When a client asks for "access control", the conversation usually starts with the question "card or fingerprint?". That is actually the smallest part of the decision. The reader is only the visible side of the system; behind it sit a controller, a lock, a power supply, access rules and an event log. If any one of these is chosen carelessly, even the most modern reader doesn't help. We'll look at how the system is built, what each type of credential offers, where the risks are, and how to choose for your own site.
What an access control system consists of
Regardless of the manufacturer, almost every system has the same building blocks:
- Reader — the device next to the door that accepts the credential (card, code, fingerprint, face, phone). It is mounted on the outer, unsecured side.
- Controller — the "brain" that compares what was read against the database and decides whether to unlock. It is installed in a protected place, inside the secured area. The decision should not be made in the reader itself: if someone rips it off the wall, they must not gain access to the lock.
- Lock — an electric lock, an electromagnetic lock (maglock) or an electric strike. The choice depends on the type of door and on how it should behave when power is lost.
- Power supply — a regulated unit, ideally with a backup battery. Locks are among the largest power consumers in the system, and weak power causes random failures.
- Exit button — lets you leave without a credential. A door-status contact is often added as well, to detect a door left open or forced open.
- Software — manages users, permissions, schedules and the log. It can run on a computer on site, on a small server or in the cloud.
Fail-safe and fail-secure — what happens when the power goes out
This is decided for each door individually and relates not only to security but also to people's safety.
| Mode | When power is lost | Typical use | Watch out for |
| Fail-safe | The door unlocks | Doors on an evacuation route; often with a maglock | When the power fails the site is left unprotected — backup power is needed |
| Fail-secure | The door stays locked from the outside | Storage room, server room, archive | Exiting must remain possible mechanically |
Types of credentials: how they work and where their weak points are
PIN code
The cheapest option — there is nothing to lose. But a code gets watched over shoulders, written on a note next to the door and "shared" between colleagues. If it is a shared code, you can't tell who exactly came in. It suits secondary rooms, and for more sensitive zones it is better as a second factor alongside a card.
Contactless cards and tags
The most widespread solution — it is fast, cheap and easy to administer: a lost card is simply blocked. There is, however, a big difference between generations of the technology:
- Older 125 kHz cards transmit only a fixed number, with no cryptographic protection. They can be copied with readily available equipment, often without the holder noticing. They are still common, but they are not a good choice for a new site with higher requirements.
- 13.56 MHz smart cards with cryptographic protection authenticate through an exchange of data rather than a bare number. The oldest schemes of this type also have publicly known weaknesses, so for a new installation ask the supplier what encryption is used.
The link between the reader and the controller matters too. The old Wiegand protocol transmits data without encryption, so the cable behind the reader is a vulnerable point if it is accessible. Newer bus protocols (OSDP, for example) allow encrypted communication.
Fingerprint
Nothing gets lost and it can't be "lent" to a colleague. The drawbacks are practical: dry, wet, injured or heavily worn fingers (in people who do manual work) cause frequent rejections, the reader has to be kept clean, and unlike a password, a fingerprint can't be changed if the data about it leaks. That is why it matters how it is stored (see the personal data section).
Face recognition
It works contactlessly and is convenient with a flow of people or when hands are full. Quality depends on lighting, angle, distance, glasses and hats. There is a difference between simple cameras, which can be fooled with a photograph, and devices with a depth sensor or infrared light that check whether a live person is in front of them. The face is also a particularly sensitive kind of data, so for employees it needs serious justification.
Mobile access
The phone replaces the card via Bluetooth or NFC. Permissions are added and removed remotely, which is convenient for guests and for buildings with many tenants. The risks come from the phone: a drained battery, a change of device, different operating system versions, and people's reluctance to use their personal phone for work. It is sensible to have a fallback option.
Comparison
| Credential | Advantages | Disadvantages | Suited for |
| PIN code | Cheap, nothing to carry | Easily shared and watched | Second factor, secondary rooms |
| 125 kHz card | Cheap, widespread | Easy to copy | Existing systems with low requirements |
| 13.56 MHz smart card | Better protection, flexible | Can be lost; depends on the type | Most offices and buildings |
| Fingerprint | Tied to the person | Rejections with worn fingers; personal data | A small number of users in higher-risk zones |
| Face recognition | Contactless, fast | Depends on light; sensitive data | Entrances with a flow of people, where justified |
| Mobile access | Remote permissions | Depends on the phone and battery | Buildings with many tenants and guests |
In practice the best result is often a combination: a card or phone for common entrances, a card plus PIN or biometrics for the most sensitive rooms.
Doors and emergency exits
A locked door can be a problem for people who need to leave the building quickly. That is why, at the design stage, it is determined for every door how one exits through it. The general principle is that the evacuation route must stay clear and must open without a credential and without special knowledge.
- Electromagnetic locks are wired so that they release on a signal from the fire alarm system and from an emergency button next to the door.
- An electric exit button on its own is not always enough; mechanical or emergency release is often added.
- Automatic locking must not block exit when power fails, unless another safe solution has been provided.
- "Temporary" fixes such as propped-open doors or taped latches are not a way to deal with the inconvenience.
Important — fire safety requirements depend on the type of building, the number of people and the regulations in force. Agree the door layout with a fire safety specialist or the designer before choosing locks. This article gives general guidance and does not replace the design.
Schedules, roles and the event log
Hardware is only half of it. The benefit comes from the rules you set in the software:
- Roles and groups. Instead of configuring each person separately, you create groups (management, accounting, warehouse, cleaning) and give them access to specific doors.
- Time schedules. The cleaning crew comes in the evening, while the courier only during working hours. Schedules can also include holidays.
- Temporary access. Cards for guests or outside contractors that are valid for a day or a week and expire by themselves.
- Zones. Several doors are grouped into a zone; some systems also track the order of passage (anti-passback) so that one card isn't used by two people.
- Log. Every unlock, denial, door left open and settings change is recorded with a time and a user. After an incident, it is the first place to look for answers.
The common problem is rarely the technology, but the maintenance of permissions: a departed employee with a card that is still active, or a "temporary" card handed out a year ago. Define who adds and removes people, and make it part of the onboarding and offboarding process.
Integrations: turnstiles, barriers, video and time tracking
Access control rarely works alone. It is most often connected with:
- Turnstiles and airlocks — when only one person should pass per card. They are justified where there is a significant flow of people; for a small office they are unnecessary. A passage for people with reduced mobility and for emergencies is always provided.
- Parking barriers — a card, remote or phone opens the barrier, and the log shows who entered and when. Sensors are needed to prevent the barrier from lowering onto a vehicle.
- Video surveillance — on a door event, for example "access denied" or "door forced open", the system can link the recording to the log entry.
- Time and attendance — entrance data can support attendance reports, but passing through a door is not the same as time worked, so it is used carefully and in line with internal rules.
Personal data and biometrics — general considerations
The system collects data about people: who passed where and when. This is personal data, and the general rules for protecting it (GDPR) apply. A few things are worth keeping in mind before purchase:
- Necessity and proportionality. Ask yourself whether the goal can be achieved with a less intrusive means. For the entrance of an ordinary office, a card is usually enough.
- Biometric data is particularly sensitive. If you use it for employees, you need a clear basis, informing the people and, where appropriate, an alternative for those who don't wish to use it. Consult a lawyer or the data protection officer.
- How it is stored. Many devices keep a mathematical template rather than a picture. Ask where the template lives (in the device, on a server, in the cloud) and who has access to it.
- Log retention period. Decide how long records are kept and who may view them.
- Informing people. People should know that the system exists, what it records and for what purpose.
Scenarios from practice
- Small office. One or two doors, up to about ten people. A standalone controller or a small networked system with smart cards or mobile access, an exit button and a suitable lock is usually enough. Biometrics rarely justify the added complexity. What matters most is having someone to manage the cards.
- Shared building. The main entrance and the floors are zones with different permissions. You need groups per company, temporary access for guests and a clear log, with each tenant managing their own people or the administrator doing it quickly. Shared PIN codes are not a good idea — nobody knows who is using them.
- Warehouse. Dust and worn hands make fingerprints unreliable; cards or tags that withstand impact and moisture are more practical. Separate zones are set up for different goods, and the doors to the loading docks are linked with video. In large rooms, take care with emergency exits.
- Parking. A barrier with a reader or remote. The reader should be at a height convenient for the driver and protected from the weather. The log shows who entered, and video ties events to the vehicle.
Common mistakes and a checklist
Mistakes that keep recurring
- Choosing the reader before deciding how the lock should behave.
- A controller installed outside the secured area.
- Locks without sufficient or backup power.
- A maglock with no connection to the fire alarm.
- Old fixed-number cards for a site with higher requirements.
- No process for removing permissions when people leave.
- Biometrics without a clear basis and without informing people.
- A log that nobody reviews until the first incident.
Checklist before ordering
- For every door, describe who passes, at what hours, how people exit and what happens when power is lost.
- Define the security level of the zones and the suitable credential for each.
- Check that the door (frame, leaf, door closer) is suitable for the chosen lock.
- Clarify the power supply, the backup power and the cable routes.
- Ask whether the controller works on its own if the network goes down.
- Decide who administers users and the log retention period.
- Consider integrations — video, alarm, turnstiles — now, even if you switch them on later.
- Agree the emergency exits with a specialist.
Frequently asked questions
Which is more secure — a card or a fingerprint?
It depends on what you are worried about. A fingerprint can't be lent, but it brings personal data questions and frequent rejections. A modern smart card is secure and convenient, and for the most sensitive rooms the two factors are often combined.
Can an access card be copied?
Some types, yes. Old fixed-number 125 kHz cards are copied easily. Modern smart cards with cryptographic protection are much harder to copy, so with a new system ask what encryption the card uses.
What happens to the doors if the power goes out?
It depends on the lock: it unlocks (fail-safe) or stays locked (fail-secure). In every case there must be a safe way out, and where needed, backup power that keeps the system running for a while.
Do I have to have a server?
No. Small systems work with a controller that keeps the rules on its own and are managed from an app or a computer. A server or cloud is needed with many doors, several sites or central management of users.
Can I add doors later?
Usually yes, if the system is networked and the controllers are expandable. That is why, at the first installation, think about the overall architecture and the cable routes, not just the first door.