Access Control Fundamentals

An access control system answers one question at every door: should this person be allowed through right now. Everything else is the machinery for answering it reliably and for knowing afterwards what happened.

The four parts

Almost every system, from a single door to a campus, is built from the same four elements.

The credential is what the person presents. Cards and fobs are still the default. PINs need no hardware but are shared freely and rarely changed. Biometrics remove the sharing problem but introduce data protection obligations, since fingerprint and facial data are a special category under the GDPR and need a stronger legal basis than convenience. Mobile credentials on a phone have largely solved the lost-card problem and are increasingly the default on new installations.

The reader collects the credential at the door. Readers should be treated as untrusted - they sit on the unsecured side, and older card technologies can be read and cloned trivially with equipment that costs very little. Modern encrypted card formats and a reader-to-controller protocol that is itself authenticated are worth specifying.

The controller makes the decision. This is the part that must be on the secure side of the door. A system where the reader itself releases the lock can be defeated by opening the reader housing, which is the sort of detail that separates a real system from a doorbell with a card slot.

The lock executes the decision, and it is where the safety rules bite.

Fail-safe and fail-secure

This is the distinction that matters most and is most often confused.

A fail-safe lock unlocks when power is removed. Magnetic locks work this way by nature - they need continuous power to hold. A fail-secure lock stays locked when power is removed.

Which one is correct is not a preference. It is determined by what happens in a fire or a power failure. Doors on escape routes must allow people out, so they need to release. A fail-secure lock on an escape route is a serious life-safety fault, not a design choice.

That leads to the rules which override everything else in the system:

  • Doors on escape routes release on fire alarm activation, wired so that no software decision is involved
  • An emergency door release is provided next to the door, breaking power directly to the lock
  • Free egress from the secure side, by request-to-exit device, mechanical override or both
  • The access control system may control entry; it may never prevent exit on an escape route

These requirements come from fire safety and building regulations rather than from the access control standard, and they take precedence over any security requirement.

Practical points that cause trouble later

Door position monitoring tells the system whether the door actually closed. Without it, a door propped open reports as secure. Request-to-exit devices should release the lock rather than simply suppressing the alarm, or the door becomes a trap during a mains failure.

Plan how credentials are removed, not just issued. The most common real-world failure of an access control system is that people who left the organisation months ago still have working cards.

In the Republic of Ireland, a Private Security Authority licence is required to install access control systems commercially.

Training

The Access Control Systems Fundamentals course covers credentials, controllers, lock selection and safe egress in structured form. The UK course is Access Systems Fundamentals.

For controllers on a network and integration with other systems, see networked access control.