Structural boundary
Capture and protect the identity claim
Reader technology and credential keys determine how easily presented data can be copied, replayed, or trusted. In how access authorization decision systems work, inspect credential together with reader; then use door controller to determine whether the mechanism advanced as designed. Retain access rule entry trace before changing controller programming, because a later restore or controller confirmation can otherwise hide the original fault.
- Capture and protect the identity claim begins with a verified credential opening state
- Compare reader against the expected door controller transition
- Preserve access rule before resetting or clearing the door anomaly
- Assign a named door administrator when capture and protect the identity claim does not complete
- Retest credential after corrective work changes the entry safeguarding chain
The acceptance point for capture and protect the identity claim is a reconstructable path from credential through reader, with door controller showing the intended result and access rule identifying the accountable door anomaly.
Primary mechanism
Evaluate entry rule at the controller
The decision combines credential status, opening, schedule, anti-passback, occupancy, and emergency conditions. In how access authorization decision systems work, inspect reader together with door controller; then use access rule to determine whether the mechanism advanced as designed. Retain lock relay entry trace before changing controller programming, because a later restore or controller confirmation can otherwise hide the original fault.
- Evaluate entry rule at the controller begins with a verified reader opening state
- Compare door controller against the expected access rule transition
- Preserve lock relay before resetting or clearing the door anomaly
- Assign a named door administrator when evaluate entry rule at the controller does not complete
- Retest reader after corrective work changes the entry safeguarding chain
The acceptance point for evaluate entry rule at the controller is a reconstructable path from reader through door controller, with access rule showing the intended result and lock relay identifying the accountable door anomaly.
facility-level consequence
Actuate the door-side barrier
A grant energizes or releases hardware for a limited interval without proving that only one authorized person passed. In how access authorization decision systems work, inspect door controller together with access rule; then use lock relay to determine whether the mechanism advanced as designed. Retain door-position switch entry trace before changing controller programming, because a later restore or controller confirmation can otherwise hide the original fault.
- Actuate the door-side barrier begins with a verified door controller opening state
- Compare access rule against the expected lock relay transition
- Preserve door-position switch before resetting or clearing the door anomaly
- Assign a named door administrator when actuate the door-side barrier does not complete
- Retest door controller after corrective work changes the entry safeguarding chain
The acceptance point for actuate the door-side barrier is a reconstructable path from door controller through access rule, with lock relay showing the intended result and door-position switch identifying the accountable door anomaly.
Failure path
Compare command with door state
Position and request-to-exit inputs distinguish normal passage from forced or held-open conditions. In how access authorization decision systems work, inspect access rule together with lock relay; then use door-position switch to determine whether the mechanism advanced as designed. Retain credential entry trace before changing controller programming, because a later restore or controller confirmation can otherwise hide the original fault.
- Compare command with door state begins with a verified access rule opening state
- Compare lock relay against the expected door-position switch transition
- Preserve credential before resetting or clearing the door anomaly
- Assign a named door administrator when compare command with door state does not complete
- Retest access rule after corrective work changes the entry safeguarding chain
The acceptance point for compare command with door state is a reconstructable path from access rule through lock relay, with door-position switch showing the intended result and credential identifying the accountable door anomaly.
authorization decision decision
door door transaction and handle exceptions
Granted, denied, forced, held, offline, and administrative events support door door anomaly handling, investigation, and permission door analysis. In how access authorization decision systems work, inspect lock relay together with door-position switch; then use credential to determine whether the mechanism advanced as designed. Retain reader entry trace before changing controller programming, because a later restore or controller confirmation can otherwise hide the original fault. At an office entrance, a worker presents a credential to the reader. The controller finds the identity active, confirms that the door and schedule are permitted, and briefly operates the lock relay. The door-position switch should then show an expected open-and-close sequence. If the door never opens, the grant was unused; if it stays open beyond the allowed interval, a held-open door anomaly begins; if it opens without a preceding grant or request-to-exit, the door transaction is forced. Local controller entry rule preserves essential decisions during a server outage, then synchronizes events carefully when connectivity returns without duplicating or reordering the audit trail. Life-safety and egress rules constrain door behavior. Access authorization cannot trap occupants, and fire-interface behavior must be engineered for the specific locking hardware and local requirements. Fail-safe and fail-secure describe what a lock does when power disappears; neither label alone establishes a compliant opening. Request-to-exit sensing, latch door supervision, emergency release, and backup power affect the resulting state. Anti-passback can discourage credential sharing, but a missed exit read may also block a legitimate return and require a controlled override. Acceptance testing covers normal grants, denials, forced entry, held doors, controller network loss, power loss, emergency mode, and recovery sequencing.
- door door transaction and handle exceptions begins with a verified lock relay opening state
- Compare door-position switch against the expected credential transition
- Preserve reader before resetting or clearing the door anomaly
- Assign a named door administrator when door door transaction and handle exceptions does not complete
- Retest lock relay after corrective work changes the entry safeguarding chain
The acceptance point for door door transaction and handle exceptions is a reconstructable path from lock relay through door-position switch, with credential showing the intended result and reader identifying the accountable door anomaly.