Access control
Who opens which door, and when.
Changed in thirty seconds from a phone, instead of a locksmith and a box of keys you are never getting back.
First question
Do you need this, or do you need a bio lock?
These two pages sell different things and we would rather you land on the right one. The dividing line is how many doors, and whether anyone has to prove later who went through one.
| Standalone bio lock | Wired access control | |
|---|---|---|
| Scale | One door to a handful | A building, or a portfolio of them |
| Wiring | Batteries, no cabling | Cabled to a controller with backed-up power |
| Audit trail | On the lock and in its app | Central, per door, exportable |
| Schedules | Simple time windows | Per person, per door, per holiday |
| Lockdown | Door by door | Every door at once, from a phone |
| Fire alarm tie-in | Usually not required | Required |
| Best for | Rentals, back doors, small offices | Schools, clinics, multi-tenant, shift work |
Plenty of sites end up with both — a wired system on the main doors and bio locks on the outbuildings. The bio locks page is here.
What a door actually is
Why one door costs what it costs
Customers are quoted “per door” and reasonably assume that means a reader and a lock. It does not. Here is everything that has to be there before a door works and keeps working.
A quote that lists readers and a panel, with no door contacts, no exit sensors, no power supply and no fire alarm interface, is not cheaper than ours. It is just incomplete, and the difference turns up as a change order.
Credentials
The part that quietly decides whether any of this works
If your cards are 125 kHz, your access control is decorative
125 kHz proximity cards — the old HID Prox and EM4100 white clamshells — have no meaningful encryption. The card broadcasts its number in the clear whenever a reader powers it, which means it can be copied in seconds by a handheld duplicator that costs less than a nice dinner. Millions of these are still on lanyards in Chicagoland buildings. If that is what you are carrying, the doors are logging entries, not controlling them.
- 125 kHz PROXHID Prox, EM4100, and the generic white clamshell. Unencrypted, trivially cloned. Replace it.
- 13.56 MHz, ENCRYPTEDMIFARE DESFire EV3 or HID Seos. AES encryption and mutual authentication between card and reader — the current baseline, and what we specify by default.
- 13.56 MHz, LEGACYMIFARE Classic was broken in 2008 and the original iCLASS in 2010. A higher frequency is not the same as being secure. The encryption is the point, not the number on the datasheet.
- MOBILEThe credential lives in a phone over Bluetooth or NFC. Nothing at the reader to clone, issued and revoked remotely in seconds, and people lend a fob far more readily than they lend their phone.
- BIOMETRICA reader that reads a person rather than a card. In Illinois that decision brings BIPA obligations with it — the rules are on the bio locks page, and they apply before the first enrollment.
Not sure what you are carrying? Bring one card to a site walk. A reader tells us the technology in about five seconds, and we will tell you straight whether it is worth keeping. Re-badging a building is a real cost and we would rather you spend it knowingly than be told everything is fine.
Where the brain lives
Cloud or on-premise
Both work. The honest difference is what you would rather own: a monthly bill, or a server and the responsibility for patching it.
One thing that is true of both, and worth saying plainly: the doors keep working when the internet is down. Controllers hold their credentials and schedules locally. What you lose in an outage is remote management, not entry.
- CLOUDNo server to own or patch. Updates handled for you, every site in one login, and you can revoke someone from a phone in a car park. Ongoing subscription per door or per reader.
- ON-PREMNo subscription and the data stays in your building. You own the server, the backups, and the patching — which is fine if you have IT, and a slow-motion problem if you do not.
- HYBRIDCommon on campuses: local controllers with a cloud management layer over the top. You get remote administration without the doors depending on the link.
- EXIT PLANAsk any vendor, us included, what happens to your cardholder data and your hardware if you leave. Get it answered before you sign, not after.
Code, not preference
People have to be able to get out
This is the part of access control that is genuinely regulated, and the part where a cheap install becomes a liability. Locking a door is easy. Locking it in a way that passes inspection and does not trap anyone in a fire is the job.
- 01Free egress. On most doors a person must be able to leave with one motion and no special knowledge. That constrains which lock hardware is even legal on that opening.
- 02Fire alarm release. Magnetic locks have to drop on a fire alarm signal and on loss of power. That interface is wired, tested, and documented — it is not a setting.
- 03Delayed egress, where permitted. Allowed in specific occupancies under specific conditions. It is not a way to make a fire exit behave like a locked door because staff keep using it to smoke.
- 04The authority having jurisdiction decides. We take the door schedule to your AHJ before installation, not after a failed inspection.
- 05Annual testing. Release on alarm gets tested and recorded, the same as any other life-safety interface.
K–12
Lockdown, and the thing people get wrong about it
A lockdown button that secures every exterior door at once is the single most useful thing access control does for a school, and it integrates cleanly with the emergency alerting Illinois districts are now planning around.
- ONE ACTIONEvery perimeter door secures at once, from a phone, a fob, or a wall station — not by sending staff to turn keys while something is happening.
- STILL EGRESSLockdown secures doors from the outside. It must never prevent someone leaving. Any system that traps people inside has failed, whatever the brochure says.
- WITH THE ALERTLockdown, cameras, intercom and the panic alert should fire as one sequence, so responders get the doors and the video together.
- REHEARSEDA lockdown nobody has practiced is a plan, not a capability. We run it with your staff during handover and again annually.
Process
How we scope an access job
- STEP 01
Door schedule
We walk every opening and write down what is there now: door type, frame, existing hardware, power nearby, and what it is protecting. This document is the whole job.
- STEP 02
Credential decision
What your people will carry, and whether existing cards survive. This is where re-badging gets costed honestly rather than discovered later.
- STEP 03
AHJ review
Door schedule to the authority having jurisdiction for the openings where egress hardware is in question.
- STEP 04
Rough-in and install
Cabling, controllers, power, and hardware. Scheduled around your hours, including overnight and school holidays.
- STEP 05
Cardholders and schedules
We load your people, set the schedules, and test every door — including the fire alarm release.
- ONGOING
Offboarding, and who owns it
The system only works if someone removes leavers. We set that process up with a named owner and review it with you.