WestPoint · Access · Synergis
Synergis does not bring boxes of its own. It drives other people's.
It is the access part of a platform that also runs the video, and it is designed to run controllers that are not its own. That explains what it does well and the two things that take work.
What Synergis is, if you have never seen it.
Genetec · Synergis — Enterprise, open architecture, highly integrable. With two particularities that set it apart.
The first is that you do not buy it on its own. You buy a security platform and switch on the access part: cameras, doors and number plate readers live in the same place, with the same users and the same log. Whoever is on duty at four in the morning does not change program to see what happened at that door: the denied access and the video of that second are on the same screen because they are in the same system.
The second is what separates it from the rest: it does not sell a controller line of its own as the backbone. It is built to supervise other manufacturers' electronics —the most widely deployed controller families, wireless locks from several brands, third-party readers—, so it can come into an installation that already exists without asking for what is on the wall to be thrown away.
You find it where the video is the centre of the operation and the doors are one part: airports, transport, large campuses, retail with many shops, public administration. And where hardware from three different suppliers has been inherited and one single head end is needed on top.
How it's built.
At the centre there is a service that holds the configuration and the identity of the system, and around it roles that are spread across several machines: one for the video, another for the access control, another for the reports. When the installation grows you do not change product, you move roles to more servers. That central service takes a second one on standby, and it is worth having: if it goes down, the doors go on opening but the system is left unable to be configured and unable to log.
Between the platform and the wall there is an intermediate device. It is the one that speaks the language of each controller manufacturer and the one that keeps the local copy so the doors go on deciding with the line cut. It is the key part of the architecture: how many doors hang off each one, where it is placed and which firmware version it carries determine how the system behaves on the bad day.
There are two different programs, and this matters more than it looks: one for configuring —doors, rules, permissions, integrations— and another for working every day. It is the exact line along which the work is divided between the client and whoever maintains the system. For the credential it takes encrypted cards, the phone, a code and third-party biometrics, and there are hosted and mixed versions for anyone who does not want their own server.
What takes work, and the brochure does not say it.
Open does not mean anything goes. It means there is a list of compatible models, and that list has small print: one specific model, with one specific firmware version, and sometimes with part of its features and not all of them. The wireless locks are the classic example: they integrate, they work, and what you can do with them is not the same as with a cabled door. It gets checked before it is promised, with the exact model that is on that wall.
An integration being called native does not mean it gives no work either. It means the manufacturer maintains it, which is a lot, and not that it configures itself: there is still a matrix of versions that have to match between the platform, the intermediate device and the firmware of the controllers. A badly planned upgrade is a weekend of work instead of two hours.
Who it fits, and who it doesn't.
It fits when the video weighs as much as the doors and there are people really watching screens: there, having both in the same system saves time on every incident and leaves a single log. It fits when there is inherited hardware you want to keep, when there are several sites run separately but watched together, and when somebody at the client is going to program against the system, because that route exists and is documented.
It does not fit when all you want is doors. With no video, or with a video that is not going to be changed or integrated, half the argument disappears and what is left is a high-end access control system with a high-end licence. Nor does it fit in a small, stable installation: the cost is not only the licence, it is the server, the annual maintenance and somebody who knows how to hold it up.
What we do with it.
The spread of the parts and the versions are half the project. The other half is writing down what has to happen at each door.
- The drawing of the platform before anything else: which server carries which role, whether a second central service on standby is needed, where the video is recorded and how all that is separated from the network the company works on.
- How many intermediate devices, where and with how many doors each. This is where it is decided which buildings go on working with the line cut and for how long, and that is tested by cutting it, not by reading about it.
- The compatibility check on the existing hardware, model by model and firmware by firmware, before putting a line in the quotation. If something cannot be kept, it is said there and not in the week of the installation.
- The rules that join door and camera: what the system does with a denied access, a forced door or a door left open longer than it should be. Each one with its alert, its image and its recipient written down, which is the part that makes most systems useless when it is missing.
- The signed tests and the documentation of what is left behind: the door map, the addresses, the inventory of versions of everything, a copy of the configuration and a restore that has been tested. The version inventory is the first thing you need on the day of an upgrade.
Who configures it once we leave.
Here the line is drawn by the product itself, and that helps.
The two different programs are exactly the split that has to be made. The day to day goes in the working one and in the web client: registering a person, withdrawing access, changing a schedule, a one-off visit, looking up who went through where, pulling out a report. The client's team handles that and it should not depend on anybody outside. It can also be limited by site, so that each branch manages its own people without seeing anybody else's.
The underlying configuration is another matter: creating doors, changing the permission model, touching the rules that link access to video, adding integrations, changing version. There you need somebody who knows the installation, because a small change to a rule can stop somebody being alerted and nobody will find out until it is needed. There are clients with strong IT who take this part on too, and that is reasonable; what does not work is taking it on without anybody having written it down.
For them to run it, three things have to be handed over: the document on how the system is put together and why things are named as they are, their own administrator accounts limited by role, and training split in two —one for whoever manages people and another for whoever operates in front of the screens—. The second is usually skipped and it is the one that pays off most: an operator who knows what they can do with a door from their screen sorts out in half a minute what is otherwise a phone call.
Coming from another system, and being able to leave this one.
It is one of the platforms where a migration hurts least, precisely because it drives other people's hardware. If what is on the wall is from a compatible family, the head end is changed keeping controllers, boards, readers and cabling, and the electronics are replaced later and in stages. That turns a full replacement into a plan spread over several years, which is how large installations can afford it.
What has to be looked at closely is the condition of that hardware, not only its compatibility. A controller that is compatible but discontinued, with firmware that is no longer updated, gets connected and becomes the piece that sets the ceiling of the system. Keeping it for a couple of years as a bridge is sensible; as a final plan it is putting off the spending and paying for it twice.
Where to go next.
If what you are deciding is bigger than the brand —which credential, which doors, who governs the list—, that is in the area.
Get started
The doors and the video on the same screen?
Tell us what video you have, what controllers are on the wall and how many doors there are. The first thing we will tell you is how much of that can be kept, because the quotation depends on that far more than on the licence.