WestPoint · Access · AEOS
In AEOS the intelligence is in the box on the wall.
A European access control platform with a different idea of architecture: the controllers do not hold a copy of the list, they hold the whole set of rules. When the line is cut, the system is still the same system.
What AEOS is, if you have never seen it.
Nedap Security · AEOS — Enterprise, widely deployed in Europe. And the difference that really matters.
In most large access control systems, the controller on the wall holds a reduced copy of what it needs to carry on opening if the network goes down: a list of cards and some schedules. It works, and while the outage lasts the finer rules stop being applied. AEOS is built the other way round: the complete configuration goes down to the controller, which is a small computer with its own database. If the server disappears, that building carries on applying the same rules it applied yesterday.
That changes what kind of installation holds up. A network of small sites spread over three countries, with lines that are not always there, does not need a server at each one to have serious behaviour at every door. And a critical building does not have a degraded mode nobody remembers until the day they need it.
The other thing that places it is where it comes from: it is Dutch, it is widely deployed in Europe, and you can tell in how it is designed —data protection is not an annexe— and in the fact that it is administered entirely from a browser, with no program to install on the workstation. You find it in public administration, healthcare, universities, airports, utilities and companies with sites in several countries.
How it's built.
The server holds the configuration and the history and is administered through a browser. It looks like a detail and it is not: giving administration access to a new person requires nothing to be installed and no trip through IT, and the client can work from wherever they work. Underneath are the controllers, which are the heart of it: they carry the complete configuration, they decide on their own and they connect over the network. Out of them runs the bus to the readers.
The permissions model is the trait that most changes the day-to-day work. It is not built by adding up lists of doors: you describe areas, entrances, schedules and profiles, and you combine them. It is flexible and it scales very well when the structure is well thought out, and it is the place where an improvised structure turns into a problem you can no longer redo with thousands of people inside it. Here designing the model is not good practice: it is the project.
The licence goes by function, in modules, rather than by a single door count. That has an advantage —you pay for what you use— and a trap: what you want to do in year two may be a module that was not bought. On credentials it takes encrypted cards, phones and biometrics, with its own readers and third-party ones; and the same manufacturer comes from the world of identifying vehicles at a distance, which you appreciate when the installation has barriers and loading bays and not only doors for people.
What is decided at the start and governs everything.
The structure of areas and profiles. Drawn well, a company of five thousand people is governed with a handful of profiles and the exceptions can be counted on your fingers. Drawn badly —or not drawn at all and sorted out case by case— you end up in the same place as on any other platform: hundreds of combinations nobody can audit, with the aggravating factor that here the model is more expressive and therefore the mess can be more sophisticated.
The licence scope. It is worth putting the list of what you want to do over the next few years on the table before signing: lockers, visitors, integration with intruder detection, headcounts for evacuation. Not to buy it all on day one, but to know what route is open and what each step costs. Finding out when you already need it turns an extension into a negotiation.
Who it fits, and who it doesn't.
It fits when there are many locations and not all of them have a line you can rely on, and when you want the same permissions model applied the same way in several countries. It fits where data protection weighs on the decision and you have to be able to explain what is stored, where and for how long. And it fits where somebody is willing to learn the model and maintain it, because it rewards the client who gets involved.
It does not fit a small installation that wants something simple and cheap: the flexibility of the model is exactly what makes it excessive for eight doors and a stable workforce. And it does not fit where nobody is going to spend time on the structure. A highly configurable platform in the hands of somebody who does not want to configure ends up used like the simplest one of all, and you have paid for a capability you do not use.
What we do with it.
Here designing the permissions model is charged for as what it is: the most important part of the work.
- The model of areas, entrances, schedules and profiles, drawn with the client before touching the system. With names that mean something to their company, with the real exceptions written down —the seven-in-the-morning ones on the loading bay, not the meeting-room ones— and with the rule written for who may create a new profile.
- The split of controllers by working unit and not by what is convenient on site: which chunk has to carry on being the same system when the line is cut. And checked by cutting it.
- The synchronisation with the HR system and the design of which piece of data is master, plus the initial load with its clean-up: duplicates, credentials with no owner, people who are no longer there.
- The tests, with this platform's own test first: disconnect the server and check that a fine rule —a split schedule, an area that requires having passed through another— is still applied the same way. Plus power cuts, emergency, headcounts if there are any, and the client administering from their browser with their own account in front of us.
Who configures it once we leave.
It is built to be run by the client. The question is whether the client wants to.
Being administered from a browser removes the usual friction in one go: there is no program to install, no permission to ask for to set up an administration workstation, and adding somebody to manage access is a matter of creating an account with its scope. The day-to-day —people, credentials, schedules, permissions by area, visitors, reports— belongs to the client and should not come through us even once.
The boundary is in the model, not in the tasks. Creating profiles and areas, changing how they combine, touching the split of controllers, adding integrations or modules, upgrading a version: that is structure. And here the structure is more delicate than on other platforms precisely because it is more powerful: a new profile fitted badly throws no error, it grants a permission nobody meant to grant. There are clients who take this part on as well and it works very well, on one condition: that it is a person who has understood the model and not whoever is free that week.
What has to be handed over for them really to be able to is, above all, the model document: the drawing of areas and profiles, what each one means, what exceptions exist and why, and the naming rule. Plus their own accounts with a limited scope, separate training for whoever manages people and for whoever maintains the model, and a short guide to what is not touched without warning. That document is what turns a flexible platform into an installation that can be maintained for years; without it, the flexibility works against you.
Coming from another system.
Plainly: the controllers get changed. This platform works with its own iron, so a migration from another manufacturer replaces the electronics. What is kept is what is usually most expensive to redo: the data cabling out to the cabinets, the power supply and the building work. And it can be done building by building, with both systems coexisting while the transition lasts.
Readers can stay in many cases, and on the doors that matter it usually pays to change them to get real supervision and a real encrypted channel. Credentials, the usual: if the card technology can be read and the number can be imported with its format, people do not notice the change, and that saves the worst part of a migration, which is handing out five thousand new cards.
Where to go next.
The area covers what does not change with the brand: which credential, which doors, what each one does with no power, and who answers for the list.
Get started
How many locations, and how many with a bad line?
That is the question that makes this platform interesting. Tell us how many sites there are, how many doors at each, what is fitted today and how the permissions are managed, and we will tell you whether your case is solved with a central system or with the intelligence spread out.