WestPoint · Access control
The card that gets lent out. The spreadsheet nobody has updated.
Who goes in, where, when — and a record of all three. Project, equipment, installation and maintenance of access control, designed together with the cameras, the alarm and the fire detection.
The question that breaks the system.
«Who went into that room on Thursday afternoon?»
It is the question that comes after a small loss, an information leak or an accident, and it is the one that shows whether there is access control or just doors that open. In many installations the honest answer is that a card went in. Whose card it was that Thursday is another conversation.
Because the system that was installed was fine, and what has degraded is everything else. Cards get lent out so the maintenance man does not have to go down two floors. Car park fobs get lost and new ones are handed over without cancelling the old one. The list of who has what was kept by one person in a spreadsheet, and that person no longer works here. And there are people who left a year ago whose credential still opens doors, because removing someone was not in anybody's procedure.
None of that is an equipment failure. It is what happens when access control is installed and nobody designs how it will be governed.
Three things at once, and the third is the one missing.
Access control has to do three things at the same time: open for whoever should get in, not open for whoever should not, and leave a record of both. Any installation does the first two on the day it is switched on. The third is the one that matters when you have to answer to somebody outside, and the only one that collapses on its own if nobody maintains it.
Leaving a record is not keeping a log: it is that the log can be read and can be defended. That each credential is in a person's name and not a job title. That people being added and removed goes through the same place as HR does. That you know who gave permission to whom, and when. And that you can pull the list for a particular day in a minute, without ringing the installer.

What gets decided in the project.
The decisions here are not about brands. They are about how the people who will go through those doors every day actually work.
- How each person is identified. Card, mobile, code, fingerprint — and each with its trade-off: the card gets lent out, the code gets told, the mobile runs out of battery and the fingerprint does not work with gloves or with the hands of somebody who works with their hands. Almost always the answer is different on the street door and in the server room.
- Which doors are really controlled. Controlling the main one and leaving the loading door open all morning is building a system that records the people who were going to walk through anyway.
- What happens on the way out. If it only reads on the way in, the system does not know who is inside. You need that on the day of an evacuation, and on that day it cannot be configured.
- Timetables and exceptions, with the people who will use them in the room. The list of profiles written in a meeting and the reality of a factory at seven in the morning are nothing alike, and a system that cannot take the reality ends up with the door wedged open with a fire extinguisher.
- How it is run day to day: who adds people, who removes them, how quickly and who reviews it. Access control without this paragraph written down degrades within a year, whatever the brand and whoever installs it.
What the door does when the power goes.
It is the most important decision in this area, and it is almost never taken by the person who should take it.
A controlled door can end up in one of two states when the power disappears or the network drops: open or closed. Both are correct and both are dangerous, depending on which door it is. If it stays closed, there may be someone inside who cannot get out. If it stays open, the warehouse spends the night open.
It is not an installer's decision: it is a security decision, door by door, taken with the person responsible for the site and put in writing. And it has to be coordinated with the fire detection, because on the day it goes off there are doors that have to release on their own and others that must not.
Same with the backup: how long the system holds without power, whether it covers only the electronics or the locks as well, and what happens once that time is up. Access control that does not survive a two-hour cut protects you on the good days.
Biometrics is not the default answer.
It is sold as the natural next step —a fingerprint cannot be lent out— and sometimes it is exactly what is needed. But a fingerprint or a face is personal data of a special class, and using it has to be justifiable: why a card is not enough on that particular door, what is stored, where, for how long, and what alternative there is for someone who does not want to give their fingerprint.
That is not a formality at the end: it is part of the project, and it is far better resolved before buying the readers than after putting them on the wall. When the justification does not hold up, the honest thing is to say so and propose something else, even though biometric equipment invoices better.
And there is a practical consequence worth knowing: on a door where two hundred people pass in ten minutes, read time matters more than the technology. There are sites where biometrics does not fail on accuracy. It fails on the queue.
On its own, it is worth half of what it could be.
An access denied at four in the morning, in a system put together in pieces, is a line in a log nobody is going to read. In a system that was designed, it brings up the camera on that door, saves the image alongside the attempt, alerts whoever is on duty and lets them see what is going on before deciding.
It works the same way in the other direction: the intruder alarm has to know who has come in with a valid credential so it does not go off, and the fire detection has to be able to release the right doors without anyone running to disarm anything.
This is what does not come out when each part is installed by a different supplier. Not because any of them does a bad job, but because nobody was asked to think about the three together.

How you know it works.
Five checks anyone can do, without knowing anything about security, in the month after handover.
- Ask for the list of active credentials and look for three names of people who no longer work here. If they show up, the system is installed but it is not governed.
- Ask who went into a particular room on a particular day. It has to come out in a minute, with names, and without ringing anybody outside.
- Cut the power to a door and watch what it does. What it does has to match what is written in the project for that door.
- Try to get through with somebody else's credential. That has to leave a trace somewhere: a log entry, an alert or an image.
- Ask how long it takes for somebody dismissed today to lose their access. If the answer is not «the same day» and there is no procedure behind it, the most important door is open.
What we do not do.
We do not install access control unless there is somebody inside in charge of adding and removing people. That is what keeps the system useful a year from now, and when it does not exist we say so before quoting, rather than handing it over and watching it degrade with our name on it.
We do not fit biometrics because it looks better in the bid. If that door is solved with a card and a decent procedure, that is what solves it.
We do not keep the administrator passwords. If a client wants to change supplier, they have to be able to do it without asking our permission. There is plenty of installed kit out there held hostage by a password nobody would hand over.
The other seven areas.
Access control is the one that talks most to the rest: to the camera that documents, to the alarm that must not go off and to the fire system that opens the doors.
The twenty platforms we work with.
An access control integrator is chosen, among other things, for which platforms they know how to work with: someone who has one deployed across five sites is not looking for «an installer», they are looking for someone who has actually handled it. Each one with what it is, who it suits, who it does NOT suit, and who can administer it after we leave.
What people ask about access.
The ones that come up most. There are 40 on this subject, and the other 34 are in the question index.
All the questions, by subject▸What is best for identifying people: card, fob, mobile, PIN or fingerprint?
It depends on what you lose if that credential ends up in the wrong hands, and it is almost never the same answer on the street door as in the server room. The useful question is not which technology is best, but what happens the day somebody uses it who should not.
Each one has its trade-off, and it is worth stating them in full. Cards and fobs get lent out and get lost, and they are the most convenient and the cheapest to replace. A PIN can be said over the phone, so more people know it than the record shows. A mobile is almost never lent out because nobody hands over their phone, and it runs out of battery. A fingerprint cannot be lent out and in exchange drags a serious legal problem behind it, and does not work with gloves or with heavily worked hands. A number plate identifies the car, not the driver.
The rule that works is duller than the technology: one credential per person, in that person's name, and two factors only on the doors where the risk justifies it. What we have seen since 2006 is that these systems rarely fail on credential technology. They fail because nobody removes anyone.
▸How do I stop people lending each other cards?
You do not stop it entirely: a card is an object and objects get passed around. What you can do is make lending it inconvenient and make it leave a trace.
What you fit: compulsory reads on the way out as well, and anti-passback, so the same credential cannot enter twice without having left; a speed gate or a corridor that only lets one person through at a time; the photo of whoever is passing on the control room screen; the image from that door's camera saved alongside the event; and a second factor on the doors that deserve it, because a PIN or a fingerprint does not get lent out with the card.
And the part that is not technical, which is usually the cause: if people lend each other cards it is almost always because the system gets in their way. Somebody needs to get into a place at six in the morning and does not have permission, so they ask for the card of someone who does. Before chasing the lending, it is worth reviewing the permissions, because if the reason is still there, the habit comes back.
Access control: which credential on which door Alarms verified with the video from that moment
▸Is it worth using the mobile as a credential?
It is worth it where access has to be granted and withdrawn remotely and in a hurry. A contractor coming in on Saturday gets their credential by email on Friday afternoon and nobody has to wait for them with a card in hand; on Monday it expires by itself.
The trade-offs have to be told up front: the battery, changing handsets, and above all that nobody can be forced to install a company app on their personal phone, so there always has to be an alternative. On site, with gloves on or with your hands full, getting your phone out is worse than presenting a card. And almost every platform charges for the mobile credential per user per year, which is a cost the card does not have.
There is one technical detail that decides a lot: if the read is short-range proximity you have to bring the phone up to the reader, like a card, and if it is longer-range radio you can open from several metres away. The second sells very well and opens doors that should not open, because the system does not know whether whoever pressed is standing at the door or walking down the corridor. In practice the mobile lives alongside the card, it does not replace it.
Brivo Access: access in the cloud and on mobile Access control: which credential on which door
▸Is a PIN keypad good enough to control a door?
As the only credential, only on low-risk doors. A PIN is the one thing that can be passed on by phone, in writing or shouted from the other end of the corridor, and that means more people end up knowing it than the system records.
Its other two problems are that it does not expire on its own and it does not identify anyone: if six people share the code for a room, the log says the code went in, not who. If it is used, it has to be one PIN per person with a scheduled change, not a zone code written on a piece of paper inside the electrical panel.
Where the PIN is very useful is as a second factor. Card alone during working hours, and card plus PIN out of hours or on the warehouse door: you gain a lot without changing credential or buying biometric readers. And it is worth looking at the keypad itself: the ones that block the side view and the ones that shuffle the position of the numbers stop the person in the queue learning the code by repetition.
Paxton Net2: small installations, door by door Doors, readers and permissions, told in full
▸Can the barrier be opened by reading the number plate?
Yes, and in company car parks it works well because the driver does not have to wind the window down or look for anything. What has to be clear is that the number plate identifies the car and not the person inside it.
For it to read properly you need specific things: a camera dedicated to that with its own infrared lighting, the angle and distance worked out for that lane, one lane per camera, and a written decision on the odd cases — foreign plates, dirty or bent plates, motorcycles with no front plate, trailers, courtesy cars. And always a second way in when the read fails: intercom to the control room, long-range card or fob.
There is a data protection side worth resolving in the project: a number plate linked to a person is personal data. That means you have to inform people, set how long the movement is kept and not reuse those records for anything other than what was stated, such as checking what time each person arrives.
Number plate reading on entrances and barriers Car parks: vehicles in and out Doors, readers and permissions, told in full
▸What do I do when someone loses their card or leaves it at home?
Cancel the lost one the same day and issue another; and for the one left at home, a temporary credential that expires by itself at the end of the shift. Both have to be written into a procedure, because they are the two things people most often improvise.
What cannot happen is issuing a new one without cancelling the old one. That is how you end up with a list holding more active credentials than people, and car park fobs that have been opening the barrier for years with nobody knowing whose they are. The other habit to stop is the loan card at reception, the one that has been passing from hand to hand for half a decade and always shows up in the log as the same person.
It is also the best measure of the system's health: ask for the list of active credentials and count how many have no name behind them. That number says more about the state of the access control than any report.
Cancelling and issuing credentials, step by step Technical support: day-to-day incidents
Get started
Do you know who can get in today?
If the answer takes more than a minute, there is work to do. Tell us how many doors there are, what system is in place and how people are added and removed, and we will tell you what can be fixed by configuration and what really has to be changed.