Skip to content

WestPoint · Access · Paxton

Genuinely simple. And that has small print too.

Net2 and Paxton10 are the sensible answer for between five and fifty doors: they are run from inside, there is no licence per door and the day-to-day is handled by whoever is on reception. What they are not is a platform for twelve sites and an audit committee.

What it is, and what it is for.

Paxton is a British house that has been doing one thing for a long time and doing it simply: access control for installations that do not have a security department. Net2 is its classic platform, with software on a PC or a small server and controllers in a cabinet. Paxton10 is the new generation: it is administered from the browser, there is no software to install and it brings the video onto the same screen.

The problem it solves is the one most installations in Spain have, which do not have two hundred doors: a clinic, a school, a sports centre, an office, an industrial unit with a workshop and a store. Places that need cards, schedules, a log you can search and somebody inside who can add a person at nine on a Tuesday morning without calling anyone.

And it solves something that is not technical and weighs a lot: the cost of owning the system. The software is not paid for per door or per user, so the year-two budget holds no surprise. In installations of this size that is the difference between a system that is kept up and one that is abandoned.

How it's built.

Simple on the outside does not mean weak on the inside. It means the decisions have been taken for you.

In Net2 each controller keeps its copy of who can open and on what schedule. Turn the PC off, lose the network, drop the server: the doors carry on working and note down what happens so they can report it when somebody switches back on. That is not an extra, it is the architecture, and it is why you see installations working for years with the administration computer switched off almost all the time.

Paxton10 changes the approach: the server part lives in the installation's own unit and you get in from a browser or from a phone, without keeping a Windows PC as a critical piece. And it puts access and cameras on the same screen, which for a twenty-door site is exactly what is needed: a denied access with its image alongside, with nothing to integrate.

On credentials it does what it has to: encrypted cards from the usual families, fobs, codes, phones and wireless handles for the internal doors nobody wants to cable. With video and intruder detection there are reasonable integrations, and there is a programming interface to connect to payroll or to a visitor system.

Where it falls short, said plainly: federating many sites with separate administrations and a hierarchy by tenant, real server redundancy, permission approval workflows, and an audit trail at the level a demanding auditor asks for. It is not that there is none of that; it is that it is not what it is built for, and stretching it that far ends up costing more than choosing something else would have.

The risk that comes with being easy.

It is the one we see most in installations of this size, and the system does not cause it.

When administering is easy, everybody administers. It starts with one person, then their colleague for the holidays, then the maintenance chap so he does not have to wait, and a year later there are seven people with permission to add whoever they like. None of them has done anything wrong. There is simply nobody left who can answer who gave permission to whom, and when.

The second symptom is the permission group that grows on its own. Instead of deciding what profiles there are, somebody copies the one belonging to a similar person and changes one thing. Two years later there are forty groups with names like «offices 2b» and nobody dares delete any of them, because nobody knows who is inside.

Both are avoided on day one and cost one meeting: two administrators by name, a deputy, a short list of profiles decided on purpose and a quarterly review of the active credentials. With that, this holds up for ten years. Without it, it decays like any other, only faster.

Who it fits, and who it doesn't.

  • It fits from five to a few dozen doors, at one site or a few, with a manager inside who wants to run it themselves.
  • It fits when the cost of owning the system matters as much as the cost of fitting it: with no licence per door, the maintenance is spent on maintaining.
  • It fits if you want access and a few cameras on the same screen without building a control room. Paxton10 does a very clean job of that.
  • It fits where continuity rules: the doors carry on deciding on their own even with no network and no server.
  • It does not fit an organisation with many sites needing separate administrations and permissions approved through a workflow.
  • It does not fit if you have to account to a demanding audit for who granted each permission and when, with fine traceability.
  • It does not fit if intruder detection, video and access have to live under one operator desk with shifts. That is another league and another budget.

What we do with it.

In an installation like this the value is not in the equipment: it is in the decisions and in leaving it governed.

  • The design with the visit in front of us: which doors are really controlled, what happens on the way out, what each door does when the power goes and how it is coordinated with the fire system. Controlling the main door and leaving the loading door open all morning is recording somebody who was going to walk through anyway.
  • The list of schedule and zone profiles decided with the people who will use them, not with their boss. The factory at seven in the morning looks nothing like the meeting where the list was written.
  • The credential choice, with the encrypted card instead of the usual low-security one, which is copied with a twenty-euro device.
  • The installation: cabinet, power supply, backup, the protected reader cable and the network kept separate from the one the company works on.
  • The commissioning against tests written down before anything is fitted, including cutting the power to a door and checking it does what the design says it should.
  • The governance: two named administrators, the joiners and leavers procedure agreed with HR, and the review of active credentials built into the maintenance.

Who configures it after us.

With this one the answer is yes, and it is the main reason for choosing it.

Joiners and leavers, schedules, permissions by zone, issuing a card, cancelling the card of somebody who leaves and pulling the report of who went in where: the client runs all of that, and people with no technical background run it. You need neither IT nor security; in many installations it is administered by reception or by whoever handles HR, from the browser or from a phone.

What stays ours: adding a controller or a door, changing the cabling, touching the reader configuration, the firmware updates and the day something stops communicating. And the middle gap nobody plans for: redesigning the profiles because the company has reorganised. That is not adding somebody, it is redesigning a part of it.

For them really to be able to, little is needed, but it is needed. A couple of hours on their own system, with their doors and their names, and with the two or three people who are going to touch it. One sheet with the five procedures of the week —joiner, leaver, lost card, visitor, pull a report—. And the list of who is an administrator, with a date, because that is the first thing to get lost.

The administrator keys belong to the client. If tomorrow they want to change supplier, they have to be able to do it without asking our permission or paying a ransom.

Migrating from something else.

The most common thing is coming from an old system from the same house or from a contraption made of keypads and relays. In the second case there is nothing to migrate and that is a relief: you design from scratch, reuse the cable that is sound and throw away the rest.

Going from Net2 to Paxton10 deserves a warning, because it sounds like an upgrade and it is not. They are two different platforms, with a different way of storing the data and different hardware underneath. There are routes and there is equipment that can be reused, but that is checked door by door and cabinet by cabinet before anything is promised. Anyone who says it is one click has not opened the cabinet.

And on the old card: if it is one of the low-security ones, migrating properly includes changing the credentials. You can live for a few months with readers that read both, but coexistence is the route, not the destination.

Back to access control

Get started

Five doors or fifty?

Tell us how many there are, how many sites and who is going to handle the joiners and leavers. With that we will tell you whether this is right for you or whether we would be selling you short.