Latest
Subscribe
Advertisement

Access control glossary

Plain-language definitions of the terms this industry actually uses — including the distinctions most publications get wrong.

A

Access control as a service (ACaaS)

A physical access control system delivered as a cloud subscription: the management software runs in the vendor's cloud rather than on a server at the site, and the customer pays per door or per month.

Not to be confused with Cloud access control.

Access control panel

The controller that receives credential data from readers and makes the grant/deny decision against stored access rules, driving the door hardware.

Access control reader

The device at the door that reads a credential (card, phone, PIN or biometric) and passes it to a controller for the access decision.

Access control vestibule

A small two-door space (a "mantrap") where the second door will not open until the first has closed, allowing only one authorised person through at a time.

Not to be confused with Tailgating.

Anti-passback

A rule preventing one credential from being used to enter twice without an intervening exit — stopping a card being passed back to admit a second person.

B

Biometric template

The mathematical representation derived from a biometric sample (face, finger, iris). It is not a stored image and generally cannot be reversed into one.

C

Credential

The token a person presents to prove they are authorised: a card, fob, mobile credential, PIN or biometric. What the reader reads.

D

Directory synchronisation (SCIM) (SCIM)

Automatically provisioning and de-provisioning access from an identity source (e.g. Entra ID, Okta) so a leaver loses building access when they lose their login.

Duress code

An alternate PIN that grants entry as normal while silently signalling to security that the user is being coerced.

F

False acceptance rate (FAR)

The rate at which a biometric system wrongly accepts a non-matching person. The security-side error metric, traded off against the false rejection rate.

Not to be confused with False rejection rate.

False rejection rate (FRR)

The rate at which a biometric system wrongly rejects a legitimate, enrolled person. The convenience-side error metric, traded off against the false acceptance rate.

Not to be confused with False acceptance rate.

Fingerprint recognition

Biometric matching based on the ridge patterns of a finger, used at readers for verification or identification.

I

Interoperability

The degree to which access control components from different vendors work together — readers, credentials, controllers, video and identity systems — without proprietary lock-in.

Not to be confused with Open architecture.

Iris recognition

Biometric matching based on the pattern of the iris, offering very high accuracy at short range.

L

Liveness detection (PAD)

Techniques that confirm a biometric sample comes from a live person present at the sensor, defeating photos, masks and replays. Formally, presentation attack detection.

M

Mobile credential

An access credential stored on a smartphone (or smartwatch) and presented over BLE or NFC, replacing a physical card.

Not to be confused with Proximity card.

N

O

Open architecture

An access control design that uses non-proprietary readers, credentials and interfaces (e.g. OSDP, open card formats) so the buyer is not locked to one vendor.

P

Palm vein recognition

Contactless biometric matching based on the subcutaneous vein pattern of the palm, which is hard to spoof because it is beneath the skin.

Physical access control system (PACS)

The system of readers, controllers, credentials and management software that decides who may open which door, when — as opposed to logical (IT) access control.

Physical security information management (PSIM)

Software that aggregates and correlates alarms and data from many independent security systems — access, video, intrusion — into one operator view.

Power over Ethernet (access control) (PoE)

Delivering both power and data to a door controller or reader over a single Ethernet cable, simplifying wiring for IP-based access control.

Proximity card (Prox)

A legacy 125 kHz contactless card that transmits a fixed number with no encryption — easy to use and easy to clone.

Not to be confused with Smart card.

R

Request to exit (REX)

A sensor or button that signals a controller someone is leaving, so the door can be released from the inside without triggering a forced-door alarm.

S

Smart card

A 13.56 MHz contactless card (e.g. MIFARE DESFire, iCLASS SE) that uses mutual authentication and encryption, resisting the cloning that defeats prox cards.

Not to be confused with Proximity card.

T

Tailgating

An unauthorised person following an authorised one through a door on a single valid credential. Also called piggybacking.

Not to be confused with Anti-passback.

Turnstile

A physical entrance-control barrier (optical, tripod or full-height) that enforces one authorised passage per credential, physically preventing tailgating.

U

Ultra-wideband (UWB)

A radio technology that measures distance very precisely, used in access control to make unlock depend on the phone's exact position, resisting relay attacks.

V

Video intercom

A door-entry device combining a camera, audio and a release control, letting a person or app verify a visitor before unlocking — central to multifamily access.

Visitor management system

Software that registers, credentials and tracks guests — pre-registration, check-in, badge printing and host notification — often integrated with the access control system.

Not to be confused with Video management system.

W

Wiegand

The legacy point-to-point wiring interface between a reader and a controller. Unencrypted, unsupervised and one-way — the problem OSDP was created to replace.

Wireless lock

A battery-powered electronic lock that communicates over a wireless link, extending access control to doors where wiring a controller is impractical.