What Actually Goes Into a Modern Access Control System
To most people, access control is the card reader next to the door. Badge in, door unlocks. But that reader is the visible tip of a system with real depth beneath it — credentials, controllers, wiring protocols, management software, door hardware, and a set of life-safety decisions that carry legal weight. The gap between a well-designed access control system and a cheap one installed without much thought is the difference between security you can trust and a false sense of it.
Here's what's actually under the hood, and the decisions that matter.
Credentials: How You Prove Who You Are
The credential is what a person presents to be let in, and it has evolved a long way from the metal key.
Proximity ("prox") cards at 125 kHz were the workhorse for years. They're convenient — but the older ones are also easy to clone with cheap equipment, which is a genuine security weakness few users appreciate.
Smart cards at 13.56 MHz (such as MIFARE DESFire) use encryption and mutual authentication, making them dramatically harder to copy. For any new system, this is the baseline worth insisting on.
Mobile credentials turn a smartphone into the badge, using Bluetooth or NFC. They're convenient, hard to clone, and easy to issue or revoke remotely — no physical card to print or collect.
Biometrics (fingerprint, facial, iris) tie access to the person rather than something they carry, for the highest-security doors.
The takeaway: if a proposal is built around legacy 125 kHz prox, ask why. The technology to do better is mature and affordable.
The Wiring Question Almost Nobody Asks: OSDP vs. Wiegand
This is where an expert installer separates from an order-taker, and it's the single most overlooked decision in access control.
For decades, readers talked to their controllers over a protocol called Wiegand. It works, but it was designed in another era: it's unencrypted, one-directional (reader to controller only), unsupervised, and limited in distance and features. Because it's unencrypted, someone who can reach the wiring between the reader and the controller can potentially capture credentials or inject a signal to open the door — defeating the entire system without ever touching a valid card.
OSDP (Open Supervised Device Protocol) is the modern replacement. It runs over two-wire RS-485, and it's:
Encrypted (via its Secure Channel, using AES), so the reader-to-controller link can't be trivially eavesdropped or spoofed
Bidirectional, enabling features like reader status, tamper alerts, and remote management
Supervised, meaning the system knows if a reader is disconnected or a line is cut, rather than failing silently
Capable of longer cable runs and connecting multiple devices on a single line
Security-conscious organizations — and increasingly government and industry guidance — specify OSDP for exactly these reasons. If you're investing in access control to make a facility more secure, wiring it with an insecure legacy protocol undercuts the whole point. It's a question worth asking of any proposal on the table.
Controllers, Locks, and the Life-Safety Decisions
Behind the readers sit the controllers — the panels that actually make the access decisions and drive the locks. And the locks themselves involve a choice with real legal and safety implications: fail-safe versus fail-secure.
A fail-safe lock unlocks when it loses power. A fail-secure lock stays locked when it loses power. This isn't a preference — it's governed by building and fire codes, because doors in an egress path must always allow people to get *out*, even during a power failure or fire alarm. Life-safety codes require free egress, and certain doors must release automatically when the fire alarm activates. Getting this wrong isn't just a security flaw; it can be a code violation that endangers people and fails inspection. A competent designer works these requirements out door by door, in coordination with the fire alarm system — it is not an afterthought.
Increasingly, controllers and even locks are powered over the network via PoE, which brings the same benefit it brings elsewhere: centralized, UPS-backed power for the door hardware, managed from one place. When the building's doors are on network-delivered power, the reliability of that power — and the cabling behind it — becomes part of your security posture.
Cloud vs. On-Premises Management
How you manage the system is its own decision.
On-premises management runs the software on a server you own and control. There's no recurring cloud subscription and your data stays in your building, but you're responsible for maintaining, updating, and backing up that server.
Cloud-based management is hosted and maintained by the provider. You can administer doors, run reports, and even unlock a door remotely from anywhere, updates happen automatically, and there's no server to maintain — in exchange for an ongoing subscription and reliance on your internet connection. For organizations with multiple sites or lean IT staff, the cloud model is often compelling; for others, keeping everything in-house is the priority. Neither is universally right.
Access Control Doesn't Live Alone
The real power of a modern system shows up when it's integrated with the rest of your security. Tie access control to your video surveillance and a badge event can instantly pull up the camera covering that door — so you're not just seeing that a credential was used, but who used it. Integrate it with intrusion alarms, visitor management, and identity systems, and you get a coordinated picture instead of a set of disconnected tools. A system designed with integration in mind is worth far more than the sum of separate products bolted together after the fact.
How O.B. One Designs Access Control
We design access control as a system, not a pile of parts. That means specifying secure, modern credentials rather than easily-cloned legacy cards; wiring readers with OSDP so the link between reader and controller is encrypted and supervised; working out fail-safe versus fail-secure door by door in coordination with life-safety requirements; and integrating the system with your cameras and other security so it actually works as a whole. Because we also handle the structured cabling and the PoE infrastructure underneath, the whole system is designed and installed as one coordinated build — tested, documented, and backed by our 100% lifetime warranty.
The Bottom Line
Access control looks simple from the hallway, but the decisions that determine whether it's genuinely secure happen out of sight: the credential technology, the protocol wiring the readers, the fail-safe logic on every door, and how well the whole thing integrates with your other systems. A reader on a door is easy. A system you can actually trust to secure your facility — and to let everyone out safely when it matters — takes design. That's the difference worth paying for.