Key takeaways
- Start with the property and its daily access flow, not a product list.
- Treat every controlled door, gate, garage, or elevator connection as a complete opening.
- Define who needs access, where, when, and how those permissions will change.
- Inspect existing doors, frames, locks, wiring, power, and controllers before deciding what can be reused.
- Plan egress, fire and life-safety coordination, and accessibility with the applicable design team and authority having jurisdiction.
- Compare proposals by scope, system fit, handoff, and support—not reader count alone.
System anatomy
A controlled opening is more than a reader.
A person presents a card, fob, mobile credential, or code. Behind that simple interaction is a connected chain of physical hardware, electronics, software, and operating rules.
The reader receives the credential information. A controller or connected system evaluates the request against the assigned permissions and schedule. If access is granted, the system commands the locking or release hardware. The door still has to open, close, latch, and return to a secure state.
If one layer is unsuitable, the opening can feel unreliable. A valid credential does not correct a dragging door, a misaligned latch, inadequate power, damaged wiring, or release hardware that does not fit the frame.
| Layer | What it does | Question to answer |
|---|---|---|
| Door and frame | Provide the physical opening and mounting conditions | Does the door close and latch consistently, and can the frame support the proposed hardware? |
| Locking or release hardware | Physically secures and releases the opening | Which supported locking method fits the door, frame, existing hardware, and required behavior? |
| Credential and reader | Receive a credential or identifier and pass the access request | Are the credential, reader, controller, mounting location, and user workflow compatible? Unique credentials are needed for individual attribution. |
| Controller and software | Apply permissions, schedules, and system rules | Who will administer access, and what capacity, licensing, and support are required? |
| Power, wiring, and conduit | Connect and support field devices | Are the routes, supplies, cable types, device loads, and service access practical? |
| Exit and door monitoring | Support the intended egress and door-state behavior | What request-to-exit, door-position, manual-release, or connected-system functions apply? |
| Handoff and support | Keep the system manageable after installation | Who receives administrator access, documentation, training, and a service path? |
Operating model
Define people, places, and time before selecting products.
A useful access-control design begins with a plain-language access policy that the property team can operate.
People
List employees, managers, commercial tenants, residents, leasing staff, maintenance teams, vendors, contractors, deliveries, visitors, temporary users, and after-hours contacts. Each group may need different openings, schedules, and administrative rules.
Places
Inventory main and secondary entries, tenant suites, staff and service doors, garages, vehicle and pedestrian gates, package rooms, amenities, restricted rooms, elevators, and shared corridors. Record how each opening works today.
Time
Document regular hours, tenant or resident schedules, vendor windows, temporary access periods, holidays, after-hours rules, turnover, and any planned public-unlock periods that fit the property and system.
System decisions
Choose credentials and architecture around the property team.
Cards, fobs, mobile credentials, and keypads can all be useful. The deciding questions are who uses them, how they are supported, and what the selected readers and platform can actually manage.
Cards and key fobs
Physical credentials can be assigned to individual users and managed without mechanically rekeying every affected opening. The property still needs a process for issuance, return, replacement, and deactivation.
Mobile credentials
Phone-based access requires compatible readers, a supported platform, user onboarding, a plan for lost or replaced phones, and backup access for the groups that need it.
Keypad codes
Code-based access needs a clear decision about individual versus shared codes, who changes them, how temporary use is handled, and whether the keypad is part of a centrally managed system.
Standalone or centrally managed
Standalone electronic locks can fit a limited opening set, while centrally managed systems bring users, schedules, events, and multiple openings into shared administration. The right direction depends on operational scale and support.
Cloud-managed or on-premise
Compare existing equipment, network requirements, administrator access, recurring costs, offline behavior, system ownership, migration options, and support responsibilities—not the hosting label alone.
Retrofit planning
Reuse existing components only after verification.
An upgrade does not automatically require replacing every door, lock, reader, controller, power supply, or cable path. Reuse should be based on condition, compatibility, capacity, and serviceability.
| Existing condition | Verification before reuse |
|---|---|
| Door and frame | Closing, latching, alignment, wear, hardware preparation, and suitability for the proposed locking method |
| Lock or exit hardware | Function, compatibility, condition, egress behavior, and fit with the proposed release method |
| Readers and credentials | Technology, controller compatibility, user needs, and the migration path |
| Controllers | Supported devices, available capacity, software status, condition, and future serviceability |
| Power supplies | Device requirements, load, condition, location, and the applicable backup strategy |
| Wiring and conduit | Cable type, route, condition, labeling, test results, and compatibility with the proposed devices |
Beyond the door
Gates, garages, and elevators need their own scope.
Vehicle and pedestrian gates
Gate planning can involve reader placement, vehicle approach, pedestrian movement, operator interfaces, release behavior, weather exposure, long cable paths, intercoms, cameras, and staff overrides.
Parking garages
Garage access may combine vehicle credentials, pedestrian doors, visitor entry, gate release, camera coverage, and building access. The gate should connect cleanly to what happens after a person or vehicle enters.
Elevators
Elevator access can introduce floor permissions, reader placement, controller interfaces, elevator-contractor coordination, building operations, and life-safety review. It is not a standard door connection.
Project review
Plan egress and code-sensitive conditions before hardware is ordered.
Electrified locking affects doors used by real occupants. Applicable requirements depend on the occupancy, opening, locking arrangement, adopted code, local amendments, and authority having jurisdiction.
This guide is general planning information, not a code determination for a specific opening. Listed, compatible components should be used where required, and the fire marshal or other authority having jurisdiction determines compliance.
- Document how the opening is operated from the egress side.
- State what happens when power is lost and when relevant building systems activate.
- Identify request-to-exit, manual-release, and door-position functions in the approved design.
- Flag panic hardware, fire exit hardware, fire-rated doors, accessibility conditions, and other-trade coordination.
- Assign permits, design review, inspections, and authority approvals instead of leaving them implied.
Before the proposal
Bring a practical opening and operations inventory to the site walk.
The more clearly the property can describe its current openings and daily access needs, the more specific the resulting scope can become.
- Property type, operating hours, primary contacts, user groups, current access problems, and priority openings
- Door and gate inventory with photos of the secure and egress sides
- Existing locks, strikes, maglocks, exit devices, closers, readers, controllers, and power supplies
- Openings that drag, sag, bind, fail to latch, or remain unlocked
- Available drawings, device schedules, service records, administrative access, and known cable or conduit routes
- Intercom, gate, elevator, camera, alarm, network, and automatic-operator connections
- Credential issuance, lost-credential, temporary access, turnover, reporting, and training needs
Buyer checklist
Ask whether the proposal makes the complete system understandable.
- Does it identify every controlled opening and its observed condition?
- Does it state what will be reused, replaced, repaired, or tested?
- Are door hardware, power, wiring, controller, credential, and software needs included?
- Are gates, elevators, intercoms, networks, alarms, and other coordination points assigned?
- Does it explain user groups, schedules, credential migration, administrator access, and handoff?
- Are subscriptions, recurring fees, alternates, allowances, exclusions, and owner-provided work visible?
- Does it define commissioning, testing, documentation, training, warranty, and support?
- Does it identify code-sensitive conditions and the parties responsible for review and approval?
Avoidable gaps
Common access-control planning mistakes
- Selecting a platform before inspecting the openings
- Treating a reader as the complete access-control scope
- Assuming existing wiring is usable without identification and testing
- Ignoring a door that does not close or latch consistently
- Leaving user groups, schedules, and offboarding until the end
- Comparing bids that include different hardware, wiring, software, and support
- Omitting gate, elevator, intercom, network, or alarm coordination from the responsibility matrix
- Finishing without clear administrator access, documentation, training, and a support path
Common questions
Commercial access-control questions property teams ask
Can access control be added to one existing door?
Often, yes. The door, frame, lock or exit hardware, closer, power, wiring path, reader location, controller, credential plan, and egress conditions should be reviewed before selecting the scope.
Can an existing keycard system be upgraded in phases?
Often, yes. A phased plan can begin with priority openings when the old and new system conditions, credential transition, controller capacity, wiring, administration, and support path are understood.
Can a property use cards, fobs, and mobile credentials together?
Many systems support more than one credential type, but actual compatibility depends on the platform, readers, credential technology, user groups, and management plan.
Does every project require new wiring?
No. Existing wiring may be reusable when its type, condition, route, labeling, and compatibility are confirmed. New devices or communication methods can change cable and power requirements.

Sources and further reading
These references support the general technical guidance. The right answer for a specific opening still depends on the property and the authorities responsible for the project.
- Security Industry Association: The Basics of Physical Access Control
- Security Industry Association: Open Supervised Device Protocol
- National Institute of Standards and Technology: FIPS 201-3, Personal Identity Verification
- California Building Standards Commission: Current California Building Standards Codes
- California Building Standards Commission: 2025 California Code Changes: Chapters 9 and 10