Modern access control systems beyond badge readers
Modern access control systems compared: mobile credentials, biometrics and Bluetooth unlock, with the legal duties and rollout traps of each.

The badge reader has not changed much in twenty years. What has changed is what people will carry, what a credential proves, and what a court says about the fingerprint you stored. Modern access control means picking between a phone, a face and a card.
Past the badge reader there are three options: a mobile credential, a biometric read, or hands-free Bluetooth unlock. Mobile suits offices where IT can revoke remotely. Biometrics suit the few doors where identity must be proven, and carry statutory duties in several states. Bluetooth suits throughput and hurts your log. Match strength to what is behind each door.
What is a credential actually proving?
Three things, and most systems check exactly one.
- Something you have
- A card, a fob, a phone. Proves possession of an object, not identity. Anything you can hand to a colleague, you will.
- Something you know
- A PIN or a code. Proves knowledge, which is also shareable, and which gets written on the underside of the desk.
- Something you are
- A fingerprint, a face, an iris. Proves the person. This is the only factor that resists lending, which is exactly why it is also the one that is regulated.
An older 125 kHz proximity card transmits a fixed number and nothing else. That number is an identifier, not an authenticator, and it should not be the only thing standing between the corridor and the room where the money is. NIST makes the same point in reverse in SP 800-116 Revision 1, which is built around a risk-based strategy for choosing an authentication mechanism per area rather than one mechanism for the whole building.
Mobile credentials
The phone as the badge
- Works because: people forget badges and do not forget phones. Issuing and revoking is remote and instant, which matters most on the day someone is let go.
- Fails because: a dead battery is a locked door, and some staff will object to installing a work app on a personal device. Have an answer for both before rollout, not after.
- Fits: offices, tech campuses, anywhere the workforce already runs on a phone.
The revocation speed is the underrated part. A card sits on a hook in a drawer until someone remembers to collect it, which is the same failure mode that makes key control hard. A mobile credential dies the moment someone clicks.
Biometrics
- Works because: it cannot be lent, lost or left at home, and it is the only factor that ties an entry to a person rather than to an object.
- Fails because: gloves, dust, wet hands, masks and bad lighting all degrade it, and manufacturing and food plants are full of all five. Cost per door is higher.
- Fits: the small number of doors where identity genuinely has to be proven. Server rooms, cash rooms, controlled substance storage, an armory.
Biometrics is where a technology decision becomes a legal one. Under the Illinois Biometric Information Privacy Act, a private company must publish a written retention and destruction policy, must inform the subject in writing of what is collected and for how long, and must obtain a written release before collecting it.
Section 20 provides liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless one, plus attorneys' fees. Texas and Washington have their own statutes and more states keep adding them. Check your state and your client's state before scoping a fingerprint reader, not after the install.
Bluetooth and proximity unlock
- Works because: the door opens as you walk up, hands full, which is the entire point at a loading dock or a stairwell during shift change.
- Fails because: range is fuzzy. A credential in a pocket on the other side of a wall can open a door nobody walked through, and your log now says something that did not happen.
- Fits: high-traffic openings where throughput matters more than a precise record of who crossed.
Be honest about that last line. If the reason you installed readers was to be able to answer "who was in the building at 11:40", hands-free unlock is working against you.
Why do rollouts fail?
Not at the design stage. At the switchover.
- Integration. Does it talk to visitor management, elevator control, the alarm panel and the HR system that knows who still works here? An access system that does not read from HR will keep letting people in for months.
- Backup access. When the head end is down, how does the night shift get in? Write the manual override procedure and rehearse it, or you will invent one at 2am under pressure.
- Training. People need to have used it before it becomes the only way in. Run both systems in parallel for a week.
- Edge cases. Contractors, deliveries, agency staff, the fire department. Every one of them needs a defined path, and the paths you do not define become a propped door.
The access system is also on the network, which makes it a target rather than just a tool. Cybersecurity basics for physical security teams covers the default credentials and flat network segments that turn a reader controller into a way in.
What do most sites actually end up with?
A mix, and that is the right answer rather than a compromise. Card and PIN on the general population doors. Biometrics or two factors on the short list of rooms that justify it. Mobile where the workforce will use it. Mechanical keys held in a controlled cabinet as the fallback that works when the power does not.
Decide the tiers by asking what is behind each door and what it costs you if the wrong person opens it. That is the same exercise as a physical security audit, and it is worth doing before a vendor scopes it for you. For the highest tier, data center physical security shows what layered authentication looks like when it is taken seriously.
One adjacent note: the same tap-to-read hardware that opens doors also proves a patrol reached a location. That is a different job with different requirements, covered in NFC checkpoints and guard tours.
Key Takeaways
- Pick the authentication strength per area, not per building. NIST SP 800-116 is built on that principle.
- A legacy prox card sends a static number. Treat it as an identifier, not proof of identity.
- Mobile credentials win on revocation speed, which is the control that matters on a termination day.
- Biometrics carry statutory duties. Illinois BIPA requires written notice, a written release and a published retention policy.
- Rollouts fail on integration, backup access, training and edge cases. Plan all four before the cutover.
Continue Reading

What autonomous security patrol robots do
Security patrol robots observe, record and alert but cannot intervene. What Knightscope and Boston Dynamics publish, realistic runtime, and where a robot fits.

Drones in security operations: rules and uses
Where a security drone beats a guard on foot, what FAA Part 107 requires of the pilot and aircraft, and the recording consent you need before the first flight.

Security operations trends for 2026: pay and data
Security operations trends for 2026: guard pay now matches warehouse work, clients buy reporting in the RFP, and paper is still the real technology gap.