By the DC Fire & Security engineering team — installing and maintaining fire and security systems since 2010. Updated July 2026.
Access control replaces keys with credentials — a fob, card, PIN, phone or fingerprint — checked at the door by a reader and controller that decide, in real time, whether that person may pass through that door at that moment. The step up from keys isn't convenience, it's control: lost fobs are deleted rather than locks changed, every opening is logged, and permissions follow rules — which is what role-based access control (RBAC) means: people get access by role (staff, manager, cleaner, visitor), not by individual favours that nobody remembers granting.
Every electronic access system is the same four parts: a credential (what you carry or know), a reader at the door, a controller (the brain that checks the credential against its rules), and door hardware — an electric strike or magnetic lock that physically holds the door, plus an exit device (push-to-exit button, handle or motion sensor) on the safe side.
Standalone systems put the brain in the door unit itself — right for a single door, a shared entrance, a plant room. Networked systems put every door on one management platform: one place to add a starter, delete a leaver, pull an audit trail, or lock the whole building down. The crossover point comes fast — around three or four doors, managing standalone units door-by-door becomes the expensive option.
| Credential | Strengths | Watch out for |
|---|---|---|
| Fob / card (proximity) | Cheap, instant to issue and revoke, the default for good reason | Legacy 125kHz cards are clonable at market stalls — modern encrypted (MIFARE DESFire class) credentials close that door |
| PIN keypad | Nothing to carry or lose | Codes get shared and stale — fine for low-risk doors, weak as the only factor; combine with a fob for sensitive rooms |
| Mobile (phone as credential) | Nobody forgets their phone; remote issue for contractors and viewings | Tied to platform and app quality — judge the vendor, not the brochure |
| Biometric (fingerprint/face) | The credential can't be lent or lost | Cost per door, throughput at busy entrances, and biometric data brings real GDPR duties — justify it per door, not per building |
RBAC is the grown-up way to run permissions: you define roles — Staff, Manager, Cleaner, Contractor, Visitor — decide what each role may open and when, and then assign people to roles. The office manager doesn't grant Dave the warehouse door; she makes Dave *Warehouse Staff*, and the role does the rest. When Dave leaves, one deletion revokes everything.
The alternative — per-person permissions granted ad hoc — is how buildings end up with a fob population nobody can explain and leavers who can still open the stock room. In practice a small business needs three to five roles; more than that usually means the roles are being invented per person, which is the old problem wearing a new name.
Time schedules bolt onto roles naturally: Cleaners' fobs work 06:00–09:00 weekdays, Contractors' expire Friday, the office unlocks itself for business hours and locks for everything else. The audit trail then answers the questions that matter after an incident: who entered, where, when — data worth having and data with UK GDPR duties attached (retention limits, a stated purpose, staff told about monitoring).
People must always get out. Whatever the lock, escape must be possible without a credential — push bars, exit buttons, handles that override the lock. And the choice between fail-safe locks (release when power dies — maglocks) and fail-secure (stay locked — most strikes) is made door-by-door: escape routes fail safe; a server room's strike can fail secure because its escape side still opens mechanically.
The fire alarm wins every argument. Doors on escape routes must release on fire alarm activation — a hard-wired interface, not a software preference. It's the first thing we test at commissioning and the thing we most often find missing on systems installed by generalists. If your access control has never been tested against your fire alarm, that test is overdue — it's also a standard part of a fire risk assessment done properly.
Think per door: a single standalone door lands in the mid-hundreds installed; networked doors with encrypted credentials and proper door furniture run higher per door but amortise the head-end across the estate. The full per-door cost guide breaks the numbers down, and door entry for flats — a cousin of access control with its own economics — has its own guide.
One buying rule from the vans: ask any bidder two questions — *what happens on fire alarm?* and *what happens when your company disappears?* The first answer must be 'doors release, hard-wired'. The second must not be 'the system dies with us' — open, takeover-able platforms exist and are what we fit.
We design and install access control across Luton, Bedfordshire, Hertfordshire and North London — single doors to multi-site systems, SSAIB certificated, integrated properly with your fire alarm so doors release when they must. Free survey, per-door pricing, no locked-in platform.
Free site visit · No obligation · Response within 24 hours