Access Control

Who gets in, and what the door does when they do

Two problems that are always sold as one. Credentials, readers and controllers on one side; strikes, maglocks, request-to-exit and egress compliance on the other. Getting the second half wrong is how buildings end up with doors that are illegal.

The two halves

A reader is the cheap half of the problem

Most quotes describe credentials and software in detail and describe the door in one line. The door is where the money and the liability are.

The credential side is what buyers think they are buying: a fob or a card or a phone, a reader on the wall, a controller in a closet, and software that says who may go where and when. That side is real, and the choices in it matter, particularly the credential technology, which most buildings get wrong by inheritance rather than by decision.

The door side is what actually determines whether the system works, and whether it is legal. Every controlled door needs a locking device matched to the lock and the frame it is going into, a way for people to get out that satisfies code regardless of what the electronics are doing, a way for the system to know the door is closed, power sized for the load with real headroom, and battery behind that power. Miss any one of those and you get a door that fails in a way nobody predicted.

Concretely: an electric strike has to mate to the specific lock and frame. Cylindrical locks are the easy case, but the deadlatch finger has to land on the strike face rather than dropping into the pocket, or the door can be shimmed open by hand. Mortise locks are harder because the latchbolt centerline shifts. Aluminum storefront jambs are often only around one and three-quarter inches deep and may not accept a standard strike at all, especially next to a sidelite. Hollow metal frames are frequently grout-filled and need a die grinder. None of that appears on an equipment list, and all of it is labor.

Then there is the moving-door problem. An electrified lever or exit device needs current transferred through a door that opens and closes tens of thousands of times a year, through an electric hinge, a power transfer or a surface door loop. The single most common cause of intermittent door faults on a retrofit is a door-loop conductor that has work-hardened and fractured. That fault reads as a software problem for weeks before somebody flexes the loop by hand and watches the door drop.

Credentials

What is actually in your residents’ pockets

This is the single most under-discussed decision in the trade, and the one with the widest gap between what buildings believe they have and what they have.

CredentialSecurity in practiceWhere it belongs
125 kHz proximityTransmits a fixed facility code and card number in the clear, with no encryption. A handheld duplicator costs under $30 and copies a card in roughly fifteen seconds; long-range harvesters that read through a wallet fit in a backpack, and consumer kiosks in supermarkets now duplicate these cardsNowhere new. If your building runs prox, it should be on a migration plan, not a re-order
MIFARE Classic (13.56 MHz)Higher frequency, but its cipher was broken years ago and key recovery is a well-documented attack. Being 13.56 MHz is not a security claim by itselfNot a security upgrade. Buildings move to this thinking they have solved prox and have not
MIFARE DESFire EV3AES-128 with mutual authentication, and the only mainstream card credential carrying Common Criteria EAL5+ certificationThe default recommendation for new card and fob deployments
iCLASS SE / SeosAES-128 with mutual authentication. Note that original iCLASS, a different and much older product, had its proprietary cryptography publicly broken. The names are similar and the security is notStrong, widely supported, common where a building is already on that ecosystem
Mobile (Bluetooth)Longer range, hands-free and wave-to-unlock behavior. Convenience is genuinely better; range is also the attack surfaceStaff doors, garages, anywhere the user has hands full
Mobile (NFC / wallet)Short range, generally considered the more secure of the two for badge emulation. Wallet-based credentials need explicit reader support, which not every reader hasOffices and mixed-use where phone-only entry is realistic for the whole population
PIN codesNo hardware to lose and no hardware to issue. Also shared, written down, and never changed after a staff departure unless somebody makes a policy of itBack-of-house doors, contractors, and as a second factor rather than a first

The migration path we normally recommend is multi-technology readers that accept both the legacy credential and the encrypted one, running both through a full re-badging cycle, then disabling the 125 kHz side. It avoids a single changeover day, which in a residential building is the difference between a project and an incident.

Egress

Fail-safe or fail-secure is not a preference. On some doors it is decided for you.

Fail-safe means power off equals unlocked. Fail-secure means power off equals locked. Both describe the entry side only. The egress side must always allow free mechanical exit by lever or push bar regardless of power state. That is not a design goal, it is the baseline every other decision sits on.

Fire-rated door assemblies must be fail-secure and listed for that use, because a rated door has to stay positively latched to contain smoke and fire. A fail-safe device on that door unlatches on power loss and destroys the rating. Magnetic locks are the mirror image: they hold only while energized, so they are inherently fail-safe, they provide no latching at all, and they are never a substitute for a latch on a rated door.

Where a magnetic lock is permitted on an egress door, New York City Building Code §1010.1.9.8 governs sensor release. That arrangement requires an overhead sensor on the egress side that unlocks on approach, unlocking on loss of power to the sensor and on loss of power to the lock, unlocking on fire alarm or sprinkler activation and staying unlocked until the system is reset, and a manual button mounted 40 to 48 inches above the floor within five feet of the door, labeled to push to exit, that cuts lock power directly and independently of every other electronic path and holds the door unlocked for at least thirty seconds. Delayed egress arrangements are covered separately under §1010.1.9.7. And under NYC Fire Code §1027.3.1, egress hardware must be maintained in working order at all times, which is a maintenance obligation, not an installation one.

The detail that catches integrators is the fire alarm interface. A good access power supply drops selected outputs on a fire alarm signal, and the selection is per output on purpose: the maglocks on the stair doors must drop, the fail-secure strikes on the rated doors must not. Wiring that as a single global disconnect is either a code violation or an open building, depending on which way it went.

An open access control panel enclosure in a dark utility room showing a controller board, neatly landed multi-conductor cable and a standby battery below
Access control services

Five pages under this category

The specifics differ enough that each of these is written separately.

The parts nobody sells

Where the failures actually come from

Reader, credential and software get all the attention. Every service call we take is about something on this list.

  • Wiegand is one-way, unencrypted and unsupervised. Its two data conductors carry card numbers in plaintext, a device wired behind the reader can capture and replay every credential, and the panel has no way to know it is there. Practical limit is around 500 feet with a home run per reader.
  • OSDP is the answer, and half of it gets skipped. Two data conductors on a twisted pair, roughly 4,000 feet, multiple readers daisy-chained on one cable with addressing, AES-128 secure channel, and real supervision so the panel knows if a reader goes offline or is swapped. The step almost nobody performs is moving devices off the default install key onto a unique secure channel key. Without that, the encryption is decorative.
  • No door position switch means no security. Without a contact reporting open or closed, you cannot generate a forced-open or held-open alarm, you cannot verify the latch re-seated, and you cannot correlate a single card read against two people walking through. The classic finding on a survey is a building that “has access control” and does not know its service door has been propped for months.
  • Request-to-exit comes in three flavors that are not interchangeable. An overhead motion sensor shunts the forced-door alarm and, on sensor-release maglock doors, performs the unlock. A switch inside the lever or panic bar cuts lock power at the hardware. A push-to-exit button is the code-mandated independent release. Substituting one for another changes what the door does in an emergency.
  • Doors that drop offline at night are usually a battery. Access power supplies disconnect their DC outputs when the standby battery falls below roughly 70 to 75 percent of nominal. A weak battery string produces doors that fail in the small hours and work fine when the technician arrives at ten in the morning.
  • Size the supply for inrush plus 25 percent, then size the battery for the real load. Four strikes at a quarter amp each is one amp, so specify at least 1.25. And remember that magnetic locks draw continuously because they are energized while locked, which means a maglock building needs a dramatically larger battery than a fail-secure strike building where the coil only pulses on unlock.
  • Specify continuous-duty strikes wherever a door is held unlocked on a schedule. Intermittent-duty units burn out. Cheap strikes are commonly rated for something like ten cycles a day and fail quickly on a busy lobby door.
Cloud or on-premises

The subscription question, answered honestly

Cloud platforms are genuinely better at the things multifamily buildings do every week. A tenant moves out and their credential is revoked from a browser in seconds instead of a truck roll. A managing agent sees a whole portfolio in one view. Audit logs survive a panel failure. If your operational pain is administration, the recurring cost buys something real.

What it costs is worth stating plainly. Published list pricing in this market runs roughly $13 per door per month at one or two doors, falling to around $3.50 per door above eleven, and multifamily platforms often bill per apartment instead, commonly $4.50 to $6.75 per unit per month. Installation labor for a new door is frequently quoted around $1,500 to $2,000. Those are vendor and market figures, not our quote; your numbers come from the survey. What matters is that the subscription never ends and can be repriced at the vendor’s discretion.

The dependency question is the one to force into writing before signing. What happens during an internet outage, a Wi-Fi outage, a cellular outage and a power outage? Reputable systems cache the access list at the controller and keep enforcing the last known permissions offline, but new credentials, revocations and remote unlock stop working. Ask for the documented offline behavior and its duration, and ask what the fallback path is: a mechanical override, a key box, or a hardwired secondary release.

On-premises has the opposite profile: one-time capital cost, full data control, no dependence on a vendor’s continued existence, and, with open-architecture controllers, the ability to change head-end software later without replacing the hardware in the closet. The cost is that somebody has to own a server, patches, backups and remote access. For a building with a superintendent and an IT contractor that is fine. For a 24-unit co-op with a volunteer board it usually is not.

One New York specific belongs in the decision either way: buildings using keyless entry are subject to city rules on resident access data covering written consent, a published policy, limits on what is collected and retained, and a ban on selling it. That obligation lands on the building, not on the vendor.

FAQ

Common questions

Our building uses fobs already. Why would we change anything?

Because of what is inside them. If the fobs are 125 kHz proximity, which describes most fobs handed out in this region over the last two decades, they broadcast a fixed number in the clear with no encryption. A duplicator costing under $30 clones one in about fifteen seconds, and consumer kiosks in supermarkets now do it for people who do not own a duplicator.

That does not mean an emergency rip-out. The sane path is multi-technology readers that accept both the old credential and an encrypted one, a re-badging cycle at a natural point like a lease year, and then disabling the legacy side. The readers are the capital cost; the credentials are consumables you were replacing anyway.

Can we put a magnetic lock on the front door?

Sometimes, and it depends on the door and the occupancy rather than on preference. A magnetic lock provides no latching and holds only while powered, so it is never permitted on a fire-rated assembly, and where it is permitted on an egress door it brings a specific set of release requirements with it.

Those requirements include an overhead sensor releasing on approach, release on loss of power to either the sensor or the lock, release on fire alarm or sprinkler activation held until the system resets, and an independent push-to-exit button mounted 40 to 48 inches above the floor within five feet of the door that cuts lock power directly. In a lot of buildings an electrified latch or a properly specified strike is both cheaper and simpler than satisfying all of that, which is why we ask what problem the maglock is meant to solve before agreeing to one.

What does access control cost per door?

The honest answer is that the hardware is the small and predictable part and the door is the variable. A reader, a controller share and a credential batch land in a fairly tight band. What moves the number by thousands is the door itself: whether the frame accepts a strike, whether the lock is cylindrical or mortise, whether current has to be transferred through a moving leaf, how far the cable has to travel, and whether the door is on a rated assembly.

So we survey each door and price each door. Typical installed costs per door in this market span a wide range depending on all of the above, and we would rather show you three doors at three different numbers with the reason for each than average them into one figure that is wrong for every door on the schedule.

Can access control and the intercom be one system?

Usually, and it is often the right call. Modern entry panels commonly include a reader module or a keypad, so the lobby door gets one device instead of two and one hole in the wall instead of two. Where the intercom is a cloud platform, the same portal frequently manages both the directory and the credentials.

The trade-off is coupling. If the two are one system, a vendor decision about one is a decision about both, and a migration later is a bigger project. In buildings where the entry system and the interior doors have different lifespans (a lobby panel that will last fifteen years and office doors that get reconfigured every lease), keeping them separate but integrated is often better. We will lay both out rather than defaulting.

Who owns the system and the administrator accounts when the job is done?

You do. Cloud platforms get registered to your organization with your email as the account owner, and the credentials are handed over at completion along with as-built documentation and the cable labeling map.

This is worth insisting on with anyone you hire. Buildings regularly discover that their own access system is registered to a contractor they no longer use, and that removing a former tenant’s fob requires a service call to that contractor. That is not a technical limitation of any platform. It is a commercial arrangement, and a building that cannot administer its own access list does not really control its own front door.

Do you connect to our fire alarm panel?

No, and that is deliberate. Terminating on a fire alarm control panel, programming it or taking it out of service is fire alarm work, which is a separately licensed activity in New York City, and it stays that way even when the connection is a single dry contact for lock release.

The compliant arrangement is that we provide and land a relay in an enclosure adjacent to the panel, and the building’s fire alarm contractor makes the final connection and performs the acceptance test. That interface also needs functional testing on a regular cycle: the alarm is activated and each electrified lock in the egress path is physically verified to release. That testing is part of the fire alarm contractor’s scope, not ours.

Send us the door schedule, or just a photo of the door.

Most access control quotes go wrong at the door, not at the reader. A photograph of the frame, the lock and the closer tells us more than a model number does.

Sun to Thu 9am to 5pm · Fri 9am to 12pm · Sat closed

Call Get a quote