Custom Styles

We’ve got door hardware engineers on our team who have been in the industry for a long time, and if there is one thing that has stayed consistent over the years, it's that nobody sets out to make bad access control decisions. The mistakes we have seen property owners and managers make when upgrading their facility’s door hardware aren’t from carelessness, but rather from making what they thought were smart, logical, well-informed decisions that just didn’t account for a few things. Here are 5 mistakes that we see them run into most.

Offering Too Many Credential Options

A property wants to be flexible, so they offer as many credential options as possible, thinking that more options equal happier tenants. This way of thinking isn’t unreasonable. With more credentials to pick from, a tenant has more freedom to choose the way to enter their building or unit, and if there’s any issue with one credential, they can switch to another without having to get management immediately involved.  What people seem to overlook is the idea that credentials have to be maintained; when you offer as many credential options as possible, you’re adding more things you have to keep track of, which can quickly become overwhelming. 

For example, let's say an apartment complex offers tenants access via RFID key fob. If a tenant loses their fob, management can issue them an emergency PIN code until it can be replaced. The tenant then mentions it to their neighbor, and now the neighbor wants one too. Then, a tenant asks if they can get a temporary code for their dog walker instead of borrowing a fob. Before long, the property has to juggle 3 to 4 credential types per tenant across the building with no consistent policy for who gets what. 

To simplify it, the more credential options that are in rotation, the harder it is to actually know who has access to your building at any given moment, which is a problem the access control system is trying to prevent in the first place.

Poor Credential Management

This next mistake ties into the previous section, but we figured it was common and notable enough that it deserves its own section (Not to mention, it can happen to properties that keep their credential types simple). Overly broad staff permissions are incredibly common, with many buildings duplicating their master level access keys for all staff. Happens all the time, and seems efficient in the moment, but the problem lies in the potential that could happen. What if the staff member loses the keycard? Or gets let go, but doesn’t return their credential? When you lose a key with the power to open every door in your building, you open your building and tenants to a variety of risks that otherwise wouldn’t happen with proper credential management. Canceling the credential also becomes a nightmare, since the copies are all identical, so oftentimes you can’t tell the copy that went missing.

The bigger issue is remembering to actually revoke credentials when they are no longer in use, master key or not. Most newer systems make it easy to revoke a credential in a couple of clicks, but actually remembering to do it is the part that comes back to bite you. Forgetting to pull access the day after someone moves and not running an audit every so often instead of only looking at the system when something goes wrong can easily cause problems. Luckily, this is an easy fix, it’s just important to remember that a system designed to manage access well can only work if someone’s actually managing it.

Not Planning for Scalability

It’s easy to see why this one happens. A property only needs certain features right now, so paying more for a bigger package feels like paying for stuff you’re never going to use. The problem is that the future sneaks up on you quicker than you may realize. When a couple years down the road arrives and you decide to add an extra building next door, you discover that upgrading isn’t nearly as simple as it would’ve been if you had planned for it from the start. 

Maybe the system you installed maxes out at a certain number of doors or credentials, so the new building needs its own separate system with its own login. Now you and your staff are juggling 2 different dashboards to manage one property, and if a tenant moves between buildings, they’re going to need 2 different credentials instead of just one. And if one of your staff members' employment ends, you now have to remember to pull their access from not just 1, but 2 access systems (ties into the last issue as well).

This is actually a large part of why we built AegisSecure the way we did. You can start with the feature set you need today and scale up later without ripping anything out, including scaling from local server-based AegisSecure up to cloud-based AegisCloud if your property grows past what an on-site system can handle. The same goes for the hardware itself. You can start with a lock that runs offline, and if you decide down the line you want additional features and functionality, it can be added through plug-n-play components, rather than a full hardware swap. All in all, buying the least expensive option today isn’t the mistake, but rather not accounting for whether it can grow with you.

Choosing on Price Alone

Price matters a lot,, and most people shopping for access control naturally compare price against features. People looking at locks will think “I only need features x, y, and z, so I will pay the minimum price to ensure my lock has features x, y, and z”.  What often gets overlooked is everything aside from the features list that a person doesn’t necessarily think about: Important mechanical elements (chassis material, throw length of deadbolt, etc), certifications, and how it holds up under the number of times a door is used on a daily basis. 

Take cycle ratings, for example - a Grade 3 lock is tested to function normally for at least 100,000 - 200,000 open-and-close cycles, whereas a Grade 1 lock is tested to function normally for a minimum of 1,000,000 cycles. These numbers may not show up on a price tag, but for busy doors, it's the difference between a lock failing within a year or two and a lock holding up for 10+ years.

While you might be saving a couple hundred bucks buying a cheaper lock, the cost you’re saving will eventually sneak up on you. Let’s use an example: say you’re comparing a $500 Grade 3 lock and a $1000 Grade 1 lock for your 10 unit residential apartment building. You decide to buy the $500 locks, as it’s cheaper and fits better within your overall budget. 6 months later, you’re finding that 8 of your $500 locks are failing in a way that renders them unusable, so now you have to buy replacements. Now you’re paying an extra $4000 on top of the $5000 you spent, and that’s only within the first 6 months. If the locks keep breaking throughout the year, that number is unfortunately only going to go up, easily exceeding the $10,000 you would have paid if you went with the more expensive, but better rated locks.

What if you decided you were tired of these locks failing, and wanted to switch to a different brand? Well because most manufacturers build their hardware to their own door prep, you’re essentially locked into the brand you picked (no pun intended) unless you want to pay thousands to buy new doors. And while sure, you might think to look at higher end locks of the same brand, only to find out they’re way out of your budget.

We saw this issue and engineered our Rejuvenator series of locks to work around that problem 

(Check them out here), but it’s far easier and more cost effective in the long run to pay a little extra to avoid the problem in the first place.

No Plan for What Happens When the System Goes Offline

Every electronic access system has some version of this risk, and there are a few different approaches in how people handle it. Some go with bigger, well-known cloud providers and accept that an internet outage is possible, whereas others prefer a system with real backup plans, even if the name on it isn’t as well known. Neither choice is wrong. What's wrong is not asking the question at all. 

Imagine your building's internet drops for 30 minutes. If your credentials only get validated against the cloud in real time, that’s 30 minutes where nobody’s badge works. Sure, the staff can start letting people in or propping doors open so they don’t have to move around, but you create a huge security risk in doing so. It’s just smart to be conscious of a few questions: If your system runs on the cloud, what actually happens at the door when the internet goes out? Where does your access data live? On-site? In the cloud? Both? Is it backed up? If it gets corrupted or wiped, how easily can it be restored? Does the system provide notifications in the event something stops working? What’s the plan if something catastrophic happens, like the server fries? 

There are dozens of questions that can come up, and the last one is actually why AegisSecure ships with a backup maintenance app. Whatever system you decide to go with, it’s important that you plan for the worst, no matter how uncommon it may be.

It All Boils Down to the Same Thing

Every single mistake on this list can be drawn from the same idea: Not thinking far enough ahead when choosing an access control solution. These aren’t caused by dumb decisions, but they are preventable mistakes, so long as you account for growth, turnover, and maintenance. If you’re in the middle of upgrading, now is the time to take action and address these points before they turn into problems you’re dealing with later.