The reader is not the system.

An access-control decision joins an opening, locking hardware, credential, identity process, controller, network, software, life-safety interface, operating team, and audit trail. Scope the whole chain.

Scope controlled openings before products.

For every door, gate, lift destination, garage, and restricted area, define who needs access, when, with which exception path, what the opening should do during fire alarm, power loss, network loss, and system failure, and who owns daily administration.

Access path in view

The door is a system, not a reader.

A sound review follows the credential through the decision point and all the way to the physical opening.

Commercial lobby turnstiles with integrated access readers01
Flow — observe how entry works in the real lobby.
Hand presenting an unbranded credential to a wall-mounted access reader02
Decision — verify identity, policy, and exception handling.
Gloved technician inspecting secure door hardware and a protected cable loop03
Opening — inspect the hardware that enforces the decision.

Published 8 September 2026 · reviewed 9 September 2026. Editorial illustrations generated for Hamed Helped; they do not depict a named site, vendor, or client.

Decision criteria

Six layers have to agree at the opening.

01Physical

Opening & hardware

Door, frame, lock, egress, power, monitoring, accessibility, environment, and failure behavior.

02Identity

People & credentials

Enrollment, proofing, issuance, lifecycle, lost credential, role change, visitor, contractor, and termination.

03Control

Decision architecture

Where access rules run, what works offline, how time and schedules behave, and who can override.

04Integration

Connected systems

Video, intercom, visitor, lifts, alarms, identity, HR, tenant systems, mobile wallets, and incident workflows.

05Operation

Administration & response

Daily changes, exceptions, alarms, investigations, evidence retention, vendor support, and escalation.

06Lifecycle

Security & exit

Updates, remote access, keys, backups, recovery, device support, data export, and replacement path.

Questions to ask

Ask about the day after handover.

  1. Who administers access every day?

    Map new joiners, tenant changes, visitors, vendors, role changes, terminations, lost credentials, and after-hours exceptions.

  2. What happens without the network?

    Define local decision behavior, cached rights, monitoring, alarms, operator awareness, and restoration.

  3. What happens during a life-safety event?

    Require jurisdiction- and design-specific review of egress, door release, fire-alarm interface, overrides, and testing.

  4. Which identity is authoritative?

    Name the source of identity and access rights, synchronization path, conflict handling, and deprovisioning evidence.

  5. Who can reach the controllers remotely?

    List accounts, approval, authentication, duration, monitoring, logging, support purpose, and revocation.

  6. Can the property change providers?

    Document credentials, hardware constraints, controller ownership, configuration export, records, keys, and transition support.

Evidence table

Separate design acceptance from operating evidence.

Claim or decisionEvidenceOwnerWhen checked
Opening behaviorDoor schedule, hardware and interface design, failure modes, approved test resultDesigner + life-safety stakeholdersDesign, commissioning, material change
Identity lifecycleSource-of-truth map, approval rules, joiner/mover/leaver test, exception logSecurity + identity ownerBefore rollout and periodically
Offline operationDocumented behavior and observed test for network, server, cloud, and power lossOperations + system ownerCommissioning and recovery exercise
Remote supportNamed accounts, approvals, authentication, session records, review and revocationSystem owner + securityBefore support access and at review
Exit readinessConfiguration, credential, record, hardware, key, and transition inventoryProperty owner + procurementBefore contract and at renewal

Failure modes

Four signals that the scope is too small.

F-01

The bill of materials is the design

Products are listed before people, openings, exceptions, operating roles, and failure behavior are agreed.

F-02

Mobile equals modern

A credential form is chosen without mapping identity proofing, phone loss, privacy, offline behavior, and alternatives.

F-03

Integration means API

A technical connection exists but ownership, error handling, incident response, support, and evidence do not.

F-04

Handover ends the project

Administration, updates, remote support, records, backups, recovery, and provider exit have no durable owner.

Secure the system

Place access control inside the building’s cyber-physical boundary.

Open the baseline

Evidence trail

Sources behind this guide

  1. 01
    NISTGuide to Operational Technology (OT) Security — SP 800-82 Rev. 3 (external link)

    Primary guidance that includes physical access control systems in OT scope.

  2. 02
    Security Industry AssociationSIA Proptech Report (external link)

    Commercial-real-estate research covering security technology priorities, interoperability, and buying considerations.

  3. 03
    Security Industry AssociationSecurity Convergence 2024 (external link)

    Industry research on the meeting point of physical and cybersecurity responsibilities.