A door credential used to mean one thing: a card in a badge holder, read by a proximity reader wired back to a panel in a closet somewhere. That model still works fine. But the technology behind that door has changed more than most facilities directors realize, and current platforms handle credentialing, multi-site management, and audit reporting in ways older proximity-only systems were never built to do. Here’s how the landscape breaks down, and what matters when evaluating a system for one building or a group of them across several states.
Proximity Cards and Smart Cards: What Most Buildings Still Run
Most commercial buildings run some version of card-based access, and two very different technologies hide under that one label. Low-frequency proximity cards — the 125 kHz “prox” format standard since the 1990s — communicate with the reader in the clear, with no encryption. That’s not a theoretical weakness: card-cloning devices that copy a standard prox credential in seconds are inexpensive and easy to find online. Plenty of buildings still run this format simply because nobody’s had a reason to change it.
Smart cards operating at 13.56 MHz — HID iCLASS Seos, MIFARE DESFire, and similar formats — encrypt that communication, closing the cloning gap and supporting multi-application use, where the same card opens doors, releases a print job, and loads value onto a vending account. Moving from prox to smart cards doesn’t have to be a rip-and-replace project: multi-technology readers that accept both formats let an organization reissue credentials in smart-card format as employees turn over, retiring the old cards gradually instead of re-badging an entire building in one weekend.
Mobile Credentials: The Phone as the Badge
Mobile access uses a smartphone, held near or within range of a reader, in place of a physical card. It works one of two ways: Bluetooth Low Energy (BLE), which reads at longer range and doesn’t require pulling the phone out of a pocket, or NFC, which mimics a contactless payment — a deliberate tap at short range. Credentials get provisioned through a dedicated access app or, on newer platforms, loaded directly into Apple Wallet or Google Wallet the same way a boarding pass would be.
The real advantage isn’t convenience for the end user — it’s issuance and revocation. A new hire’s credential can reach their phone before their first day, and a departing employee’s access can be pulled the moment HR flags it, without waiting on a badge to be returned. That matters more as an organization adds locations, since there’s no card to hand over in person. Two things worth planning around: mobile credentials generally need reader hardware that supports BLE or NFC, so older panels usually need a reader upgrade rather than a software update, and any BYOD environment needs a policy for a lost, sold, or factory-reset phone.
Where Biometrics Actually Make Sense
Fingerprint and facial recognition readers get discussed like they’re the obvious next step for every door, but in practice they’re deployed selectively — server rooms, data centers, pharmacy and cash-handling areas — spaces where the extra seconds per entry are worth it. At a building’s main entrance or a high-traffic interior door, biometrics usually create more of a bottleneck than they solve a problem.
The more common pattern is layering: a badge or mobile credential for general building access, with a biometric reader added as a second factor at the specific doors that need it. One point worth flagging for any Illinois-based organization: the state’s Biometric Information Privacy Act (BIPA) imposes real requirements around consent, disclosure, and retention schedules before collecting fingerprint or facial data from employees or visitors. That’s a legal and HR conversation as much as a technical one, and it needs to happen before biometric readers go in, not after.
Cloud-Managed vs. On-Premise Platforms
Every access control system still has hardware at the door — a controller, a reader, wiring back to a panel. What differs is where the management software and credential database live. On-premise systems run on a server or local VM the customer’s own IT team maintains: patching, backups, and hardware refresh are local responsibilities, but so is full control over the data. Cloud-managed platforms host that database off-site, with the local controller checking in over the network, so administrators manage doors, users, and schedules from a browser instead of a desktop client tied to one building.
The cloud model is easier to operate across multiple locations — an organization with sites spread across Illinois, Wisconsin, and Indiana works from a single console instead of connecting into each site’s local server separately. It’s usually a subscription rather than a capital purchase, with automatic updates. A well-designed system, cloud or on-prem, still caches credentials locally on the controller so doors keep working on schedule if the internet drops — worth confirming during evaluation. A few factors tend to decide which model fits better:
- How many sites need managing, and whether a single console is worth it
- Whether internal IT has the bandwidth to maintain a server long-term
- A preference for predictable subscription costs over upfront capital spend
- How the system behaves during an internet or power outage
Visitor Management Belongs in the Same Conversation
Visitor management often gets bought as an afterthought, but it’s really an extension of the same access control question: who is in the building, and can that be verified after the fact. A kiosk or tablet at the front desk that scans an ID, captures a photo, and prints a time-limited badge is the baseline. Pre-registration builds on that: a host invites a visitor ahead of time, the visitor gets a QR code by email, and check-in takes seconds instead of a call to reception.
For schools and healthcare facilities especially, visitor systems increasingly run watchlist or background screening at check-in, far beyond what a paper sign-in sheet ever offered. And in an emergency, an accurate, real-time visitor log is what lets a front office give first responders a real headcount of who’s in the building — which is also where access control and emergency notification systems end up connected in a building’s overall life-safety plan.
Managing Credentials as an Organization Grows
The technology at the door is the easier half of this. The harder half is the administrative discipline behind it, especially for an organization adding locations or growing headcount, where access control tends to sprawl unless someone manages it deliberately. A few things separate a system that stays clean from one that turns into years of orphaned credentials and undocumented door groups:
- A documented process tying credential issuance and revocation to HR onboarding and offboarding, not a step someone has to remember
- Access levels built around roles or departments rather than assigned door-by-door per person
- Consistent naming conventions and access groups applied the same way at every site
- Audit logs reviewed on a schedule, not just pulled up after something’s already gone wrong
- One clearly assigned owner who can add, remove, and modify access, rather than that responsibility being split across several people
Directory integration helps too — syncing the access platform against Active Directory or Azure AD means a person’s status in the access system follows their status as an employee, instead of living as a separate list maintained by hand.
Access control has quietly become a network application as much as a physical security one. The readers, panels, and credential databases run across the same switches and cabling as everything else in a building, and a system planned without accounting for that creates problems for IT later, not just for security. Whether the project is a single building standardizing on mobile credentials or a multi-site organization getting consistent access levels across several states, the question is the same: does adding someone, removing someone, or pulling a report take longer than it should.
That’s the same network-first approach Cyber IT Tech brings to access control projects across the Chicago area and the greater Midwest — starting with the door hardware and credential technology that fits how a building actually operates, then building the network and credential-management structure underneath it so the system stays manageable as a client adds doors, sites, and people. Our team carries Cisco, Fortinet, and Microsoft certifications alongside our physical security credentials, because a modern access control platform is a network application first and a door lock second, and it holds up best engineered like one from the start.