined with the integrator at deployment
Additional galleries layered on top of Primary to match a deployment's operational needs. They are segmented by:
- Purpose — watchlists / sanction lists, VIP or fast-track facilitation, zoning by journey or location, risk-based segmentation, or integration with external systems (e.g. national or international databases).
- Modality — for example a face-only or fingerprint-only gallery where a deployment requires it.
Overlay galleries are agreed and shaped together with the integrator during customization / on-premises deployment to reflect real operational needs — they are not created ad hoc by integrators at runtime.
Gallery structure is currently static: the set of galleries is established at deployment. Dynamic, runtime creation and removal of galleries is on the roadmap.
Membership
A traveler always belongs to the Primary gallery and may additionally appear in one or more overlay galleries, so the same person can participate in several operational contexts — for example a watchlist and a terminal zone — without losing global visibility. TIS keeps a traveler's gallery presence consistent as their status changes (for example, added to and later cleared from a sanction overlay).
Deployments with strict segmentation requirements can operate in a restricted, single-gallery mode, where a traveler is assigned to only one active gallery at a time and moving between galleries replaces the previous assignment.
Identification scope
An identification can search the Primary gallery and/or selected overlays — a single search can span several galleries, so one check can look across the general population and a watchlist at the same time, scoped to the operational context (gate, zone, or time window).
See also
- Biometrics via Traveler Identity Service — how galleries are used during identification and verification
- Traveler Identity Service overview — module landing