smart access systems a simple guide 1 0 44847
smart access systems a simple guide 1 0 44847

Smart Access Systems: A Simple Guide

Industry

Everything a smart access system is sold on, the app, the audit trail, the remote revocation, rests on a single half second: the moment between a credential being presented and a latch actually moving. This guide follows that half second from end to end, then looks at the part of the specification that decides what the door does when the system is no longer in charge.

A smart access system replaces a mechanical key with a digital credential. A reader captures it, a controller checks it against a stored rule, and an electrically operated lock releases the door. The decisions that matter most are not about which credential you choose, but about how the door behaves during a power cut or a fire alarm, and about the personal data the system creates every time it opens or refuses.

The short version

  • Four elements do the work: credential, reader, controller, and electrically operated lock hardware.
  • Fail-safe and fail-secure describe opposite behaviours on power loss, and the fire strategy usually dictates which one a given door gets.
  • Access logs and biometric templates are personal data, with biometrics treated as a special category under EU law.
  • Aliro 1.0, published in February 2026, is the first serious attempt at a common credential standard across suppliers.

The sequence behind an unlocked door

Presenting a card or a phone triggers a short chain of events, and every step in it is a component someone had to specify, install and power. Understanding the chain is what makes the difference between reading a product sheet and reading a system.

  1. The credential is presented. A card, fob, phone, wearable or biometric sample identifies the holder. Nothing about the credential itself grants entry; it only carries an identifier.
  2. The reader captures and transmits it. The reader is a peripheral, not a decision maker. It converts what it sees into a message and passes it inward on a wired or wireless link.
  3. The controller applies the rule. A controller holds the access rules, who may pass through which door, at what times, and returns a grant or a refusal. In a well designed installation it keeps working when the network or the cloud platform is unreachable.
  4. The lock hardware moves. An electric strike, a solenoid lock, a magnetic lock or a motorised lock case releases the door. This is the only step with any mechanical consequence.
  5. The door reports back. A door contact and a request-to-exit device confirm what physically happened, which is what turns an entry attempt into a usable log entry rather than a guess.

Two failure modes follow directly from that chain. A door held open after a valid entry produces no alarm unless a door contact was fitted, and a system that centralises all decisions in a cloud platform will refuse everyone when its connection drops. Both are specification choices made long before anyone touches the software.

Fail-safe or fail-secure, and why the answer is per door

Electrically operated locks behave in one of two opposite ways when they lose power, and confusing the two is the most consequential error in this field. Fail-safe hardware unlocks on power loss. Fail-secure hardware stays locked and relies on mechanical egress from the inside. Neither is correct in general; each is correct for particular doors.

Behaviour On power loss Typical use Main risk
Fail-safe Door releases Doors on escape routes, magnetic locks Building left open during an outage
Fail-secure Door stays locked Server rooms, external perimeter doors Egress depends entirely on mechanical hardware

In Europe, the door hardware side of this is covered by EN 13637:2015, which sets requirements and test methods for electrically controlled exit systems used on escape routes. It treats such a system as a kit of three parts, an initiating element that requests release, an electrical locking element, and an electrical controlling element, and it also covers time delay and denied exit modes where those are permitted.

What the fire strategy takes back from the access system

On an escape route, the access control system is not the authority. The fire strategy is. In the United Kingdom, BS 7273-4:2015+A2:2023 is the code of practice covering the actuation of release mechanisms for doors, and it addresses the design, installation, commissioning and maintenance of the electrical arrangements that unlock or release doors in a fire. Its logic is consistent across most jurisdictions we look at: an electrically locked escape door needs a local manual means of release at the door itself, independent of whether the fire alarm interface works, and the release has to survive a fault or a power failure.

The practical consequence is a sequencing rule. Door-by-door lock behaviour is settled with the fire engineer and the local authority first, and the access supplier configures around that decision. Doing it the other way round produces installations that pass a functional demonstration and fail a fire inspection. Requirements differ by country and by building type, so national regulation and the building’s own fire strategy are the operative documents, not a manufacturer’s guidance note.

An access system decides who comes in. It does not get to decide who gets out.

Every entry creates a record, and some records are regulated

An access system generates personal data continuously. Timestamped movement logs identify individuals, and where biometrics are used the template itself is special category data under Article 9 of the GDPR, which prohibits its processing unless a specific condition applies.

Employment is the awkward case. European data protection authorities have taken a consistent line that employee consent is rarely freely given, since refusing an employer carries real or perceived consequences, so consent is a weak basis for a workplace biometric reader. France offers the most explicit framework: the CNIL published a template regulation on biometrics in the workplace on 28 March 2019, which requires the employer to justify the use of biometrics in a documented, circumstantial way, to meet strict technical and organisational security requirements, and to favour storing the biometric template on a medium held by the employee rather than in a central database.

Two design habits follow. Keep log retention short and defined rather than indefinite, and treat a biometric reader as a decision needing written justification, not a premium feature switched on because the hardware supports it.

The credential fragmentation problem, and what changed in 2026

Mobile credentials have been technically viable for years while remaining commercially awkward, because each supplier ran its own wallet integration and its own reader protocol. The Connectivity Standards Alliance published Aliro 1.0 on 26 February 2026 to address exactly that. It defines a common credential standard working over NFC for tap-to-access, Bluetooth Low Energy for user-initiated release at range, and Bluetooth LE combined with ultra-wideband for hands-free authentication, with Apple, Google and Samsung committed to supporting it in their wallet platforms.

For now we would treat this as a procurement question rather than a technology one. The specification exists and wallet support is announced, but the certified product ecosystem is still building out, so the reasonable position in a 2026 tender is to ask suppliers what their Aliro roadmap is rather than assume interoperability is already delivered.

Questions that come up early

Does a smart access system still work if the internet goes down?

It depends on where the decision is made. Controllers that hold their own credential database and rule set continue granting and refusing entry offline, and synchronise their logs afterwards. Architectures that ask a cloud service for every decision do not.

Are digital credentials more secure than mechanical keys?

They solve a different problem. A lost card is revoked in seconds, where a lost key means rekeying a cylinder or a whole suite. In exchange, the system introduces network exposure, firmware to keep patched, and a database to protect, which mechanical hardware never had.

Can biometrics be used for staff attendance as well as entry?

In the European Union, that is a separate processing purpose and a harder one to justify. Several national authorities have taken enforcement action over biometric time and attendance specifically, on the basis that a less intrusive method would have achieved the same result.

How long should access logs be kept?

Long enough to serve a stated purpose such as incident investigation, and no longer. The retention period should be written down, applied automatically by the system, and justifiable if a regulator asks why it is what it is.

Ready to move from principles to a specification?

The buying decisions, credential types, reader protocols, hosting and integration costs, deserve their own treatment.

See our guide to specifying commercial access control

Access control rarely stays a standalone system for long. Where it sits in relation to the rest of the building, and how that differs from consumer automation, is covered in our comparison of building automation and smart home technology.

Published in 2025. Updated on 13 August 2026. Sources: EN 13637:2015; BS 7273-4:2015+A2:2023; Regulation (EU) 2016/679 (GDPR), Article 9; CNIL, template regulation on biometrics in the workplace, 28 March 2019; Connectivity Standards Alliance, Aliro 1.0 announcement, 26 February 2026. This article is general information and does not replace the fire strategy, national regulation or professional advice applicable to a specific building.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *