Site Management · Access Control

Know Exactly Who Is On Site, and Whether They Should Be

SmartX HUB combines RFID access control with facial recognition so entry is never a single unverified swipe. Identity, credential validity, required documents and zone authorisation are checked together at the door, every decision is logged with the evidence behind it, and exceptions raise an alert instead of quietly opening the gate.

Compound entry decision Credential lifecycle management Document and training validation Per-event audit trail
From Swipe to Verified Entry

Why RFID Access Control Alone Is Not Enough

A badge proves that a credential reached the reader. It does not prove who is holding it, whether that person still has valid training, whether their contractor documentation expired last week, or whether they are authorised for the zone behind the door. Most sites discover the gap during an audit, when the log shows an entry nobody can account for.

SmartX HUB treats entry as a compound decision. RFID access control gives you fast, reliable credential reads at scale; facial recognition confirms that the person at the door is the person the credential belongs to; and the platform checks documentation, training and zone permission in the same moment. Because people are one of the object types on the shared enterprise platform record, that check draws on the same identity used by tracking, safety and compliance rather than a separate door database.

How It Works

The Entry Decision, Step by Step

In an RFID access control deployment these four checks run as one transaction. If any of them fails, access is refused with a specific reason rather than a generic denial, and the event goes to the alert centre for review.

01
Identify

An RFID or NFC credential, a QR pass or a camera resolves the person against the workforce, contractor and visitor register. Facial recognition returns a confidence score rather than a silent yes.

02
Validate

Credential status, induction, certifications, medical or contractual documents and their expiry dates are checked. An expired document blocks entry before it becomes an audit finding.

03
Authorise

Access rules decide whether this identity may enter this zone, at this time, under these conditions. Rules can be scoped per site or zone, so a multi-site deployment stays readable.

04
Record

Each attempt is stored as a session with the detail behind it, not just a pass or fail flag, so a disputed denial can be reviewed afterwards against what was actually evaluated.

Two Ways In

Credentials and Faces, on the Same Rules Engine

Sites rarely need one method everywhere. A perimeter turnstile handling thousands of movements a day has different requirements from a controlled store room. Both run against the same identity register and the same access rules, so a permission change applies once and takes effect at every door.

RFID, NFC and QR credentials

Fast, hardware-agnostic credential reads for high-traffic entrances, vehicle gates and equipment rooms, built on open GS1 EPC identification standards rather than a proprietary card format that locks you to one supplier.

  • UHF RFID badges, NFC cards, printed QR passes and mobile credentials
  • Works hands-free at range for gates, forklifts and vehicles
  • Badges double as tracking tags, so presence and mustering come free
  • Instant revocation when a credential is lost or a contract ends

Facial recognition terminals

Camera-based identification for entrances where a badge can be shared, forgotten or handled with gloves on. Recognition is backed by a real enrolment and device-synchronisation pipeline, which is what makes it dependable across dozens of terminals rather than impressive in a single demo.

  • Enrolment captures several reference images per person, tied to the same identity used everywhere else
  • A sync queue pushes enrolments to terminals, with queue health, batch sync and a full sync log
  • Terminal keepalive shows which doors are online and current, with remote reset for decommissioning
  • Optional protective-equipment check at the same gate, so identity and readiness pass together
Biometric data stays under your governance

Facial recognition is only appropriate where enrolment is informed and consented, and where retention is defined up front. Enrolment is a deliberate, role-restricted action; face data belongs to the tenant and is isolated from every other tenant; and for organisations that cannot let biometric data leave the premises, the platform can be deployed on site so recognition runs locally rather than through an external service. Where biometrics are not appropriate at all, credential-based entry covers the same rules without them.

Credentials and Compliance

Manage the Credential, Not Just the Door

Most RFID access control problems are administrative rather than technical. A contractor finishes a job and keeps a working badge. A certification lapses and nobody notices until an inspection. A visitor is registered at reception and never checked out. Credential lifecycle management closes those gaps by making issue, validity, permission and revocation properties of the person record rather than settings buried in a door controller.

Employees and credentials

Issue a badge or enrol a face against the workforce register, assign zone permissions by role and department, and revoke in one action when someone changes function or leaves.

Permissions follow the person, so the same rule set governs every terminal at every site.

Contractors and documents

Prequalification, induction, insurance, licences and training certificates are stored with their expiry dates and checked at the gate. An expired document blocks entry automatically and notifies the responsible owner.

Pairs naturally with onboarding and orientation and training records.

Visitors and escorts

Pre-registration ahead of arrival, a temporary credential valid for a defined window, a named host, an explicit list of permitted zones, and a check-out that actually closes the visit.

Anyone still on site at end of day appears on the open-visit list instead of disappearing into a paper book.

Alarms and Exceptions

Every Refusal Has a Reason, and a Route to Someone

A denial that nobody sees is a denial that nobody fixes. Access exceptions feed the platform alert engine, which routes them by rule, escalates when unacknowledged and suppresses repeats of the same condition so the security team is not clearing the same event a hundred times.

Identity not recognised

Someone unenrolled at the terminal, or a confidence score below threshold. Caught immediately rather than silently allowed through.

Documentation expired or missing

A lapsed certificate, induction or permit. The alert goes to the document owner as well as the gate, so the fix starts straight away.

Zone not authorised

A valid person at the wrong door, or outside their permitted hours. Repeated attempts on the same restricted zone are worth a supervisor's attention.

Terminal offline or tampered

A door that stops reporting is a control gap. Keepalive monitoring and tamper detection surface it before anyone relies on a reader that is not there.

Alerts are delivered across email, messaging, SMS, push, in-app streaming and outbound webhooks, with escalation groups, per-rule cooldown and bulk acknowledge so a shift handover does not begin with several hundred unread notifications. Serious events can open an incident record with root cause and corrective action attached.

Connected to the Platform

The Same Identity, Everywhere Else on Site

Because access runs on the shared people record, the badge that opens the door is also the badge that counts heads during an evacuation and confirms who is holding which equipment. Click any capability to explore the solution behind it.

The Technology

Whichever Identification Fits the Door

RFID access control suits high-traffic gates and vehicle entrances; short-range technologies suit controlled rooms; wide-area coverage suits remote or outdoor sites. Mixing them on one site is normal, and all of them resolve to the same person record.

Governance and audit
  • Twelve role profiles with group data filters and field-level access
  • Two-factor authentication and single sign-on, including directory and enterprise identity providers
  • Tamper-evident audit log with retention policy and export for external security monitoring
  • Multi-tenant isolation, so one organisation never sees another's identities
  • Cloud, on-premise or private cloud deployment, chosen for residency and policy

Close the Gap Between the Badge and the Person

Bring one entrance, one contractor population and your current access log. We will show what a verified entry decision looks like when identity, documents and zone rules are checked together.

FAQ

Access Control — Common Questions

Answers to the questions security, operations and compliance teams ask most when evaluating credential and biometric entry control with SmartX HUB.

What is RFID access control, and how is it different from a traditional badge system?
A traditional badge system compares a card number against a list held in a door controller and opens or refuses. RFID access control in SmartX HUB reads the credential the same way, but the decision is made against the shared person record: credential status, document validity, training, zone permission and time window are all evaluated together. The practical difference shows up in administration. Revoking access is one action on the person, not a change repeated across every controller on site.
Do we have to use facial recognition, or can we run credentials only?
Credentials alone are a complete configuration: RFID access control on its own covers the full rule set. Many sites use badges everywhere and add facial recognition only at a handful of entrances where credential sharing is a real risk, or where gloves and protective equipment make handling a card impractical. The rules engine is the same either way, so you can start without biometrics and introduce them later at specific doors without reworking permissions.
How is biometric data stored and protected?
Enrolment is a deliberate, role-restricted action rather than something that happens passively, and it belongs to the tenant under multi-tenant isolation, so no other organisation can reach it. Access to the enrolment screens is governed by the same role profiles, two-factor authentication and audit logging as the rest of the platform. For organisations that cannot allow biometric data to leave their premises, the platform can be deployed on site so recognition runs locally. Consent, notice and retention periods are decisions your organisation makes and configures, and we recommend agreeing them before enrolment begins rather than after.
How does document and certification validation work at the gate?
Documents are held against the person with their type, issue date and expiry, and access rules can require specific ones for specific zones. When a certificate lapses, the person stops satisfying the rule automatically rather than relying on someone remembering to remove them from a list. Expiry alerts go out before the date, so the usual outcome is a renewal rather than a refused entry. This is the same document layer used by onboarding and training and certification.
Can we manage visitors and contractors as well as employees?
Yes, and they are usually where the value shows first. Visitors can be pre-registered before arrival with a named host, a temporary credential valid for a defined window and an explicit list of permitted zones, plus a check-out that closes the visit. Contractors carry a document set with expiry control, induction status and zone permissions, so the gate enforces prequalification instead of assuming it. Anyone still on site at the end of the day appears on an open list rather than in a paper book.
What happens if a terminal goes offline?
Each terminal reports a keepalive, so a device that stops responding is surfaced as an alert rather than discovered later. Administrators can see which terminals are online and current, retry or clear a stuck enrolment synchronisation, and reset a device remotely when it is being replaced or decommissioned. Whether a specific physical door should fail secure or fail safe is a site design decision, agreed during commissioning alongside fire and evacuation requirements rather than assumed by the software.
How do access alarms reach the right person?
Access exceptions feed the platform notification engine, so routing is a rule rather than a hard-coded recipient. Alerts can go to email, messaging, SMS, push, in-app streaming or an outbound webhook into your own systems, with escalation groups when nobody acknowledges, per-rule cooldown so a repeating condition does not spam the team, and bulk acknowledgement for routine clearing. Serious events can open an incident record with corrective action tracked to closure.
Does it work across multiple sites with different rules?
Access rules and their monitoring views can be scoped to specific sites or zones, so a reviewer at one location is not looking at every event from every location. The person record stays central, which means someone transferring between sites keeps one identity and one document set instead of being enrolled twice. Site, area and zone hierarchy is configured once and reused by tracking, safety and access alike.
How does access control support an evacuation?
Entry and exit events give a live count of who is on site, which is exactly what a muster needs. Instead of a supervisor working from a clipboard, the roll call starts from a current list and highlights who has not yet been confirmed at the assembly point, so effort goes to the people still to be accounted for. It works alongside emergency roll call and emergency preparedness, and drill results are recorded the same way as live events.
How does this fit with the other SmartX HUB solutions?
Access control governs the boundary: who may cross it and under what conditions. Real-time location covers what happens after the door, staff workflow turns that movement into operational insight, staff duress protects people once inside, and environmental monitoring watches the conditions of the space itself. They are complementary rather than overlapping, and all of them run on the same record described on the enterprise platform page. To see the combination on your own site, book a demo.
error: Content is protected !!