Showing 0 products

Frequently Asked Questions

Which credential technology should be specified now?

An authenticated smart credential - card or mobile - for anything new. Legacy proximity should only be bought to match an estate that is already being replaced.

Low-frequency proximity credentials broadcast a static number with no cryptography. Copying one requires inexpensive equipment and no expertise.

Smart credentials authenticate using a key held in a secure element, so the exchange cannot be recorded and replayed.

Mobile credentials give the same protection with the additional advantage that issuing and revoking is instant and remote.

The one legitimate reason to buy legacy credentials is compatibility with readers not yet replaced - and in that case the order should be for the transition period only, with a date attached.

Where a site is genuinely stuck with legacy readers for now, add a PIN or biometric second factor at the doors that matter most.

Card, fob, wristband or phone?

Card where a photo ID is wanted on the same item, fob for pocket use, wristband for wet or gloved hands, phone where the population already carries one.

Cards are the default because they double as visual identification and can be printed with a photo, a name and a colour code for area or role.

Fobs are more robust and more convenient for people who do not wear a lanyard, but they carry no visual identity, so a site using them alone loses the ability to check who someone is by looking.

Wristbands and tags come into their own where hands are wet, gloved or full: leisure centres, clinical areas, food production and heavy industry.

Mobile credentials remove the physical item entirely. They suit staff populations with company or personal smartphones and are poor for visitors, contractors and anyone whose device cannot be enrolled.

Most sites end up with a mix, and the system should be able to hold more than one credential against one person.

How should lost credentials be handled?

Revoke immediately in the software, then issue a replacement - and treat the revocation as the urgent half of the task.

A lost credential is a key in an unknown pocket. Until it is disabled in the system it opens every door it ever opened.

The report-to-revoke path should be short and available out of hours. Most exposure comes from a loss reported on Friday evening and actioned on Monday.

Charging for replacements reduces casual loss and is common practice, but a charge that discourages reporting is counterproductive. Free replacement with a mandatory report is usually the better trade.

Watch for the credential that reappears. A card reported lost and later found should be destroyed rather than reactivated, because there is no way to know where it has been.

Audit periodically: compare the active credential list against the current staff list and investigate anything that does not match a person.

What are facility codes and card numbers?

The site identifier and the individual number encoded on a credential - and they need to be planned so a later order cannot duplicate an existing card.

Most credential formats carry a code identifying the site or customer and a number identifying the individual credential within it.

Duplication happens when a second order is placed years later without reference to the first, and the supplier restarts the numbering. Two cards then open the same doors and the audit trail cannot tell them apart.

Keep a record of every range issued: format, code, start and end numbers, order date. It should live with the access system's own documentation.

Some manufacturers operate managed number ranges that guarantee uniqueness across their customers, which removes the problem at the cost of tying the site to that supplier.

When ordering a top-up, always state the existing format and the last number issued rather than leaving it to the supplier.

Can one credential do more than open doors?

Yes - smart cards are routinely used for print release, cashless payment, time recording and logical access, and that is often what justifies their cost.

A smart card can hold several independent applications in separate key-protected areas, so the access application and the payment application cannot read each other.

Print release and cashless catering are the most common additions, and both remove separate cards from people's pockets.

Logical access - using the card to log into a computer - is the highest-value integration and the one with the strictest key management requirements.

The catch is governance. Each application has an owner, and adding one later means loading keys onto cards already in circulation, which is far harder than doing it at issue.

Decide the intended applications before the first order even if only one is being implemented, and specify cards with the capacity to carry the rest.

How are mobile credentials issued and revoked?

By email or app invitation to the user's phone, and revoked centrally in seconds - which is their main operational advantage.

Issuance is an administrative action rather than a physical one: the user receives an invitation, installs or opens an app, and the credential is provisioned over the air.

Revocation is equally immediate and does not depend on recovering anything, which is a material improvement over chasing a card from a leaver.

The dependencies are real, though. The phone needs charge, the right radio enabled, and in some implementations network access at provisioning time.

Personal devices raise a policy question that should be settled before rollout: what is installed on someone's own phone, what it can see, and what happens when they leave.

Licensing is usually per user per year rather than a one-off purchase, so the comparison with cards is a total-cost calculation over the expected life, not a unit price.

What do credentials cost over a population's life?

The unit price is the smallest part - replacement rate, printing, encoding and administration dominate.

Physical credentials have an annual attrition from loss, damage and non-return that is easily several percent of the population, and every replacement carries administrative time as well as a card.

Printing photo ID adds consumables - ribbons, cards, cleaning kits - and a printer to maintain.

Smart cards cost more per unit than proximity cards but do not fail more often, so the difference is a one-time step rather than a recurring one.

Mobile credentials usually invert the model: no unit cost, a recurring per-user subscription, and much lower administrative effort.

Model both over five years including the labour. On populations with high turnover, mobile frequently wins on total cost even where the subscription looks expensive against a card price.