A key cannot tell you who opened the door at 2am, and cannot be switched off

Most businesses do not lose keys. They lose track of them. The cleaner’s key from four contracts ago, the spare in the drawer at the front desk, the one the last shop foreman never handed back.

About this piece

  • Article
  • Security & surveillance
  • Written by Nicholas Backwell · Founder, Redsilicon
  • Updated 2026-08-24

Every one of those still works, and none of them leaves a record. That is the case for an access control system in a small business, and it has almost nothing to do with technology.

The short version

  • A key opens a door and tells you nothing. There is no record of who, and no record of when.
  • You cannot cancel a key. You can only rekey the lock, which means new keys for everyone who was fine.
  • Fobs, cards and phone credentials can be deleted in seconds, from anywhere, by whoever runs your office.
  • The hardware on the door decides what happens in a power cut, and that decision is made at install, not later.
  • Door events make a rough time record for free, and a rough one is often better than the paper sheet you have now.

What a key actually costs you

Rekeying a building is the punishment for one lost key. Every cylinder gets pinned again, every staff member gets a new key, and somebody has to hand them out and chase the stragglers. Most owners look at that, decide the risk is tolerable, and do nothing. That is a reasonable call once. Made five times over ten years, it means your building is open to a set of people you can no longer name.

The second cost is quieter. When something goes missing on a Sunday, a key system gives you nothing to work with. You have a list of everyone who might have had access and no way to narrow it. Cameras can show you a person at the door, and a door log can tell you which credential opened it. Together they answer the question. Separately, each gets you halfway.

Fobs, cards and phones

All three do the same job: present something the reader recognises, the reader asks the controller, the controller decides. The differences are practical.

CredentialGood atWatch out for
Fob on a keyringCheap, tough, staff already understand itGets left in a coat, shared between people, easy to clone if the technology is old
CardDoubles as photo ID, easy to print and replaceSnaps, delaminates, ends up under a car seat
Phone credentialNothing to hand out, nothing to collect, issued and revoked remotelyDepends on staff phones and battery, needs a reader that supports it

Two notes worth more than the table. First, older proximity technology from the 1990s is still widely installed and can be copied by a device that costs less than lunch. If you are buying new, ask specifically what technology the credentials use and whether they are encrypted. Second, phone credentials sound like the modern answer and are genuinely convenient, but a shop floor where people wear gloves and leave phones in lockers may run better on fobs. Pick against the work, not the brochure.

Whatever you pick, the thing that matters is that removing someone takes one action in one place. That is the entire difference from keys.

The door is the hard part

The reader gets the attention. The door hardware is where the money and the mistakes are.

An electric strike replaces the plate the latch drops into, so the door can be pushed open while the lock stays engaged. It suits most timber and hollow metal doors and it is the common answer.

A magnetic lock is a plate and an electromagnet that holds the door shut with a lot of force. It suits glass doors and gates where there is nothing to strike into. It also holds the door shut absolutely, which is why fire code cares about it.

Around either of those you need a way to get out. A request-to-exit sensor or a push bar tells the system that someone leaving is not a forced door. Without it, every exit looks like a break-in and you learn to ignore the alerts.

You also want a door position switch, which is the small magnet contact that says whether the door is actually shut. That is what catches the real problem in most buildings: the back door propped open with a fire extinguisher on a warm afternoon.

What happens when the power goes out

This is the question to ask before anything gets ordered, because the answer is physical.

Fail-secure hardware stays locked when power is lost. You cannot badge in, and you can still push the bar and walk out, because the exit side is mechanical.

Fail-safe hardware unlocks when power is lost. Magnetic locks are fail-safe by nature. Cut the power and the door is open.

Most sites end up with a mix, decided door by door. A server room or a drug cabinet is fail-secure, because an unlocked door in a blackout is worse than a locked one. A main entrance on a maglock is fail-safe by necessity. Battery backup on the controller keeps the system running through short outages either way, and the batteries are a consumable, so somebody has to remember them.

Fire code decides some of this for you

Locks on a door people escape through are not just your decision. Under the Ontario Building Code and the Ontario Fire Code, doors in an exit route have to let people out without keys, tools or special knowledge, and electrically locked doors are normally required to release when the fire alarm sounds.

In practice that means an interlock between the fire alarm and the locks, plus manual release hardware where the inspector wants it. Your local fire inspector is the authority having jurisdiction and their reading of the code is the one that counts. Ask before you install, not after. It is much cheaper to add a release device during the job than to retrofit one after a failed inspection.

Time and attendance, almost for free

Every badge read is a timestamp with a name on it. That is not a payroll system and you should not treat it as one, because people hold doors for each other and forget to badge at all.

What it is good for is the argument you cannot otherwise settle. Whether the site was actually opened at 6am. Whether the contractor was there on Thursday. Whether anyone was in the building when the freezer failed. If you run shift work, the log is worth exporting monthly and keeping.

One thing to sort out first: door logs are records about employees. If you have 25 or more employees in Ontario, they belong in your written electronic monitoring policy alongside cameras. Say plainly what you collect and what you use it for, and the whole subject stops being awkward.

What this means for your building

A trades business in Whitby with a shop, a parts room and a yard gate is the standard shape. The shop door goes on a reader because everyone uses it, the parts room goes on a reader because that is where the theft is, and the yard gate stays on a padlock because the gate is a fence panel and running power to it costs more than the risk justifies. That is a sensible mix, not a compromise.

A clinic in Pickering is different. The exterior door matters less than the records room and the dispensary, and the log matters more than the lock, because you may have to show who had access to a file.

What to do about it

  1. Count your keys. Not the keys you issued, the keys you can physically account for today. The gap is the reason for this article.
  2. List every door and mark it: needs a record of entry, needs a lock only, or fine as it is. Most buildings need readers on two or three doors, not all of them.
  3. For each of those doors, decide fail-safe or fail-secure and write down why.
  4. Ask your fire inspector what they expect on your exit doors before you buy hardware.
  5. Decide who administers it day to day. An access control system is only better than keys if somebody deletes a credential the day a person leaves.
  6. Tie it to the rest. Door held open, badge at odd hours and a forced door are all events your alarm system can act on rather than log quietly.

Want this scoped for your site?

Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.

Before you call

Do we have to do the whole building at once?

No, and it is usually cheaper not to. Start with the exterior door everyone uses and whichever internal room holds the valuable or sensitive things. Add doors later as they matter.

Is a keypad enough?

For a low risk internal door, sometimes. Understand that a shared code is a shared key: no audit trail worth the name, and it spreads. If you use codes, give each person their own, and change them when people leave.

We have five staff who have all been here a decade. Do we need this?

Honestly, maybe not. If nobody has left in years, the keys are accounted for and the building holds nothing a locked door would not deter, a good lock and a habit of collecting keys is a fine system. Revisit it when you take on your first contractor with after-hours access.

Will it work if the internet goes down?

The doors keep working. Controllers hold their own copy of who is allowed in. What you lose is remote administration and live notification until the connection comes back.

\n
\n \n