What Is an Access Control System?

Also called: Electronic access control system, Door access control system, Physical access control system (PACS)

Related problems: Too many keys out there and no idea who still has one; Can't see who opened a door or when; Departing employees' badges still working at some sites; Old badge server in a closet that nobody knows how to manage

An access control system is the electronic system that decides who can open which doors, gates or turnstiles, at what times, and records each attempt. It is made of card or badge readers, door controllers, electric locks and management software, and it replaces most physical keys in offices, warehouses, clinics and data rooms. This is physical access control; network access control (NAC) and role-based access to applications are related ideas from IT security that govern networks and software, not doors.

At a glance

  • Core parts are readers at the door, controllers that make the unlock decision, electric locks and door sensors, and software where administrators manage people and permissions.
  • Credentials can be cards, fobs, PIN codes, phones or biometrics, depending on the readers installed.
  • In an on-premises system, the management software runs on a server you own; cloud-managed versions move it to a provider’s platform.
  • Fire and building codes govern how locked doors must behave for exit, during alarms and on power loss, and the rules vary by jurisdiction.
  • Controllers and servers are network devices and belong on a protected network segment.

What problem it solves

Keys are hard to control. They get copied, lost and not returned, and changing the locks after someone leaves is expensive enough that it often doesn’t happen. A key also leaves no record of who opened a door or when.

An access control system ties each door to a list of people and schedules. Access for a departing employee can be removed in minutes, a lost badge can be disabled without rekeying, and door events (granted, denied, forced open, held open) are logged. That log is often what auditors, insurers and customers ask for when they want proof that sensitive areas such as server rooms, pharmacies or records rooms are restricted. It is a core layer of a broader physical security program.

How it works

Readers and credentials. A card reader at the door reads a credential: a proximity card, a smart card, a phone carrying mobile credentials, a PIN or, at higher-security doors, a biometric. The reader passes the credential data to a controller.

Controllers and panels. The door controller, sometimes called an access panel, holds a copy of who is allowed through which doors and when. It decides whether to unlock and records the event. One controller may serve one door or several. Because controllers usually store permissions locally, doors commonly keep working if the connection to the server drops, though exact behavior varies by product.

Locks and door hardware. The controller drives an electric strike or electrified lockset, or a magnetic lock (maglock). A door position switch reports whether the door is actually closed, which is how “door forced” and “door held open” alarms work. A request-to-exit device, such as a motion sensor or push bar, tells the system someone is leaving so it doesn’t raise an alarm. Which lock types are allowed on exit routes, and how doors must release during a fire alarm or power failure, is set by fire and building codes that vary by jurisdiction; confirm the design with a licensed installer and the authority having jurisdiction (AHJ).

Software. In an on-premises system, management software runs on a server at a site or in a data center. Administrators add people, assign access levels, set schedules and review events there. Many systems integrate with HR or identity platforms, cameras, visitor management systems and intrusion alarms.

Network and power. Controllers and servers sit on the IP network. Some controllers and readers can be powered with Power over Ethernet (PoE) where the product supports it, though locks often need separate power supplies. As with other connected building devices, network segmentation and basic IoT security practices, such as changing default passwords and patching firmware, reduce the chance that a door system becomes a way into the network.

When it matters for buyers

  • When opening or renovating a space. Door hardware, cabling and power are far cheaper to plan before walls close.
  • When the server or software reaches end of support. Unsupported access software on an old server is a common finding in security reviews.
  • When offboarding is unreliable. If badges are removed site by site by hand, former staff may keep access.
  • When auditors or customers ask about physical access. Logs and access reviews for restricted rooms are a frequent request.
  • When your cards are old. Replacing controllers is a natural time to move off easily copied card formats.

Questions to ask vendors

  • Which readers, credential types and reader protocols does the controller support, and can we reuse existing wiring?
  • What happens at each door when the network, server or building power fails?
  • Does the system integrate with our identity provider or HR system for automatic provisioning and removal?
  • How are firmware and software updates delivered, and for how long will this version be supported?
  • Who is responsible for code compliance at each door, and will the installer coordinate with the local AHJ?
  • How are administrator accounts protected, and is there an audit log of permission changes?
  • What would it take to move to a cloud-managed platform later without replacing door hardware?

How it differs from ACaaS

Access control as a service (ACaaS) uses similar readers, controllers and locks but runs the management software on a provider’s cloud platform for a subscription, with the provider handling updates and hosting. A traditional on-premises access control system runs that software on a server you own and maintain, usually bought upfront with optional support. On-premises can avoid recurring platform fees and keep everything inside your network; ACaaS trades those for multi-site management from a browser and less to maintain. For help comparing options, see our door access controls overview.

Frequently Asked Questions

Is an access control system the same as network access control?
No. An access control system controls physical doors and gates. Network access control (NAC) and role-based access control (RBAC) govern which devices and users can reach networks and applications. Many organizations link the two through their identity systems, but they are different products.
What happens to the doors if the power goes out?
It depends on the lock type and the design. Fail-safe locks unlock when power is lost; fail-secure locks stay locked from the outside while usually still allowing exit. Controllers often have battery backup. Which behavior is required on which door depends on fire and building codes, so confirm with a licensed installer and the authority having jurisdiction.
Can we keep our existing readers and cards when we replace the system?
Sometimes. Many controllers accept common reader interfaces, so readers and wiring can often be reused. Whether you should keep old cards is a separate question: legacy 125 kHz proximity cards are widely reported to be easy to copy, so a replacement project is a natural time to plan a credential upgrade.
How is an on-premises access control system priced?
Typically as an upfront purchase of software licenses, controllers, readers, locks and installation, often with optional annual software support. Cloud-managed systems usually shift the software into a subscription per door or controller. Installation and door hardware are frequently the largest share of either.
Should access control be on the same network as our computers?
It is generally better not to mix them. Controllers, readers and the management server are network devices that are often patched less frequently than laptops, so many organizations put them on a separate network segment or VLAN with tightly limited access.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.