The phone as the credential, the access list in a browser, the bill every month forever.
Cloud access control genuinely solves the worst part of running a building’s doors. It also introduces a cost that never stops and a dependency most quotes never mention. Here are both, with numbers.
“Cloud” describes where the administration lives, not where the door is
The panel is still bolted to a wall in your basement. What moved is the database, the software and the invoice.
A cloud access system has the same physical anatomy as any other: a reader at the door, cable back to a controller, a power supply, a battery, locking hardware, request-to-exit and a door position switch. What is different is that the controller talks outbound to a hosted platform instead of to a server in your building, and you administer it from a browser or a phone.
For a managing agent that is a genuine change, not marketing. Adding a resident, revoking a departed one, changing the hours a contractor can use the service door, pulling the door history for the night a package went missing. All of it stops being a truck roll and becomes a two-minute task from a desk in another borough. On a portfolio of a dozen buildings that difference is the entire business case, and it is why we install these systems.
What you are also buying is a recurring bill with no end date, hardware that may only work with one vendor’s platform, and a dependency on somebody else’s uptime and somebody else’s pricing decisions. Nobody in this trade likes writing that paragraph. It belongs in the quote anyway.
Phone credentials: BLE, NFC and wallet badges are not the same thing
| Method | How it behaves at the door | What it needs |
|---|---|---|
| Bluetooth Low Energy (BLE) | Long range. Supports wave-to-unlock and hands-free unlock as you approach, which is the feature residents actually notice. | Works on iPhone and Android. Longer range is a convenience and a small attack surface at the same time. It is why we set range deliberately rather than at maximum. |
| NFC via a phone app | Tap to unlock, a few centimeters. Behaves like a card. | Native on Android. On iPhone, app-based NFC for door credentials is not generally available. The iPhone path is a wallet badge. |
| Apple Wallet employee or resident badge | Tap the phone or watch, works with the phone locked, and keeps working on reserve power after the battery dies. | The reader must explicitly support Apple’s value-added services and enhanced contactless polling. Not every reader does, and adding it later means changing readers. |
| Google Wallet badge | Same behavior on Android. | Requires reader support for Google’s smart-tap protocol. |
| Card or fob alongside the phone | The fallback that stops the 2 a.m. phone call. | A multi-technology reader that handles both. We specify this on residential work as a matter of course. |
The practical instruction: if there is any chance you will want wallet badges later, buy mobile-ready readers now. Reader replacement across a building is a five-figure decision; specifying the right reader at the outset costs a little more per door and nothing in labor.
The five-year arithmetic, using published list pricing
These are the numbers as published by the platforms at the time of writing. They change, and they are the reason we do this calculation before you sign anything.
| Scenario | Where the money goes | Five-year subscription |
|---|---|---|
| 12-door commercial building on a per-door cloud plan | Published tiering on one major platform runs $13.50 per door per month for the first two doors, $7.50 for doors three to ten, and $3.50 from door eleven, about $94 a month for twelve doors. | Roughly $5,600 in software alone, on top of hardware and installation |
| The same building’s capital cost | Cloud controller hardware is published around $1,100 to $1,600 per two-door module, and installation wiring for a new door commonly runs $1,500 to $2,000. | $25,000 to $34,000 before a single subscription month |
| 200-unit residential building on per-unit multifamily pricing | Multifamily plans are priced per apartment, not per door, and are published at roughly $4.50 to $6.75 per unit per month. That is $900 to $1,350 every month regardless of how many doors you control. | $54,000 to $81,000 |
| Mobile credential passes | Published at roughly $0.35 to $0.75 per credential on some platforms; other vendors sell blocks (for example around $199 for up to twenty mobile users). | Small per user, material at 200 units |
| Alternative vendor models | One major hardware vendor publishes a four-door controller around $1,799 with a $249 annual license; another prices software at roughly $5 to $20 per reader per month and quotes $2,500 to $5,000 per door all-in. | Compare like for like, per door and per unit |
Published vendor list pricing, not our quote, and it moves. The point of putting it here is the shape of the curve, not the decimal: per-door cloud pricing gets cheaper per door as you add doors, and per-unit multifamily pricing does the opposite. It scales with the size of the building whether you control three doors or thirty. For a large co-op that single distinction is worth more than any hardware comparison.
What happens when the internet drops
This is the question we are asked least and should be asked first. The honest answer for a well-built system: the controller caches the access list locally and keeps enforcing the last known version, so residents and staff continue to get in and out. Reputable platforms are explicit that devices continue operating during a connectivity loss.
What stops working is everything that needs the platform: adding a credential, revoking a credential, remote unlock, live event monitoring, and in most cases the mobile app path for phone credentials. If a resident moved out this morning and the line went down this afternoon, that revocation may not have reached the panel. And a resident whose only credential is their phone may find themselves at a door that will not open, which is the second reason we specify a card or fob fallback on residential buildings, the first being the resident whose battery is flat.
Put these to any vendor in writing before you sign, and hold the answers: What happens during an ISP outage? A Wi-Fi outage? A cellular outage? A power outage? Are cached credentials still honored, and for how long? Can residents still be buzzed in? What is the documented mechanical override, and who holds it? If the answers are not in the proposal, they are not commitments.

Whose account is it, and what happens the day you fire your integrator
On cloud platforms the system exists as an account, and the account has an owner. We have walked into buildings where that owner was a contractor the board had stopped using two years earlier, which meant removing a former tenant’s credential required a phone call, a service ticket and a fee. That is not a technical limitation. It is a business model.
Our rule is simple and it is written into every handover: the tenant of the account is your building or your company, the owner email is yours, and we hold an installer role you can remove in one click. You get the credentials at handover along with the as-builts and the labeling map. If you want to move to another integrator, nothing about that requires our cooperation.
The harder version of the same question is hardware. Open controller platforms, the boards that sit underneath a large share of branded systems, can be moved between head-end software packages without replacing panels, so a change of platform is a software project rather than a demolition. Closed platforms bind the panel, the readers, the credentials and the account together on purpose. Both are legitimate products and the closed ones are often very good. But you should be told which one you are buying, and what leaving it would cost, on the day you buy it rather than the day you want to leave.
Seven things we settle before specifying a cloud platform
- Per door or per unit. On a 200-unit building the pricing axis matters more than the hardware. Ask for both quotes and do the five-year multiplication yourself. Nobody does it for you.
- Reader capability, decided once. Multi-technology, mobile-ready readers that handle encrypted cards, phones and wallet badges cost modestly more per door than a basic reader and save a building-wide reader swap later.
- A physical fallback credential for every resident. Phone-only access fails for flat batteries, replaced handsets, visiting family, and anyone who does not want an app. It is also an accessibility question, not a preference.
- Network path and what backs it up. A UPS in the network closet and battery at the door station are cheap; discovering during a storm that the controller and the router share an unprotected outlet is not.
- Where the cellular or Wi-Fi signal actually is. Verified at the door, not assumed from the leasing office. Below-grade garages and back-of-house service corridors are exactly where signal dies and exactly where the doors are.
- Data: what is collected, where it lives, how long it is kept. A door log is a record of when identified people came and went. Set a retention period deliberately and write it down, and if you are considering biometric readers in a retail, entertainment or food-and-drink space, note that NYC Admin Code §22-1201 imposes signage duties on those establishments.
- An exit plan in writing. What happens to the panels, the readers and the credential data if you leave the platform. Ask before signing; the answer is a fact about the product and it is much harder to obtain later.
Common questions
Is cloud actually cheaper than an on-premise system?
Below roughly eight to ten doors it usually is, because the alternative carries a server, an operating system to patch, backups, a VPN for remote administration and an annual software maintenance agreement, and those costs do not shrink just because the system is small. Cloud also removes the version-lock problem, where a software upgrade orphans panels you bought four years ago.
Above that, and especially on multifamily buildings priced per apartment, the arithmetic inverts and it inverts hard. A 200-unit building at published per-unit rates is looking at $54,000 to $81,000 in subscription across five years, which buys a great deal of on-premise hardware and administration. Vendors publish claims that cloud runs 32 to 47 percent below on-premise over five years; those are vendor figures, they are calculated on mid-size commercial deployments, and they do not describe a large residential building. We do the sum for your building with your door count and your unit count, and we show our working.
Do residents have to use a smartphone?
They should never have to. We specify multi-technology readers so every resident has the option of an encrypted card or fob, and we recommend that boards issue one to every unit regardless of whether the resident also installs the app.
The reasons are practical before they are anything else: flat batteries, replaced or lost handsets, visiting relatives, home aides, and residents who simply do not want a building app on a personal phone. There is also a fair-housing dimension: making a smartphone the sole means of entering your own home is a decision a board should make consciously, in writing, and in our experience they decline once it is put that way.
Will Apple Wallet work with any reader?
No, and this is the most common expensive surprise on mobile projects. Putting a building credential into Apple Wallet requires the reader to support Apple’s value-added services and enhanced contactless polling; Google Wallet requires support for Google’s smart-tap protocol. A reader without them will read your cards perfectly and ignore the phone entirely.
Some current reader lines ship mobile-ready with those protocols plus encrypted card formats and standard NFC. Others do not, and no firmware update adds the capability. This is why reader selection happens at design time even when nobody is asking for wallet credentials yet. The marginal cost now is a few dollars per door, and the cost of finding out later is every reader in the building.
Who can see our door logs?
Your administrators, and the platform operator, because the records live on their infrastructure. That is the trade you are making for browser administration, and it is worth stating plainly rather than discovering in a privacy policy.
What you control is what gets collected and how long it is kept. Set a retention period that matches why you actually need the data (incident investigation, usually measured in weeks or a few months) rather than accepting an indefinite default. Restrict who holds administrator rights and review the list at least annually, because in most buildings the administrator list grows and never shrinks. If you are adding video to the same platform, the retention and privacy questions get larger, and New York has specific rules about camera placement and audio that we cover on the security camera pages.
Can we start with cloud and move to on-premise later, or the other way round?
It depends entirely on whether the controller is an open platform or a proprietary one, and that is a question you can answer before you buy. Open controller boards are used underneath a number of different head-end packages, so changing software can leave the panels, the wiring and often the readers exactly where they are.
Proprietary cloud hardware generally cannot be repointed at anything else. If it is discontinued, or the pricing changes in a way your board will not accept, the replacement scope is the whole system. That is not a reason to refuse those products (several are excellent and the multifamily features are genuinely ahead), but it should be a deliberate decision recorded in the board minutes, not a discovery made in year six.
Can we keep our existing readers and just add the cloud part?
Sometimes. If your readers are a common format and the new controller accepts that reader interface, the readers can stay and only the panel and software change. That is the cheapest path to browser administration and we look for it first.
Two things frequently block it. First, some cloud controllers only support the secure reader protocol with their own readers, so mixing brands quietly drops you back to the older unencrypted reader wiring. Second, if your existing credentials are 125 kHz proximity, keeping the readers means keeping a credential that is copied in about fifteen seconds by a $30 device. You would have bought better administration of an access list that anyone can add themselves to. Where budget forces a phased approach we will do the panel first, but we will say in the scope that the credential problem is still open.
Work that usually comes with this
Access Control Installation
Complete door-control systems, from a single door to a multi-building portfolio.
Key Fob Entry Systems
Fob-based building entry, plus the credential management that keeps it from becoming chaos.
Elevator Access Control
Floor restriction for co-ops, condos and mixed-use buildings.
Video Intercom Systems
See who's at the door: lobby panels with cameras, in-unit monitors and phone apps.
Property Management
Portfolio work: one vendor, consistent hardware, COIs on file, documented every time.
Small Business & Retail
Storefronts, bodegas, salons and offices: cameras, buzz-in entry and back-of-house control.
Ask us for the five-year number, not the monthly one.
Give us your door count and your unit count and we’ll put the per-door and per-unit models side by side, with the hardware and installation added in, before anyone signs a platform agreement.
Sun to Thu 9am to 5pm · Fri 9am to 12pm · Sat closed