Showing 0 products
What should access control software do well?
Make routine administration fast and hard to get wrong: enrol a person, put them in a group, and have the right doors follow automatically.
Group-and-schedule models scale. Access is attached to a role or department, and a new starter inherits it in one action.
Per-person, per-door administration does not scale. It is accurate on day one and wrong within months, because nobody revisits every door when someone changes job.
Bulk operations matter more than they appear in a demonstration: onboarding fifty people, changing a schedule for a public holiday, or revoking a whole contractor group.
Search has to be good. Finding one cardholder among tens of thousands, or every use of one door last Tuesday, is the everyday task.
Look for role-based administration too, so a site manager can enrol local staff without being able to alter the rules for the whole estate.
What reporting is worth having?
Who has access to what, who used a door and when, what changed and who changed it, and a muster list for an evacuation.
An access-rights report - all doors for a person, or all people for a door - is what audits ask for and what most systems make hardest to produce.
Event history with filters on person, door, time and outcome is the investigation tool. Denied events are as informative as granted ones.
An administrative change log answers the question that matters after an incident: who granted this access, and when.
Roll-call or muster reporting lists who is currently inside, for use at an assembly point. Its accuracy depends on people badging out, so it is an aid rather than an authority.
Scheduled reports emailed to an owner are worth setting up, because a report nobody runs is a report nobody reads.
How is access control software licensed?
By doors, readers, cardholders, client workstations, or as a per-door subscription - and often by several of those at once.
Door or reader counts are the most common base licence, with tiers that step up at awkward points. Confirm the price of the door that crosses a tier boundary.
Cardholder limits catch out sites with large or seasonal populations, and visitor records sometimes count towards them.
Client licences limit concurrent administrative sessions. Sites with several reception desks need to count them properly.
Integration modules - video, directory synchronisation, intruder, lifts, visitor management - are frequently separate line items rather than included features.
Subscription models bundle support and upgrades into a recurring fee. Perpetual licences do not, and the annual maintenance contract that keeps them supported is the figure to compare against.
Should the software integrate with HR or the directory?
Yes, wherever an authoritative staff record exists - nothing else stops leavers keeping their access as reliably.
When the identity system is the source of truth, a leaver's building access ends at the same moment as their account, without anyone remembering to do it.
Joiners and movers benefit equally: a department change updates access automatically instead of leaving the old permissions in place alongside the new ones.
The integration needs rules about precedence. If a record is edited in both systems, which wins, and can a local administrator override the feed at all?
Contractors and visitors usually sit outside the HR system, so the platform still needs a manual path with expiry dates for them.
Check how the integration is licensed and supported. It is a common place for a separately chargeable connector to appear once the project is committed.
On-premises or software as a service?
SaaS for multi-site estates and organisations without IT resource; on-premises where data residency, network isolation or capital budgeting decide it.
SaaS removes servers, backups, patching and version upgrades, and makes remote administration of many sites straightforward. The cost becomes recurring and unavoidable.
On-premises keeps the data inside the organisation's boundary, which some sectors require, and can be run entirely disconnected from the internet.
Either way the controllers should hold their own rules, so the doors keep working independently of where the management platform lives.
For SaaS, get explicit answers on data residency, retention, export format and what happens at the end of the agreement. Access logs are personal data under most privacy regimes.
For on-premises, budget the server, its operating system licences, the backup regime and the person who maintains all three.
How is the software kept secure?
Individual named administrator accounts with roles, multi-factor authentication, a patching plan, and no shared credentials.
Shared administrator logins destroy the administrative audit trail, which is precisely what an investigation depends on.
Role-based permissions limit what each administrator can do - enrolling staff is a different privilege from changing door rules or deleting events.
Multi-factor authentication on administrative access is now a baseline expectation, particularly for anything reachable remotely.
The server needs the same patching discipline as any other business system, and the database needs a tested backup rather than an assumed one.
The integrator's remote connection should be time-limited and under the customer's control. A permanent vendor tunnel into the system that opens the doors is a risk that outlives the project team.
What happens to the doors if the licence lapses?
That varies by product, and it is a question worth asking in writing before purchase.
In most well-designed systems the controllers keep enforcing the rules they already hold, so doors continue to work and existing credentials continue to be accepted.
What stops is administration: no new enrolments, no revocations, no reporting. That is a serious security problem in itself, because leavers cannot be removed.
Some subscription products disable the management platform entirely, and a few restrict controller functionality. The difference is material and is rarely prominent in the marketing.
Data export is the other question. Confirm the format in which cardholder records and event history can be extracted, and test it during the contract rather than at the end.
Get the answers as contract terms, not as assurances in a meeting.