Back to Blog
Access Control

How Physical Access Control Systems Actually Work

Monarch ConnectedSeptember 1, 202616 min read
Hand pressing a small round credential reader mounted under a wooden reception desk, part of physical access control systems.

Real talk? Most people think physical access control systems are just "fancy door locks with a beeper on them." (I used to think that too — then I spent a week troubleshooting a mag-lock that kept unlocking every time the HVAC kicked on. Turns out, doors have opinions.) There's a lot more happening behind that little green LED than you'd guess, and if you're the one signing the check, you deserve to know what you're actually buying.

So let's pop the hood. No sales-deck fluff, no vendor bingo — just a plain-English walkthrough of how these systems work, where they break, and how to spec one that doesn't turn into a Monday-morning fire drill.

What Physical Access Control Systems Actually Are

At its simplest, a physical access control system is a set of hardware and software that decides — in real time — who can open which door, at which time, under which conditions. That's it. That's the whole game.

But "that's it" hides a lot of moving parts. You've got the credential (the thing in someone's hand or pocket), the reader (the thing on the wall), the controller (the brain hidden above the ceiling), the door hardware (the muscle), and the management software (the place where the rules live). Yank any one of those out and the whole thing turns into a doorstop.

The reason the modern version matters more than the old lock-and-key setup is auditability. A key doesn't tell you who used it, when, or how many copies are floating around in someone's ex-employee glove box. An electronic system does. Every swipe, tap, or denied entry gets stamped and stored. That's not paranoia — that's just how insurance carriers, auditors, and lawyers all want it now.

The Four Layers Every System Has

Verkada AC43 access control panel shown open with internal components visible.

Every access control deployment, whether it's a single-door dentist office or a 47-building logistics campus, breaks down into four layers. Miss one and something is going to bite you.

  • Credential layer: what the user carries — key fob, card, mobile app, biometric, PIN.
  • Reader layer: what recognizes the credential at the door.
  • Controller layer: what makes the actual "allow/deny" decision.
  • Management layer: the software where you set schedules, add users, and pull reports.

The credential and reader are what everybody sees. The controller and management software are what everybody forgets to spec properly. Guess which two decide whether the system still works when your IT provider ghosts you in year three.

If you want the same idea from a different angle — role-based vs discretionary vs mandatory — we broke it down in a separate post on the three types of access control. Worth a skim before you start writing policy.

Credentials: The Thing in Someone's Hand

Credentials are how the system knows it's you. Historically that meant a plastic card. Today it's a smorgasbord.

  • Prox cards (125 kHz): cheap, easy to clone with a $30 device off the internet. Fine for a broom closet. Not fine for anything sensitive.
  • Smart cards (13.56 MHz, DESFire EV2/EV3): encrypted, mutual-authentication, actually secure. This is the modern default for cards.
  • Mobile credentials: the user's phone becomes the credential over Bluetooth or NFC. Convenient, harder to lose, harder to clone, and it kills the "I forgot my badge" excuse.
  • Biometrics: fingerprint, face, iris, or palm-vein. Great for high-security zones. Slower for high-throughput doors — a lobby that pushes 400 people between 8:55 and 9:05 will hate you if you biometric-gate the front door.
  • PINs: fine as a second factor, terrible as a first. People share them. People write them on sticky notes. You know they do.

Two-factor is the sweet spot for anything that matters — usually "card plus PIN" or "phone plus face." One factor gets you in the door, the second proves you aren't just holding someone else's stuff.

Readers: The Wall Bit Everyone Sees

The reader is the beige (or, if you sprung for it, brushed aluminum) rectangle mounted next to the door. Its job is boring but important: read the credential, pass the data to the controller, blink a helpful color at the user.

The big shift in the reader world is the move from Wiegand to OSDP. Wiegand is a 1980s protocol that transmits credential data in the clear — meaning a person with a $50 tool and thirty seconds behind a reader can literally sniff every card that gets presented. OSDP (Open Supervised Device Protocol) encrypts that traffic, monitors the reader for tampering, and supports bidirectional communication. If a vendor is still quoting you Wiegand-only readers in 2026, that's a red flag. The Security Industry Association publishes the OSDP specification and it's now the recommended baseline.

Reader form factors matter too. Mullion-mount readers (skinny, fits on a door frame) vs single-gang (wider, fits a standard electrical box) vs long-range (for gates and parking). Pick the wrong one and your installer will "make it work" with an adapter plate that looks exactly as ugly as it sounds.

Controllers: The Actual Brain

Here's the part people skip past. The controller is the small computer, usually panel-mounted in an electrical closet, that receives the credential data from the reader and makes the yes/no decision. It stores the cardholder database locally, so if the network dies, doors keep working.

That last bit — local decisioning — is huge. A cloud-only system where every door has to phone home to a server in Virginia before it unlocks is a system that stops working the day your ISP hiccups. Real physical access control systems keep the access rules cached at the edge and sync back up when the network returns.

Controllers come in a few flavors:

  • Single-door controllers: cheap, distributed, one per door. Easy to add capacity.
  • Multi-door controllers (usually 2, 4, 8, or 16 doors): one panel serves multiple doors on one floor.
  • IP-at-the-door: some newer platforms put the "controller" logic right at the reader itself with PoE. Less wiring, more units to manage.

The controller is also where relay logic lives — what fires the strike, how long, whether it triggers a camera to record, whether the intrusion alarm arms/disarms automatically when the last person badges out. Which brings us to the next layer.

Where Access Control Meets the Intrusion Alarm

Access control and intrusion alarm systems used to be sold and installed by two different companies who never spoke to each other, and you'd end up with two keypads next to every door, two apps on your phone, and two invoices that never matched. Fun.

Modern platforms fold them together. When your last badge-holder leaves for the night, the system arms the intrusion alarm automatically. When the first person badges in at 6:14 a.m., it disarms — but only for that specific area, and only if that badge has "can disarm" permission. If the door opens without a valid badge? The system knows the difference between an authorized entry and a "someone just kicked the back door in" event. That's the point of the integration: the doors and the sensors tell the same story.

The alternative — running access and alarm as separate silos — is how you end up with false alarms that cost you money and true alarms that get ignored. Insurance carriers have started noticing. Some now offer premium credits for integrated systems where entry events reconcile against motion and glass-break sensors in real time.

Door Hardware: The Muscle

The electronics are only as good as the physical door they control. This is where a lot of otherwise well-designed installs quietly fall apart, because someone assumed "the door is fine" and it very much was not.

The two dominant lock types are electric strikes (which replace the metal plate the latch drops into) and magnetic locks (a big electromagnet holds the door shut). Strikes fail secure by default — power out, door stays locked. Mag locks fail safe — power out, door unlocks. Which one you want depends on the door's life-safety role, and the local fire code has strong opinions here.

Request-to-exit sensors (REX) tell the controller that someone inside pressed the bar to leave, so the system doesn't flag it as a forced-open event. Door position switches (DPS) tell it whether the door is actually shut. Miss either of those and you get either constant false alarms or, worse, no alarm when someone actually props the door open with a fire extinguisher for their smoke break.

The door frame itself has to be square, the hinges have to be tight, and the gap has to be within spec. I've seen $80,000 systems fail their commissioning walk because the door was warped and wouldn't latch. Electronics don't fix woodwork.

Management Software: Where the Rules Actually Live

This is the layer nobody demos properly and everybody uses daily. The management software is where you add and remove users, define schedules, group doors into "access groups," pull audit reports, and see who's currently in the building.

Cloud-based management (browser or app) has basically won this argument. On-prem servers still exist, but they cost more in year-two support than the software ever saved you upfront. Cloud means:

  • Add a user from your phone at 10 p.m. when a subcontractor calls needing weekend access.
  • Auto-sync with your HR platform so terminated employees get cut off the moment their record flips.
  • Real-time alerts pushed to whoever's on call.
  • Automatic firmware updates on the controllers, which — trust me — you do not want to be doing manually.

The really important question to ask about management software is who owns the data if you leave. Some legacy platforms hold cardholder databases hostage in proprietary formats. A vendor that won't hand you a clean export on request is a vendor you're renting from, not buying from. Monarch's own access control solution page walks through what the day-to-day looks like on a modern cloud platform, if you want to see one in the wild.

A Realistic Look at Cost

Here's where most articles get squishy. Real numbers, based on typical commercial installs — treat these as ranges, not quotes, because door hardware condition and cable runs swing everything.

ComponentTypical cost per doorNotes
Reader (OSDP-capable)$150 – $400Mobile-ready readers land at the higher end
Controller share (per door)$200 – $600Cheaper per-door in multi-door panels
Electric strike or mag lock$150 – $500Fire-rated doors run higher
REX + DPS + wiring$200 – $500Highly install-dependent
Installation labor$400 – $1,200Conduit, cable pulls, commissioning
Software license (per door, per year)$60 – $180Cloud-managed platforms

Rough all-in first-year cost per door: $1,200 to $3,000, with an ongoing annual software fee. High-security doors (turnstiles, mantraps, biometric mustering) run 2–5x that. If someone quotes you $400 a door all-in, they're either using Wiegand prox from a decade ago or they're planning to disappear before commissioning.

Compliance and What Auditors Actually Ask

Depending on what your building does, you're on the hook for one or more compliance regimes. A few of the common ones:

  • HIPAA: healthcare facilities. Audit logs of who accessed rooms with PHI.
  • PCI DSS: any environment handling cardholder data. Physical access to servers must be logged and reviewed.
  • CJIS: law enforcement and any vendor touching criminal justice info. Very strict.
  • SOC 2: increasingly requested by enterprise customers of SaaS vendors. Physical controls are part of the audit.
  • Local fire code (NFPA 101 in the US): governs egress. Your locks cannot trap people in a burning building. Non-negotiable.

The National Institute of Standards and Technology publishes SP 800-53 controls that most of the above cascade from, and it's worth having your integrator explain which specific control families they're helping you satisfy. If they can't answer, that's data too.

Cabling, Power, and the Boring Stuff That Breaks

Nobody wants to talk about cable, but cable is why 80% of access-control problems happen. Some quick truths:

  • Composite cable (one jacket carrying reader, lock power, REX, and DPS pairs) simplifies install but makes future upgrades painful. Individual runs cost more day one and save you day 900.
  • Power supplies need battery backup. A power blip that reboots your controller and drops thirty doors offline is not a fun Tuesday.
  • PoE (Power over Ethernet) is increasingly viable at the door with newer readers. Simpler wiring, one cable pull, fewer failure points.
  • Cable distance matters. Wiegand tops out around 500 feet before it gets flaky; OSDP is more forgiving but still has limits.

Ask your integrator for as-built drawings after install. If they can't produce them, they didn't do the job right — and the next tech you hire is going to charge you double to reverse-engineer the wiring in your walls.

Visitor Management, Which You Will Regret Ignoring

Every physical access control system deployment eventually has to answer "what do we do with visitors, contractors, and delivery drivers?" The wrong answer is "the receptionist buzzes them in." The right answer is a visitor management workflow — pre-registration, self-serve check-in, temporary credential (often a QR code to a phone), auto-expiration, and a badge log tied to the host employee.

Modern systems tie this straight into the same platform running the doors, so a visitor gets a QR credential that opens exactly the lobby and one meeting room, expires at 5 p.m., and shows up in the same audit log as everybody else. Contractors get a slightly wider window with the same expiration. Delivery drivers get a dock door and nothing else.

This is also where things like OSHA's workplace security guidance intersect with access control — a lot of workplace violence incidents involve someone who "shouldn't have been in the building" but was, because nobody was actually managing visitor flow. Not to be grim about it. But that's the reason it matters. For a broader look at how our team approaches this stack end-to-end, our contact page is the easiest place to start a conversation.

Common Deployment Mistakes (Written From Battle Scars)

A short, incomplete list of ways I've watched these projects go sideways:

  • Speccing enough hardware for today, not enough for growth. That fourth floor you're building out next year? Its controller capacity should already be planned.
  • Skipping the door survey. Not every door can accept an electric strike without frame modification. Find out before install day, not during.
  • Ignoring failover. What happens when the internet dies? What about when the controller dies? Have an answer.
  • Letting HR and IT skip the integration conversation. If terminations don't auto-sync, someone will forget to revoke a badge and it'll be the one that mattered.
  • Buying on price. The cheapest quote wins the job and then wins your entire next decade of headaches. Buy on the integrator, not the invoice.

Where the Technology Is Actually Headed

A few trends worth knowing about, without getting breathless:

  • Mobile credentials are becoming the default, and physical cards are becoming the fallback. This flips how you think about issuing credentials — you're provisioning a phone, not printing a card.
  • Video verification of every access event. The camera above the door records a five-second clip tied to the badge swipe, and AI flags mismatches (badge says "Jamie," face at the door isn't Jamie).
  • Occupancy-aware buildings. Access data feeds HVAC and lighting so unused zones power down automatically. Not sexy but it pays for itself.
  • Zero-trust for buildings. Instead of "you're in the building so you're trusted," every door checks conditions in real time — is this the right person, in the right zone, at the right time, from the right credential.

None of this changes the fundamentals. Reader, controller, credential, software, integrated intrusion alarm. The plumbing stays the same. The intelligence layered on top gets smarter.

How to Actually Choose a System

If I had to compress this whole article into a checklist you'd bring to a vendor meeting:

  1. Ask what protocol their readers use. If the answer isn't OSDP, ask why.
  2. Ask what happens to the doors during a network outage. If they don't answer "local decisioning, they keep working," move on.
  3. Ask how the system integrates with your intrusion alarm and your camera platform. Watch them demo it, don't just take a slide.
  4. Ask how HR integration works. Auto-provisioning and auto-deprovisioning saves you from your own future forgetfulness.
  5. Ask for a data-export clause in the contract. You should own your cardholder data, forever.
  6. Ask to talk to three current customers on the same platform. Not the vendor's showcase account — the boring, average one.
  7. Get a proper site survey before signing. Every door, measured, photographed, condition-noted.

Do that and you'll dodge probably 90% of the mistakes people make on these projects. The remaining 10% is what integrators exist for.

FAQ

Do physical access control systems still work if the internet goes down?

A well-designed system, yes. The controllers store the cardholder database locally and make access decisions at the edge, so doors keep unlocking for authorized users during an outage. What you lose during a network outage is real-time visibility, remote management, and cloud logging — those catch up when connectivity returns. If a vendor tells you every unlock has to phone home to their cloud, walk away.

How is a physical access control system different from just changing the locks?

Locks and keys give you no audit trail, no ability to revoke access without collecting hardware, and no way to differentiate schedules per person. An electronic system logs every entry attempt, lets you cut off a departing employee in seconds, and can enforce time-of-day and zone rules automatically. It also integrates with the intrusion alarm and camera systems, so entries reconcile against sensor and video data. The lock is a mechanism; the access control system is a policy engine.

What's the difference between OSDP and Wiegand, and does it actually matter?

Wiegand is a 1980s reader-to-controller protocol that transmits credential data unencrypted, meaning someone with a cheap sniffing tool can capture cards presented to your reader. OSDP encrypts that communication, detects tampering, and supports bidirectional messaging for features like firmware updates and reader health checks. If you're deploying in 2026, OSDP should be the default. Wiegand-only quotes in a new install are a legitimate reason to ask hard questions.

Can I integrate my existing door hardware, or do I have to rip everything out?

Often, yes — you can reuse existing electric strikes, mag locks, and door contacts if they're in good condition and meet code. The reader, controller, and management software are typically what changes during a modernization. A proper site survey will tell you door by door what's reusable and what has to go. Most projects end up somewhere between "reuse everything mechanical" and "replace 20% of doors that were already limping."

How long does a typical installation take?

For a small commercial site (5–15 doors), plan on 2–4 weeks from contract signing to commissioning, with the actual on-site install taking 3–7 days. Larger campuses run in phases and can stretch over months. The long pole is almost always the site survey, permitting, and coordinating with facilities to schedule downtime — not the electronics themselves. Anyone promising "next-day install" on more than one or two doors is skipping steps you'll pay for later.

Do biometrics replace cards and phones, or work alongside them?

They usually work alongside them as a second factor for high-security areas. Biometrics alone can be slow at high-traffic doors and have false-reject rates that frustrate users. The common pattern is card-or-phone at general-access doors, and card-plus-fingerprint (or phone-plus-face) at sensitive zones like server rooms, cash rooms, or research labs. Two factors at the doors that matter, one factor everywhere else.

What ongoing costs should I expect after the install?

Budget for annual software licensing (typically $60–$180 per door), credential replacements as employees turn over, occasional battery replacements in backup power supplies, and a service agreement for hardware failures. Firmware updates on a cloud platform are usually included in licensing. Every 7–10 years, plan for a partial hardware refresh — readers and controllers don't last forever, and standards move on. Total ongoing cost typically runs 15–25% of the initial install per year.

Related Solutions

Explore how Monarch Connected can help with your specific security needs.

Shop Access Control

Ready to Upgrade Your Security?

Talk to our experts about Verkada cameras, access control, and sensors — book a demo.

More Articles