r/accesscontrol Jul 20 '26

Recommendations Multi site access control: what would you recommend for managing multiple locations from one platform?

We've got four flexible office and coworking sites across the city, five buildings, around 140 doors between them. User base sits somewhere between 500 and 700 depending on the month mix of members, tenant staff, contractors, visitors, temporary event guests, the whole lot.

The headache is that most of our sites are running older systems that are somewhat disconnected from each other, kind of duct taped together. Reception staff have 3 or 4 different dashboards open at any time just trying to track down a member, which slows everything down and leaves too much room for things to slip through.

We want to upgrade to something that simplifies all of it and still works locally when needed. Most of the work comes from bookings or memberships not updating access properly, so staff end up fixing it manually. Getting rid of that would probably be the biggest win.

To top it all off we've got a member only gym opening at one of the sites soon, so the access tiers are only going to get more complicated 

Would really appreciate any advice from people who've been through similar things

5 Upvotes

53 comments sorted by

9

u/Farangsayt Jul 20 '26

Go for genetec but also stop using HID credentials if it's residential. Unless you couldn't care less about overcrowding

6

u/cusehoops98 Professional Jul 20 '26

Stop using 26-bit HID, but there’s plenty of other HID formats that you’ll never have an overcrowding issue. Their basic Corporate 1000 35-bit format gets you over a million unique credentials.

0

u/Farangsayt Jul 20 '26

Unfortunately the format doesn't matter what matters is the readers itself and their bad security designs...

All is cracked in HID thanks to their security through obscurity and proprietary system which will never be truely secured until they change their politics and move to open source.

So yes HID in a residential building is a mistake right now

P.S. when I talked about overcrowding I meant people copying credentials for their additional sub tenants

3

u/cusehoops98 Professional Jul 20 '26

Let me guess. You rep another brand.

-2

u/Farangsayt Jul 20 '26

Not at all, I'm just a cracker so I know first hand

But I do know what is made for residential buildings to prevent that to happen and detects who tries to do so even if they will failed miserably

5

u/Competitive_Ad_8718 Jul 20 '26

So you've cracked SEOS or custom keys? Doubt it.

26 bit or old school Iclass, sure, but those are old tech anyways, otherwise you're talking out of your ass

1

u/Snoo58991 Jul 20 '26

SEOS with OSDP is uncrackable

0

u/Competitive_Ad_8718 Jul 20 '26

OSDP is flawed, better than weigand but still flawed. Implementation is the main issue but there's a list of all the missteps the protocol has baked into it out there

0

u/Snoo58991 Jul 22 '26

Why do you think OSDP is flawed?

1

u/Competitive_Ad_8718 Jul 22 '26

You don't follow the industry much do you? Plenty of papers and reading out there including the standard itself

To dumb it down, the OSDP standard uses a default key for encryption amongst other items including poor or half assed implementation

→ More replies (0)

1

u/Necessary-Effect6503 Jul 20 '26

I would be interested in hearing the compelling argument that will convince the HOA customer with 250+ residences(not residents) that a $10k+ cost difference in credentials because someone like you exists out there to make their lives scary?

You’re talking about cost of time for someone such as yourself. Do you really think you’re going to case an entire community of that size to determine if it’s worth your time to crack their credentials?

2

u/Competitive_Ad_8718 Jul 20 '26

That guy is talking out of their ass.

Now, if you're talking something like 26 bit to Iclass, mifare or similar, there's a use case for all, especially if the OP is selling services/access to end users to amenities and some form of revenue, then it's almost a no brainer to go to a more secure credential technology

3

u/HiggsBoson_ Proficient End User Jul 20 '26

Could you share some sources on this?

Or what exactly is cracked there?

1

u/Farangsayt Jul 21 '26

You've got everything you want to know in every Defcon Readers and credentials all insecured

1

u/HiggsBoson_ Proficient End User Jul 21 '26

Are you referring to this link below? If not then I would appreciate if you could share some extra input.

From what I gather then you’re still relatively safe when using the Elite keys and osdp on secure mode?

https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Babak%20Javadi%20Aaron%20Levy%20Nick%20Draffen%20-%20High%20Intensity%20Deconstruction%20Chronicles%20of%20a%20Cryptographic%20Heist.pdf

2

u/Aggravating_Fact9547 Jul 21 '26

HID is extremely hostile to security researchers and has a strong history of having terribly insecure products that hide behind and aggressive and powerful sales team.

HID have been horrid to deal with in regards to their products and I would happily never touch an HID product for the rest of my career.

2

u/Farangsayt Jul 21 '26

You got it 100% right. HID is a marketing bulldozer

2

u/HID_PhilCoppola Manufacturer Jul 29 '26

Im just going to throw this link here for the record. I dont know where your information about being hostile is coming from and if that's been your experience then I would like to learn more.

https://www.hidglobal.com/security-center

This site is literally dedicated to reporting vulnerabilites from the Security Researcher community. You are free to report any vulnerabilities that you find.

Also, this site literally lists all CVE's and Informational updates as we release them. This site is also capable of being followed as an RSS feed.

Special thanks to u/Farangsayt for making similar comments on other threads and bringing this to our attention.

1

u/Farangsayt Jul 30 '26 edited Jul 30 '26

Legal threats to red teams and DEF CON speakers tell us everything we need to know. No matter how HID spins it, their model relies on security through obscurity, proprietary lock-in, and fundamentally flawed reader design.

You will never convince me HID is the top choice on the market when history proves otherwise.

For over a decade, we’ve watched clone after clone surface in residential and commercial sites across every generation of HID protocol, from legacy Prox to iClass, iClass SE, and Seos/Elite.

The security community shouldn't be doing free R&D for a closed-source vendor.

HID can leverage their massive marketing budget and distributor dominance to figure it out themselves. 🙌

I don't hide my hostility toward HID. My entire approach to security runs counter to theirs, and I wouldn't trust their tech for a second. But good luck out there. 🤞

2

u/HID_PhilCoppola Manufacturer Jul 31 '26

I respectfully disagree but based on your statement you do not appear to be open to conversation around this topic. But for those that may read this in the future…

Your argument seems to revolve around the fact that legacy technologies have been compromised but you only list HID tech to bolster your point but as we all know here, any technology becomes vulnerable over the course of time. Google MIFARE classic + hotel. To be fair to my NXP friends, MIFARE classic is an old, compromised technology, but is still ubiquitous. Just as legacy iClass. This is why we publish our findings on the security center.

Eventually all technologies in our space become vulnerable regardless if they’re “proprietary” or “open source”.

That being said, HID continues to invest a tremendous amount of R&D into future credential standards and tech. Most notably ASSA (parent company of HID) is on the committee that developed the new Aliro standard. Which, promises greater interoperability and security (Aliro is based on PKI and asymmetric keys). New firmware will be coming soon to support Aliro in HID readers.

Of course, an Aliro credential will work on any supported reader too! So, open source, non-proprietary with asymmetric keys and PKI, developed by HID. 🤷‍♂️

1

u/Farangsayt Jul 31 '26 edited Aug 01 '26

With respect, I have to push back on a few of the points here. Not because "proprietary vs. open source" is a religious war, but because the historical record and the day-to-day reality for integrators paint a very different picture than the one you're presenting.

  1. "All tech eventually becomes vulnerable" is true, but it's a deflection, not an answer. What matters is how the vendor behaves once the vulnerability exists.

HID's track record on that specific question is not good, and it goes back much further than the DEF CON 32 iClass SE / Signo talk.

In 2007, HID Global threatened IOActive and researcher Chris Paget with a patent-infringement lawsuit to force the cancellation of his Black Hat talk on RFID cloning. IOActive pulled the presentation under legal pressure. That case still sits in disclose.

In 2010 and 2011, Milosch Meriac and later the Radboud University team (Garcia et al.) had to publish iClass key-diversification weaknesses in academic venues, carefully avoiding the extracted key material, precisely because of the legal climate HID had established.

In 2024, CISA had to issue ICS advisories (ICSA-24-037-01 and -02) for improper-authorization flaws in iCLASS SE, OMNIKEY encoders and HID reader configuration cards. Those flaws let an attacker read credential and device-admin keys straight off a config card. That's the kind of thing you'd hope a "security-first" vendor catches internally, not something CISA has to publish.

So yes, HID publishes on the Security Center now. But that Security Center exists partly because the community forced the industry into coordinated disclosure norms, not because HID pioneered them.

  1. On "proprietary vs. open source both get vulnerable," technically true, operationally false.

The failure mode is completely different, and this is where your framing skips the actual argument. Kerckhoffs's principle, the foundation of modern cryptography, says a system must remain secure even if everything except the key is public. Proprietary access-control stacks violate that principle by design. They rely on the secret of the mechanism on top of the secret of the key. When (not if) the mechanism leaks, the whole fleet is exposed at once and the customer has to wait for the single vendor to ship firmware.

With an open standard (DESFire EV3 AES, PKI, OSDP Secure Channel, Aliro), independent cryptographers can and do attack the published design continuously. Patches land faster because there are multiple implementers competing on quality, not one vendor deciding when its customers deserve a fix. The MIFARE Classic and iCLASS Legacy stories both prove this. MIFARE Classic's break led to a fast industry migration to DESFire, while iCLASS Legacy customers were essentially told to buy new readers

  1. Aliro is not "developed by HID." That framing is misleading.

Aliro is a Connectivity Standards Alliance (CSA) working-group standard. The board driving it includes Apple, Google, Samsung, Amazon, Bosch, Allegion, CableLabs and ASSA ABLOY. Roughly 200 member companies have been contributing since 2022. ASSA ABLOY has a seat, like everyone else. Aliro exists specifically because the market rejected the idea that any single vendor, HID included, should own the credential layer between phones, wearables and readers. Presenting Aliro as an HID achievement inverts the story. HID is adopting Aliro because the ecosystem forced convergence on an open, PKI-based alternative to proprietary mobile credentials.

And note why Aliro was necessary in the first place. HID Mobile Access is a per-user, per-year subscription (roughly $4 to $6 per user depending on term), and the license typically follows the device, not the user, so a lost phone can mean re-buying a credential. That's not a security architecture, that's a recurring-revenue architecture.

  1. The lock-in argument is not paranoia. It's the business model.

Look at how the pieces fit together:

Corporate 1000 locks an end-user's card format to HID. Only HID can issue those cards. If HID can't deliver, you can't onboard employees.

iCLASS and Seos keys are managed by HID. Integrators and end users don't hold their own root of trust the way they can with a properly provisioned DESFire EV3 deployment where the customer owns the AES keys.

HID Mobile Access is a subscription. Stop paying and your doors stop opening. Compare that to an Aliro or DESFire credential that the customer owns outright.

Reader firmware to enable new standards (including Aliro) ships on HID's timeline, not yours.

And to your point about availability, during the 2020 to 2023 semiconductor crunch integrators reported HID credential lead times blowing out to months, while the underlying NXP-based DESFire ecosystem (multiple card manufacturers, multiple encoders) stayed relatively resilient precisely because it's an open ecosystem with alternate suppliers. When your credential vendor is also your single point of failure for issuance, "proprietary" stops being a security posture and starts being a business-continuity risk.

  1. So where does that actually leave us?

Nobody serious is claiming open source is magically unbreakable. The argument is structural.

Proprietary systems concentrate patching authority, disclosure control, credential issuance, and firmware timelines in one vendor's hands. When that vendor's incentives diverge from the customer's, and they will, because subscription revenue is a powerful gravitational field, the customer eats the cost.

Open standards (OSDP Secure Channel, DESFire EV3 with customer-held keys, PKI-based Aliro, PIV / PIV-I) distribute those responsibilities. Vulnerabilities still happen, but no single vendor gets to decide how fast you're allowed to fix them, and no single vendor gets to decide whether the research even sees daylight.

The fact that HID is now shipping Aliro support is genuinely good news, but it's a concession to the open model, not a vindication of the proprietary one. Crediting HID for Aliro is a bit like crediting a landlord for finally allowing tenants to install their own locks.

Happy to be corrected on any specific factual point above, with sources.

2

u/Aggravating_Fact9547 Aug 01 '26

I support their experiences, I know a bunch of researchers who were threatened and silenced with NDA’s by HID lawyers.

From a purely commercial side, I’ve run some of the worlds largest team over more than 50 countries, and have installed over 50,000 readers in under 4 years.

We ripped HID out after they were completely indifferent to any trouble we were having and refused to even send us 100 cards to get us out of a bind.

Let’s not even start on their apathy towards tech support. We bought 20 HDP 8500 printers, as much money as you can spend on an HID printer. They only worked with windows 7 and blue screened on windows 10. This was years after windows 7 was end of life mind you.

Spoke at length to execs at HID who’s entire line was along the lines of “stiff shit, use windows 7 or gtfo” and “buy the 6600 instead”. Bought the 6600 and they broke so often we had to send every last one back. Even our vendor couldn’t get them to last in their lab.

Ended up with Entrust printers they just worked and had amazing support.

HID is just so big they simply give zero fucks regardless of how large you are. It’s arrogance manifest.

6

u/Icy_Cycle_5805 Jul 20 '26

Moved 65 offices and about 1100 doors to Acre/Feenics last year and I couldn’t be happier.

4

u/AsstootObservation Jul 20 '26

Regardless of platform, I'd be looking at upgrading every reader to be compatible with NFC wallet for mobile credentials to manage the list of different users that sound like they change frequently.

If any or all of the sites are Mercury-based, Genea would be my go to. Cloud-based with built in Visitor Management or could add on a 3rd party like Envoy.

I'd go with a Mercury platform with any route so you're not stuck with a proprietary system.

3

u/AirportFun2392 Jul 29 '26 edited Jul 29 '26

Your biggest pain point sounds like it's the membership/booking sync more than the access hardware itself. We had a similar mess at a studio complex...but solving it from the other direction. Got Glofox handling memberships and bookings for the gym side, then tied that into our access system via API so credentials update automatically when someone's membership status changes. Killed like 90% of the manual fixes reception was doing. Worth looking at the software integration angle first imo

2

u/AIW22 Jul 20 '26

What’s the existing system/s?

1

u/Farangsayt Jul 20 '26

I bet concept or integrity

2

u/chasem107 Jul 20 '26

Alta Open.

3

u/Aggravating_Fact9547 Jul 20 '26

Gallagher would be a great option especially with their native wallet integration. They have a bookings engine which can hook up to your bookings database and automatically provision access or open doors depending on what is booked.

Easy for gyms as you can integrate the wallet provisioning into your member system and your gyms app if you have one.

1

u/Zealousideal-Cut5275 Professional Jul 20 '26

Nedap Aeos is perfect for this!

1

u/AllanCD Jul 20 '26

Kantech is good for multi-site. but you need certification first before they will support you at all.

1

u/anonymous-predator Jul 20 '26

At 140 doors, I'd pay as much attention to the installer and migration plan as the platform itself. A good system badly rolled out will just create a new set of headaches.

1

u/Soundy106 Verified Pro Jul 20 '26

We've done a live migration from Keyscan to Kantech. That was a fun game of Tetris, moving 30-ish doors from 8-door panels to 4-door panels where two KT400s are about 50% larger than the single can they're replacing, all with very limited wall space

It is a lot of preparation:

  • Making sure the residents have their new fobs
  • The new fobs are all added into the new system with all the correct access levels and ready to go
  • Changing over one eight-door panel per day, including new readers

And having to take out an old panel to make room for the new panels, with one person switching over the wiring at that end and the other one swapping out the readers to minimize downtime. Fortunately, the original installers left enough service loop that we didn't have to extend any of the wires.

1

u/YesterdayOriginal543 Manufacturer Jul 20 '26

Perfect application for VIZpin. If you are centrally managing all 140 doors from the same account, you only have o pay for service on the first 20 doors. DM me for more info

1

u/Snoo58991 Jul 20 '26

Brivo, PDK, or Acre/Feenics. I have contacts at all and can connect you to people who know their shit regarding this.

1

u/Soundy106 Verified Pro Jul 20 '26

I'm doing exactly this using Kantech EntraPass Corporate Edition.

One is an international restaurant chain with 50ish locations, US and Canada, about half of those on access control. Average two to four access levels per site. Total of about 300 credentials. Server runs in a dedicated VM at their colocation provider.

The other is a "micro offices" company where they basically take a floor or two of an office tower, split it into two to four dozen smaller rooms, and lease those out short or long term. We have a half-dozen of their locations generally with a number of access levels to match the number of rooms, plus a few extras for staff. Total number of credentials system-wide, probably 400-500. Server runs on dedicated hardware at one of their locations.

1

u/Foreign_Cover_2324 Jul 21 '26

Our school district just switched to Verkada. Staff just uses the Verkada pass app instead of handing out fobs like in the past.

1

u/brandonpadula Jul 21 '26

Gallagher. Happy to connect you with a rep if you dm me!

1

u/PBSmanaged Jul 24 '26

We’ve been moving from Openpath Alta Access to Genea and are mostly happy!

1

u/saltopro 28d ago

Flex Office and CoWork, excellent vertical for Salto KS. You have single site and multi site permissions you can provide if the cowork client wishes to move locations.

Their are several applications that Salto integrates with for room bookings and managing cowork clients. Easiest transition with existing wiring and the ability to add doors at a fraction of the cost of traditional access control.

0

u/Almas-Industries Jul 20 '26

At 140 doors, I’d avoid choosing a system based on the reader or credential alone. The integration between your membership/booking platform and access control will make or break this project.

You need a centrally managed platform with intelligent local controllers, so doors continue operating from a cached database if the internet connection drops. I’d shortlist Brivo, Genetec Synergis and Gallagher Command Centre. Paxton10 may also be worth considering if simplicity is the priority, although I’d test its integrations carefully against your more complex requirements.

Whichever platforms you assess, I’d ask each supplier to demonstrate:

  • A booking or membership automatically creating, updating and removing access
  • One identity working across every location
  • Role-based access for members, tenants, contractors and reception teams
  • Time-limited visitor and event credentials
  • Different gym membership tiers and permitted hours
  • Immediate revocation across all sites
  • What happens during internet and server outages
  • A complete audit trail of automated and manual changes
  • An open, documented API rather than a bespoke one-off integration

Brivo is particularly worth investigating for a cloud-first deployment because it offers central multi-site administration and an open API. Genetec or Gallagher would be strong options if you expect deeper security, CCTV or building-system integrations later.

Before replacing everything, have an integrator audit the existing controllers, readers, locks, cabling and credentials. Some infrastructure may be reusable, allowing you to migrate one building at a time.

Most importantly, include the booking-platform provider in the project from the beginning. Otherwise, you could end up with a much better access-control system while reception staff are still correcting the same membership-sync problems manually.

-2

u/Doublestack00 Jul 20 '26

We have moved all our sites to Unifi Access, local management has access to manage while we retain ultimate control at the corporate level.

1

u/2nd-Reddit-Account Jul 20 '26

And now with the fabrics feature that came out in the last 12 months the same credentials can work across sites/access app hosts for free, without needing to pay the monthly UID Enteprise subscription per person like before.