Security & surveillance
Access control: a key cannot be revoked
Everything sits in that sentence. A badge is cancelled in one action; a key is taken back by changing the lock — and nobody ever changes the lock.
The security article establishes that a physical door is a computing measure. This page draws the consequence, and it sits in a single sentence the rest only develops.
A key cannot be revoked. When somebody leaves, the key they had does not always come back, and even when it does nobody knows whether a copy was made. The only way to revoke it is to change the cylinder, then cut new keys for everybody.
That costs enough money and enough time that it is almost never done. The result is the one the audit article describes in the world of accounts: after five years, nobody knows how many people can get in.
So access control is not a convenience product. It is the only device in this family whose main function is to make revocation possible, and this page covers what that implies, including on the day the power goes.
A key cannot be revoked
Take an ordinary five-year-old business and ask a simple question: how many keys to the front door exist, and who holds them? The answer is almost always "I do not know exactly".
The mechanism is mundane and cumulative. A key was given to an employee who left and returned it; another to an employee who left without returning it; a third to a supplier for the duration of a job; a fourth was copied by somebody to avoid depending on a colleague.
None of those four situations is malicious and all of them are irreversible, because there is no record of who has a copy. A key has no identity: it opens, and it opens for ever.
The theoretical correction exists and is well known: change the cylinder when each person leaves. It is never applied because it costs the cylinder plus one key per remaining person, every time, and because the next departure starts it again.
That is exactly the problem the audit article describes for computer accounts, and it is the same problem in another material. The difference is that an account closes for nothing in thirty seconds and a lock does not close at all.
What a badge actually replaces
What you buy by installing access control is not the convenience of no longer hunting for keys. It is that an access becomes individually cancellable, without touching the door or anybody else’s rights.
The financial consequence is what decides, and it is written in two lines. Somebody leaving with a key costs a cylinder plus a key per remaining person, or costs nothing and leaves an access open. Somebody leaving with a badge costs a ten-second operation.
That moves the break-even towards a criterion that is neither size nor turnover: staff turnover. A ten-person business stable for six years does not need this; a ten-person business with four departures a year needs it more than it thinks.
The second benefit is granularity, and it only appears once the system is in place: not everybody needs to get in everywhere. The plant room, the stockroom, the office holding personnel files — those are three different doors and a single key treats them as one.
What is not a benefit, whatever catalogues promise: managing working hours. Access control records passages; it does not measure working time, and using it for that is a different use that calls for the next section’s precautions.
The log is the second product
Access control produces a second thing nobody consciously buys: a timestamped list of who went in where and when. It is useful, sometimes valuable, and it is a recording about people.
Its real usefulness is narrower than people imagine. It serves on the day of an incident — who was in the stockroom between six and seven — and it serves for nothing the rest of the time, because nobody reads an access log.
That is precisely why it demands a decision rather than a default setting. The family article sets the rule and it applies here unchanged: a written retention period, a designated person to consult it, and a defined reason to consult it.
Consultation deserves separate treatment, because it is what turns a security tool into a surveillance tool. Consulting the log after an incident is one use; consulting it to find out what time somebody arrived on Monday is another, and employees tell the difference perfectly well.
Our position, and it is slightly uncomfortable to write: the log is kept, limited in time, and consulted on an event rather than out of habit. A business using it to monitor hours should say so openly rather than do it quietly, because the discovery of that use costs more than it earns.
A power cut: what has to open
It is the one section in this whole pillar where the safest choice and the most secure choice point in opposite directions, and where the first wins without discussion.
An electric lock has two possible behaviours when power fails. It can unlock, which lets people out and also lets people in. Or it can stay locked, which protects the room and shuts in the people inside it.
On an escape route, the answer is dictated by people’s safety rather than by protecting property: the door has to be passable from the inside, power or no power, and with no key, no badge, no code. It is a building requirement and it comes before anything this page can propose.
On a door that is not an escape route — a plant room, a stockroom, a cupboard — the reverse choice is legitimate: it stays locked, and a mechanical key held by a named person allows entry.
The practical consequence is a question to put to the installer before ordering, and to have written down: for each door, what exactly happens when power fails, and how does somebody get out from the inside? An installer treating every door the same way has not asked the question.
The door is not the lock
Access control acts on one precise point of an assembly, and that assembly has other points. The budget concentrates on the electronic part, and what gives way is almost always somewhere else.
The frame first. An electric strike fitted to a thin or badly fixed aluminium frame holds no better than the frame, and a frame deforms. That is why a correct installation starts by looking at the door rather than by choosing a reader.
The hinges next, and it is the commonest fault we see: a door opening outwards with hinges reachable from outside can be taken off without touching the lock. The correction is a security pin and it costs very little.
The glazing last. A half-glazed door with an inside handle reachable through the glass is not a controlled door: it is a door with a reader on it. That is not a reason to do nothing, it is a reason to know it and to adapt what goes behind it.
The rule to apply before any order: ask the installer what, on this particular door, the weakest point is, and if they answer "the lock", ask the question about the frame and the hinges. It is the network article’s chain logic, applied to an object made of metal.
The shared badge cancels everything
There is one practice that instantly returns the system to the state of a key, and it appears in nearly every installation within a few months: the badge that gets passed around.
It never appears through negligence. It appears because somebody forgot theirs, because a delivery driver has to come in, because the person who opens in the morning is on leave, or because an employee has no badge and nobody ever took the time to make one.
The result is the same as a copied key, with one aggravation: section 3’s log now says something false. An entry is attributed to a person who was not there, which is worse than an absence of information on the day of an incident.
The corrections are organisational and there is no technical one. One badge per person from day one, including part-timers and trainees. A named visitor badge that gets handed back. And an explicit rule: a forgotten badge is replaced by a temporary badge at reception, not by a colleague’s.
That last rule requires the temporary badge to exist and to be available without authorisation. If three people have to be asked for one, the shared badge returns within the week — the same mechanism as every workaround described in the support article.
Three access levels, not twelve
An access control system allows as many profiles to be defined as you like, and that freedom is what makes half of these installations unmanageable within two years.
The configuration that survives is simple: three levels. Everybody, opening the common doors. Some, additionally opening one or two specific areas. And one or two administrators, opening everything and able to change rights.
What produces complexity is not need, it is the exception: somebody needing one more door for three months, for whom a bespoke profile gets created. Six exceptions later, nobody knows which profile opens what, and the system is administered case by case.
The rule that avoids it is the network configuration rule: whatever is configured fits on one page. A page with three columns — profile, doors opened, people — and a date. If it no longer fits, profiles need merging rather than the page needing enlarging.
The honest counterpart: in a business with several sites, several teams and staggered hours, three levels are not enough. But that is no longer the same scale, and at that scale the person administering the system is named and it is part of their job — which is exactly the condition the family article sets for any measure requiring a habit.
The visitor, the delivery driver, the supplier
Three quarters of the passages an installation did not plan for come from people who do not work for you, and it is the part of the subject configurations handle worst.
The visitor is the simple case: they are accompanied, they need no badge, and the door opens for them. Nothing to configure, provided somebody receives them — which assumes an intercom or a reception, hence section 9.
The delivery driver is the frequent case, and it is frequent at the same hours. A system that forces somebody to go down and open at every delivery will be worked around within a fortnight by a door wedged open, which cancels the whole thing. The right answer is a service door with its own access rather than a prohibition the working day will make impossible.
The supplier is the badly handled case: they come for a fixed period, they need real access, often to technical areas, and nobody thinks to remove that access when the job ends. It is the same oversight as the computer accounts in the audit article, and it is corrected the same way.
The correction is an access with an end date. It is a function almost every system has and almost nobody uses: a supplier badge that stops working at the agreed term, rather than a badge somebody will think of disabling one day.
What happens when the system fails
Like every piece of equipment in this pillar, access control fails. The difference from the rest is that its failure stops people getting into their workplace, which is immediately visible and immediately expensive.
The first question is section 4’s and it is settled: escape routes open from the inside, always. The second is different: how do people get in when the reader stops responding?
The answer is mechanical and it has to exist before the failure: an emergency key, on a cylinder with nothing to do with the electronic system, held by two named people and kept somewhere other than behind the door concerned. That last detail sounds comical and it causes a share of the emergency call-outs on this line.
The third question is about data: what happens to the list of rights if the controller is replaced? A configuration exported regularly, as for any equipment in the pillar, avoids rebuilding forty people’s rights by hand on a Monday morning.
And the fourth, often forgotten at purchase: the system has to keep opening for authorised people when the link to the server or to the internet is cut. Access control whose decisions depend on a connection turns a line fault into shut doors, and the pillar article explains how often that line drops.
The door somebody holds open
The technical part has to close on the limit that most often cancels it, and it has nothing technical about it: somebody comes in behind somebody else, because you do not shut a door in the face of an approaching person.
That is normal social behaviour and it is stronger than any system. No configuration prevents it, and the equipment designed to prevent it — airlocks, turnstiles, speed gates — has no place in an ordinary business.
The consequence is not to give up, it is to know what the system genuinely protects. It protects against one person entering at a moment when nobody is passing — at night, at the weekend, during a break. It does not protect against an entry at nine in the morning alongside six other people.
That changes what to equip first, and it is useful: the internal doors — plant room, stockroom, records office — benefit far more from access control than the front door, because nobody crowds through them and a passage there is always notable.
The wording we use with a client fits in a sentence: access control on the front door is an hours measure, and access control on internal doors is a security measure. Both are legitimate; confusing them puts the budget in the wrong place.
What to obtain at installation
Five things, asked for before ordering and obtained before the installer leaves. None requires technical skill to demand.
Each door’s behaviour during a power cut, written down door by door, with how somebody gets out from the inside. That is section 4 and it is the only point on this page that concerns people’s safety.
Administrative access to the controller, in your name, with the configuration exported. It is the same line as everywhere else in this pillar and it decides your ability to change supplier.
The mechanical emergency key, handed over in two copies to two named people, and kept somewhere other than behind the door it opens.
Finally, two documents: section 6’s three-column page — profiles, doors, people — dated; and the log’s retention period, written in days. Without the second, section 3 was not settled, and you will carry the consequence.
What we do, and what we will refuse to do
What we will refuse: installing access control on an escape route without exit from the inside being possible with no badge, no code and no key, power cut included. That point is not negotiable and it does not depend on what the client prefers.
We will refuse to configure more than three access levels in a single-site business, and to create a bespoke profile for a three-month exception. An exception is handled by an end date, not by another profile.
We will refuse to bring into service a system whose log has no written retention period and for which nobody has been designated to consult it. A recording about people without those two decisions is a responsibility we would be leaving you without saying so.
What we do: the door examined — frame, hinges, glazing — before choosing a reader; each door’s behaviour during a power cut written door by door; one badge per person from day one, with temporary badges available without authorisation; supplier access with an end date; the emergency key with two named people and kept elsewhere; and the three-column page handed over dated.
And what you can do this week without us: try to count the keys to your front door and name who holds each. The number you cannot attribute is the exact measure of what this page proposes to correct.
Frequently asked questions
Why replace keys with badges?
Because a key cannot be revoked: revoking it means changing the cylinder and cutting new keys for everybody, which never gets done. A badge is cancelled in ten seconds, individually, without touching anybody else’s rights.
At what size does this become worthwhile?
It is not a question of size but of staff turnover. Ten people stable for six years do not need it; ten people with four departures a year need it more than they think.
What happens during a power cut?
On an escape route, the door has to be passable from the inside with no badge, no code and no key — that is people’s safety and it comes first. On a plant room the reverse is legitimate, with a mechanical key held by a named person.
How many access levels should be created?
Three on a single site: everybody, some, and one or two administrators. Complexity comes from exceptions; handle them with an end date rather than another profile. Whatever is configured has to fit on one page.
What about shared badges?
They return the system to the state of a key and make the log false. One badge per person from day one, including part-timers and trainees, and temporary badges available at reception without authorisation.
Does access control stop somebody following another person in?
No, and nothing does in an ordinary business. It protects against an isolated entry when nobody is passing. That is why the internal doors — plant room, stockroom, records — benefit more than the front door.
Where we come in
The number of keys you cannot put a name against measures the problem exactly, and an afternoon produces it.
- We look at the door itself — its frame, its hinges, its glass — before any reader.
- We hold to three access levels on a single site, never more.
- We write the log retention period before the system goes into service.
We will install nothing on an escape route while exit still depends on a badge: that is not negotiable.
Read next
The badge that never came back: issuing, revoking, counting
A badge can be withdrawn — provided somebody withdraws it. The register, the badge lost on a Friday evening, and the departure handled in a minute.Security and surveillance: the order matters more than the product
It is the only family in the pillar bought against a fear rather than a need. And fear buys in the wrong order: what can be seen, first.What the insurer asks for: declaring, proving, being paid
The only third party that will ever examine your security does it once, after the loss. What it will ask for, and what has to exist beforehand.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.