Expertise

Access control

Access control decays through its rights table, never through its readers.

Parent division
Physical and cyber security

The problem

The difficulty is not opening a door; it is knowing who is entitled to open it eighteen months later.

Access control hardware is mature. A reader, a magnetic lock, a controller and a strike work, and a correctly cabled installation runs for years without intervention.

What decays is the rights table. Arrivals are recorded, departures rarely. Exceptional permissions granted for one intervention are not withdrawn. After two years nobody can say who may enter where, and the system keeps opening doors all the same.

An installation whose rights are never reviewed is not access control: it is a passage log. The design must therefore address the rights review procedure as much as the technical architecture.

The rights table and its review loop, schematic

01Zoning and profiles
Zones and profiles are written before any equipment is chosen.
02Equipped door
Reader, locking device suited to the leaf, position contact, emergency release.
03Controller
Decides on its own when the network fails. That is what separates access control from a remote directory.
04Supervision and log
Passages, refusals, forced or held-open doors, escalation and handling.
05Rights lifecycle
Arrival, movement, departure, temporary permission with automatic expiry.
06Periodic review
The discrepancy found is recorded and corrects the profiles. It is what reveals whether withdrawal works.
Schematic. The accented path is the loop that decides what the system is worth — the one that closes, or does not.Typical sizing figures, not measured on an installation. The rights review interval is the one an information security management system commonly sets.

Scope

What the service covers

Zoning and access policy
The building divided into zones, profiles defined, crossing rules between zones, treatment of escape routes and regulated exits.
Door equipment
Readers, locking devices suited to each leaf type, position contacts, exit buttons, release on fire alarm and manual emergency release.
Controllers and network
Controllers that keep deciding access when the network is down, backed-up power, supervised links, segmentation of the security network.
Identity management
Holder lifecycle, badges, profiles by role, temporary permissions with an expiry date, withdrawal procedure on departure, periodic reconciliation with human resources.
Visitors and contractors
Pre-registration, badge issue and return, mandatory escorting beyond a given zone, traceability of escorts, automatic expiry at the end of the day.
Logging and supervision
Log of passages and refusals, documented retention, alarms on forced or held-open doors, escalation to supervision and a handling procedure.

Situations

The most frequent situations

Administrative building
Public areas, working areas, technical areas. The constraint is having the public and staff share one building without multiplying reception desks.
Technical site or server room
Few holders, high traceability requirements, contractors escorted as a rule. The log must stand up in an audit.
Diplomatic mission
Zones under distinct regimes, strict visitor handling, how it works with the guard post and video surveillance, lockdown procedures.
Industrial site
A large and shifting population, mass entries and exits, a headcount of those present during an evacuation, interfaces with time management.

Requirements

What to require, of us as of anyone

These requirements hold whichever supplier is appointed. Written into a tender, they filter out the responses that will not hold.

  • The list of zones and profiles, written before any equipment is chosen, and approved by those who will operate the building.
  • The system’s behaviour when the network fails, when the server fails, and when the power fails. The three cases are distinct.
  • The procedure for withdrawing rights when someone leaves, its deadline, and who is accountable for carrying it out.
  • Automatic expiry on temporary permissions, without which they become permanent.
  • Compliance of emergency exits: no security device may prevent an evacuation.
  • The retention period of the passage log, and the access regime for that log.
  • A periodic review of rights, scheduled and documented, recording the discrepancy found at each review.

Pitfalls

Common mistakes, and what they cost

Leaving badge management to one person
The day they are away, exceptional permissions are settled by lending a badge. A lent badge cancels access control and corrupts the log.
Not planning the degraded mode
An architecture that refers every access decision to a central server locks every door at the first network incident. Controllers must decide on their own.
Granting permissions with no expiry
A three-day permission that never expires becomes a permanent right nobody decided to grant. This is the mechanism by which the rights table loses its meaning.
Treating access control separately from building security
Access control, intrusion detection, video surveillance and intercom all describe the same event. Installed independently, they leave the operator to correlate by hand what the system should correlate for them.

Questions

Questions asked before consulting

Badge, code or biometrics?

A badge covers most needs and can be revoked instantly. A code alone proves nothing, since it can be passed on. Biometrics answers a need for non-transferability in a small number of zones; it processes special categories of personal data, which imposes a legal basis, a retention period and an alternative for people who cannot use it. The choice is made zone by zone, not for a whole building.

What happens during a power cut?

Locking devices behave differently by type: some stay locked, others release. That behaviour is decided door by door, weighing security against evacuation, and never by default. Backed-up power must cover controllers, readers and door devices for a duration settled at design stage.

How should contractors and visitors be handled?

Under a regime distinct from staff: pre-registration, a badge that expires automatically, restricted zones, mandatory escorting beyond a given zone, and a traced return. A visitor handled as a permanent holder is a permanent permission granted by accident.

Should access control be linked to video surveillance?

The link brings a great deal: repeated refusals or a held-open door become an alarm carrying the matching image, which lets the event be qualified without walking to it. The link presupposes a clock shared by both systems; without synchronisation, the sequence retrieved does not match the event.

Can the existing installation be kept?

Cabling and door devices are often reusable; controllers and management software are the limiting factor. A door-by-door survey states what is retained, what is replaced and what must be brought back into compliance. Full replacement is justified when the badge technology in service is no longer secure.

How often should rights be reviewed?

At least twice a year across all holders, and at every movement for the person concerned. A periodic review is only worth running if the discrepancy found is recorded: that discrepancy is what reveals whether the withdrawal procedure actually works.

Evidence

Where we have applied it

  • Energy and critical infrastructure2024

    Mining site — server room and backup power

    Construction of a secure technical room and its power chain, on an isolated site with no reliable public grid.

    Weeks of measurement before sizing
    4
    Load tests per year
    12

    Reference KP-2024-008

All projects

Consultations · Pre-qualifications · Partnerships

Let us discuss the actual case.

Describe the site, the dominant constraint and the deadline. We will say what requires a preliminary study and what can be committed directly.