WestPoint · Access · C•CURE 9000
C•CURE 9000 is designed twice. The first time is the architecture.
An access platform for large installations, with controllers that decide among themselves without asking the server. The decision that weighs most is not taken at the door: it is taken by choosing whether there is one system or several.
What C•CURE 9000 is, if you have never seen it.
Johnson Controls · Software House · C•CURE 9000 — Enterprise and large installations. Starting with what makes it different.
It is the head end: the software where the people, the permissions, the schedules and the log live, while the controllers on the wall are the ones that open. So far, like the others in its class. What sets it apart is how much work goes down to those controllers: they are grouped and they talk to each other, so that rules which normally need the server —nobody passing twice on the same card, two people being needed to open a room— carry on being applied even when the server is not there.
That matters where the network is large and not always whole: a campus, a hospital with pavilions, a plant with several units, a site with ten floors and four comms rooms. On the day a section goes down, the system does not go stupid: it carries on applying the real rules and not just the list of who may pass.
You find it in healthcare, industry, data centres, public administration and large corporate sites, often alongside video from the same house, because the manufacturer also has video platforms and the join between the two is made from the inside.
How it's built.
Windows server, SQL database and services that can be split across machines when the installation calls for it. Installed administration clients, a web client for day-to-day work and a mobile app for operation. The database is the piece to size sensibly: here the volume is not set by the number of doors, it is set by the events per day and how long they have to be kept.
It talks to two families of controllers: the manufacturer's own, which is the one that allows the group working and the encryption between controllers, and the most widespread family on the market, shared by several platforms in this range. Being able to choose matters more than it looks: the first gives features the second does not, and the second lets you into an installation that already exists without changing the wall.
On credentials it takes what you would expect —encrypted card, phone, code, third-party biometrics, high-security identity credentials— and outwards it has integration routes by program and for importing people from HR. With video from the same house there is a single console; with video from other manufacturers it also integrates, and then there is a version matrix to keep an eye on.
The decision you pay for three years later.
On this platform there is one, and it is very specific: one system or several.
A company with five sites can build five independent systems or one main system with satellites that govern themselves and share the people and the policies. The first option is cheaper, it starts sooner and each site does as it pleases. The second costs more and is the one that lets a leaver in HR close the doors at all five sites the same morning.
The important thing is that going from the first to the second is not a tick box: it is merging five databases with duplicated people, permissions with the same name and different meanings and card numbering that collides. That is a project with a shutdown and a review of every permission, and it always arrives at the worst moment: just as the company has bought its sixth site. Choosing it on day one, even if it is rolled out in phases, is the difference between growing and starting again.
Who it fits, and who it doesn't.
It fits genuinely large installations, with many doors, many events a day and requirements that go beyond opening: two people to get into a room, headcounts, zones you cannot set foot in without having passed through another first, records you have to be able to defend. And it fits where continuity rules: if the network splits, what carries on working here is more than on most.
It does not fit a small installation, nor a medium one that is not going to use any of that. The cost is not only in the licence: it is in the server, the database, the annual maintenance, the update windows and the fact that somebody has to understand it. A building with twenty doors and office hours is solved with far less, and putting this in there is buying capacity nobody is going to switch on.
What we do with it.
Half the work happens before anything is installed, and the other half is testing what never gets tested.
- The architecture decision, written down and reasoned: one system or several, which sites are satellites, what is shared and what is governed locally. With the cost of each option in front of you, because it is a business decision and not an installer's.
- The database sizing based on real events, not on the number of doors: how many passages a day, how long they have to be kept and what gets archived. That is what decides whether in year three the reports come out in seconds or in minutes.
- The choice of controller family door by door where there is existing iron, keeping what can be kept without giving up the features that have been asked for. That boundary is drawn in the design and written down.
- The import of people from HR with the dirty work included: duplicates, people who have gone, cards with no owner, fields nobody filled in. Cleaned before it goes in.
- The tests almost nobody runs: disconnecting the server and checking the hard rules are still applied, splitting the network in half, cutting the power per controller, testing the release on fire alarm and having the client pull their own reports. Plus the backup actually restored and the upgrade plan written down.
Who configures it once we leave.
It splits the work well, if somebody has taken the trouble to define the operator permissions.
The day-to-day is run by the client: joiners, leavers, schedules, permissions by zone, visitors, cards, reports. The operator permissions are fine-grained —you fence off what each person sees and can touch, and it can be split by site or by company inside the same system— so it is possible for HR to manage people, for security to manage access and for neither of them to be able to touch the configuration. That separation has to be built: it does not come ready made.
The structural work is not the client's: adding doors, changing controller groups, touching hard rules, moving the architecture, updating versions. And there is one case that looks everyday and is not: changing what the doors do in an emergency. That touches the fire system and the evacuation, and it is not changed without reviewing both. If somebody on the client side wants to be able to do it, they are trained for it and it is written down who signs off each change.
For them to be able to run it you need the usual —the model document, their own accounts with a limited scope, the joiners and leavers procedure, training by role— and one more thing: the version inventory and the upgrade plan. The client has to know that exists and that it comes round every so often. An installation whose IT department does not know there are update windows freezes without deciding to.
Coming from another system, and being able to leave this one.
If the wall has controllers from the widespread family, they are kept: the head end is changed and the field iron stays with its boards, its readers and its cabling. That is the route that turns a migration into an upgrade and the one that lets you do it building by building. If what is there is another manufacturer's proprietary electronics, it gets changed, and then what is kept is the cabling and the building work.
There is a nuance worth being clear about going in: the features that make this platform strong —the group working between controllers, the encryption between them— live on its own family. Keeping somebody else's iron is possible and is sometimes the most sensible thing, and it means giving up part of that on the doors that use it. A mixed installation, with the platform's own electronics in the critical zones and the inherited ones everywhere else, is a good decision if it is taken on purpose.
Where to go next.
If the decision is not yet about a brand but about what you are asking of the access control, start with the area page.
Get started
One site or several?
It is the first question and the one that moves the most money. Tell us how many sites there are, how many doors, what controllers are fitted and whether the joiners and leavers come out of the HR system. With that you can talk about architecture before talking about licences.