Access Control & Physical Identity
One list of people, not four.
Physical access is usually its own island: a separate system, a separate database, a separate list of employees, maintained by whoever was given the software. The result is predictable — leavers keep working badges, contractors accumulate permissions nobody granted deliberately, and nobody can answer who opened a door at a specific time. The fix is not a better panel; it is making the door read from the same identity source as everything else.
- Physical and digital identity, together
- One sourcePhysical and digital identity, together
- Visitor and contractor access, by default
- ExpiringVisitor and contractor access, by default
- Who opened which door, and when
- AnswerableWho opened which door, and when
Sounds like
You might recognise one of these.
Our access control has its own list of employees and it does not match HR.
Somebody left three months ago and their badge still works.
We cannot tell you who was in the building on a given evening.
The access system is managed by a company we cannot get hold of.
What this includes
The work, specifically.
Not every engagement needs all of it. This is the range we cover and what each part is actually for.
Identity integration
Doors, gates and enclosures reading from your directory rather than from their own copy, so a leaver loses physical and digital access in the same action.
Credential strategy
Card, mobile, PIN or biometric, chosen on threat model and practicality — including the honest conversation about what biometric data you would then be holding, and whether you want to.
Audit and reporting
A queryable, retained record of who accessed what and when, in a form that answers an investigation rather than requiring one.
Visitor and contractor handling
Time-bounded access that expires by default, because the permission nobody revokes is the one granted to a contractor in a hurry.
Panels, readers and door hardware
Specified and installed, with fail-safe and fail-secure behaviour decided per door against fire and egress requirements rather than set globally.
What you get
Deliverables, not documents.
- Access design with a per-door fail-safe or fail-secure decision and its reasoning
- Directory integration, so joiners and leavers propagate automatically
- Credential rollout with a documented issue and revoke process
- Retained, queryable access logs
- Commissioning records per door
Shapes
How this usually runs.
Access review
1–2 weeksWhat you have, who holds credentials, which of them should not, and where the identity data actually lives.
Design and installation
4–10 weeksPanels, readers and integration, phased so no door is out of service longer than agreed.
Operation
OngoingCredential lifecycle, audit reporting, and periodic entitlement review.
Tooling
What we build it with.
No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.
- Identity
- Field
- Records
Questions
Access control, honestly.
Often no. A biometric template is personal data you cannot reissue if it is compromised, and several states regulate collecting it specifically. Where the threat model genuinely calls for it we will say so and design the retention accordingly; where a mobile credential is sufficient, that is the cheaper and lower-risk answer.
Frequently, and we check before proposing replacement. Where hardware genuinely has to go it is usually because it speaks a proprietary protocol with no path to your directory, and we will name the specific limitation rather than the general one.
Your authority having jurisdiction signs off egress, and we design to it and coordinate with your fire contractor. We will not fit a door in a configuration that traps somebody, and we will tell you plainly if a request would.
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.