top of page
solomons-facilities-management-logo.jpg

How to Implement Access Control in London Buildings

  • Writer: Solomons FM
    Solomons FM
  • 2 days ago
  • 12 min read

A contractor leaves a London office building, but their fob still opens the staff entrance. A delivery driver finds a propped fire exit and reaches the service corridor without speaking to reception. Later, the facilities team needs to establish what happened, but the access records are incomplete and no one can link the visitor, credential, and door event with confidence.


This is why learning how to implement access control isn't mainly a question of choosing readers and locks.


A secure building needs hardware, documented permissions, visitor procedures, trained personnel, reliable records, and a joiner-mover-leaver process that removes access when circumstances change.


UK guidance frames perimeter access points as needing physical or electronic control, while access control systems can govern one door or, through Automatic Access Control Systems (AACS), multiple doors across one or more sites.


UK government physical and electronic security guidance also supports the wider operational model of deterring, detecting, and delaying unauthorised activity.


Table of Contents



Why Access Control Demands More Than Door Hardware


The visible gap is usually an operational gap


A new reader at the main entrance may look reassuring while leaving serious weaknesses untouched. If a departing contractor's fob remains active, the building still recognises a credential assigned to someone who should no longer have access. If reception issues temporary badges without recording their return, an audit may show an authorised event without identifying who carried the badge.


The same failure occurs when electronic locks are installed while fire exits, loading bays, lift permissions, and contractor routes sit outside the design. A control room can support deter, detect, and delay, but only if staff respond to alerts and the rules match how the building operates.


Build the control around the identity lifecycle


Physical access begins with a person, organisation, or defined visitor purpose.


Give each regular user a unique identity, approve permissions through a documented process, and grant only the areas and times required for that role. System administration rights and unrestricted master permissions require senior approval, separation from routine access, and scheduled review.


A workable process gives each action a named owner:


  • Human resources or the contract owner starts the request for a new starter, mover, contractor, or leaver.

  • The line manager or tenant representative confirms the person's role and required zones.

  • Facilities or security administration provisions the credential and records the approval.

  • Reception or the security team manages visitors, temporary badges, and exceptions. Where guarding duties apply, staffing and procedures must also account for SIA-licensed personnel.

  • The system owner reviews audit records and removes obsolete rights.


This joiner-mover-leaver record should match the physical credential, door permissions, visitor record, and approval trail. Otherwise, a technically accurate access log may still fail to explain whether the right person entered.


The full implementation journey


For organisations handling personal or special category data, the Information Commissioner's Office access control guidance calls for documented policies, recorded staff access rights, monitored visitors, access logs, audits, and prompt removal of leavers' permissions.


Assessing Your Site and Defining Security Zones


Start with a drawing and a walk-through. Mark every external entrance, vehicle route, loading area, reception point, lift lobby, stairwell, plant room, roof access point, data room, tenant suite, and residential private area. Then divide the building into zones based on consequence and movement, rather than copying the existing floor plan.


Map the movement from public to critical


A useful London building model has distinct layers:


  1. Perimeter zone, including street-level entrances, gates, loading bays, and external plant.

  2. Entrance zone, covering turnstiles, speed gates, intercoms, and the first controlled door.

  3. Lobby and reception zone, where visitors are identified, registered, and directed.

  4. Internal working or residential zones, including tenant floors, common corridors, lifts, stairwells, and shared facilities.

  5. Critical asset zone, such as server rooms, control rooms, archives, executive areas, or sensitive plant.


A diagram illustrating five security zones in a multi-story building, from perimeter control to internal critical assets.

For each zone, record who uses it and under what conditions. Permanent staff may need predictable access during working hours. Cleaning teams may need time-limited access after occupancy periods. Contractors may need a named host, a work order, and an escort. Delivery personnel generally need a controlled handover point rather than unrestricted movement through the building.


Match controls to risk and building type


A financial office near Canary Wharf may need stronger identity assurance for a trading floor or technology room than for the general office floor. A Shoreditch co-working building may prioritise flexible mobile credentials, rapid changes for hot-desking members, and simple administration across shared meeting spaces. Neither building should automatically receive the same reader at every door.


Residential buildings need a separate analysis. Resident access should be distinct from cleaning, maintenance, estate-agent, and short-term-let access. Property managers should decide how platform-managed visitors, including guests associated with Airbnb-style arrangements, are authorised, where they collect credentials, and whether access expires automatically. A resident's convenience shouldn't override the need to keep private corridors and service areas separated.


Survey what the doors will permit


Technology choices are constrained by the building itself. Inspect door types, hinges, closers, locks, panic hardware, glazing, wall construction, available risers, network routes, power supplies, and fire escape arrangements. Check whether listed-building consent or landlord approval may be needed before altering common areas or visible entrance features.


Document current pain points and incidents while they're still clear:


  • Uncontrolled doors: Note doors that are routinely wedged open or bypassed.

  • Credential problems: Identify lost cards, shared fobs, forgotten temporary badges, and duplicate records.

  • People-flow issues: Record queues, delivery congestion, resident complaints, and accessibility barriers.

  • Investigation gaps: Establish whether the team can link a person, credential, door, time, and response.

  • Operational constraints: Capture shift patterns, reception cover, cleaning windows, and contractor access.


The Archives Association security guidance supports using electronic access control where possible because it makes access management auditable and restrictions easier to apply. Smaller or lower-risk venues may still use locks, signage, ropes, or push-button combination locks where a full system isn't justified.


Choosing the Right Access Control Technology


No single credential works everywhere. Card and fob systems remain familiar, easy to issue, and practical for many offices and residential entrances, but users can lose them, lend them to others, or leave them active after a change in role.


Mobile access can reduce physical credential handling and support remote provisioning, yet it depends on phone availability, battery power, compatible devices, and user acceptance.


Biometric readers provide stronger assurance that the enrolled individual is present, which can suit high-security rooms. They also introduce more demanding enrolment, privacy, fallback, and data-governance questions. Facial recognition and fingerprint processing need a clear lawful basis and careful handling of personal data. A PIN can provide a useful second factor or fallback, but shared codes weaken accountability and need controlled administration.


Turnstiles and speed gates work well in high-volume commercial lobbies where the entrance layout supports them. They need floor space, tailgating controls, emergency-release arrangements, and accessibility planning. A turnstile isn't a substitute for reception, especially where visitors, deliveries, and people with mobility requirements use the same approach.


Technology

Typical Cost per Door

Security Level

Maintenance Burden

Best Suited For

Proximity card or fob

Varies by door condition, cabling, and controller design

Moderate, stronger with individual credentials and audit review

Low to moderate, with credential replacement and reader checks

Offices, residential entrances, shared internal doors

Mobile BLE or NFC credential

Varies by platform, reader, and software subscription

Moderate to high when identity administration is disciplined

Moderate, with app support, device changes, and user assistance

Co-working, serviced offices, flexible tenant environments

Biometric reader

Varies substantially with reader type, privacy controls, and enrolment requirements

High for selected restricted areas

Moderate to high, including enrolment, cleaning, calibration, and fallback management

Critical rooms and sensitive operational areas

Turnstile or speed gate

Varies with lane design, integration, and building works

High for controlled lobby throughput, subject to anti-tailgating measures

Moderate to high, with moving parts and emergency-system testing

City offices, multi-tenant commercial lobbies, controlled staff entrances


The table is a procurement framework, not a price list. Door condition, power, network architecture, fire strategy, lift integration, and building approvals can matter more than the reader itself. A card system may be the sensible choice for a residential block, while mobile credentials suit a flexible workspace where membership changes frequently.


Integration deserves its own line in the specification. Confirm whether the platform can connect with lift controls, intercoms, visitor management, CCTV events, intrusion alarms, and the building management system.


For related surveillance planning, facilities teams can review CCTV monitoring services as part of the wider security design, rather than treating cameras and doors as unrelated purchases.


Integrating Reception and Visitor Management With SIA Compliance


A visitor can pass reception with a valid name and appointment, then reach a restricted floor without anyone confirming the destination. That failure sits between door hardware, reception practice, and identity governance. Before a guest moves beyond reception, the process should establish who they are, whom they are visiting, where they may go, and when their permission ends. The reader records the event, while staff give it operational meaning.


Pre-registration suits offices with predictable meetings. The host submits the visitor's details, reception verifies arrival, and the system issues a badge or temporary credential with a defined area and expiry. Walk-ins need a documented exception process rather than an informal wave-through. Delivery drivers should use a designated handover route. Contractors should be linked to a work order, responsible host, and site safety requirements.


A flowchart showing the four-step process for visitor management integration with SIA-compliant security procedures.

Decide what people must do


A digital visitor platform can manage invitations, sign-in, badge printing, host notifications, and departure records. It cannot independently assess a suspicious visitor, challenge tailgating, control an agitated crowd, or take charge during an alarm. The operating plan must assign those responsibilities to named roles, with escalation routes that staff can follow during a busy reception period.


ProtectUK guidance on crowded places stresses escorting visitors and contractors where appropriate. In a London commercial lobby, reception may complete the initial identity check while an SIA-licensed officer monitors the entrance, CCTV, alarms, and escalation route. The right staffing model depends on the site risk assessment, contract scope, opening hours, and work being carried out.


Map every front-of-house duty against Security Industry Authority requirements. A concierge helping tenants may have a different role from a guard enforcing access or responding to incidents. Record the distinction, provide the required licence and training, and check the position before assigning unlicensed staff to access-critical work. The same review should cover joiners, movers, and leavers. A new starter needs an approved credential, a transferred employee needs revised permissions, and a departing worker needs access removed without waiting for the next manual review.


Keep the data useful and proportionate


Visitor records contain personal information. The ICO access control checklist supports monitored visitor access, recorded rights, access logs, audits, and formal provisioning for staff and third-party contractors. Define the purpose of each field, who may view it, how long records are retained, and how staff handle data-subject requests or incidents.


The access platform should exchange only the information needed to create and control a temporary permission. Reception should not have unrestricted access to unrelated tenant records, and a contractor badge should not remain active because a host forgot to close the visit. Automatic expiry, access-log entries, and departure reconciliation provide a clearer audit trail than a handwritten sticker.


For the wider operating model, review visitor management systems where reception, security, and tenant administration need a shared record. The goal is a traceable chain from invitation and identity check to permitted door, responsible host, SIA-licensed intervention where required, and final deactivation.


Planning Deployment From Survey to Handover


Good deployment planning protects the building's normal operation. A door survey should produce more than a list of readers. It should identify the lock type, escape route, fire interface, power requirement, network route, access group, user population, and test method for every controlled opening.


Use controlled project stages


Survey and risk assessment come first. Confirm the zones, doors, users, incidents, existing equipment, and operational constraints. Include the fire strategy team and, where relevant, the lift, alarm, IT, landlord, and managing-agent representatives.


Design and approvals turn that information into a door schedule, system architecture, wiring plan, credential policy, and integration specification. Central London listed buildings may require consent for visible alterations. Multi-tenant properties often need landlord approval for common-area works, and residential sites require clear communication about temporary disruption.


Procurement and installation should be sequenced around occupancy. Install a representative door or zone first, test it with the actual lock and reader combination, then proceed door by door. Coordinate cabling with other trades, protect fire-rated assemblies, and don't allow installers to leave doors unsecured between shifts.


Configuration and testing must cover every credential type, access schedule, restricted area, alarm condition, lost-card process, visitor expiry, lift permission, and emergency release. Test normal operation and failure modes, including power loss, network interruption, forced-door alarms, and fire-system interaction.


A flowchart showing the six-step project management deployment process from initial site survey to final system go-live.

A phased programme can be organised across survey, design, installation, configuration, training, and go-live. The precise duration depends on site scale, approvals, door complexity, procurement, and working-hour restrictions. Don't promise a fixed programme until the survey has exposed those dependencies.


Make user acceptance testing operational


Facilities teams should test the system as they will use it, not merely confirm that a reader beeps. Create test scripts for a new starter, a mover, a leaver, a temporary worker, a contractor, a visitor, a lost credential, and an emergency responder. Ask reception to issue and close visits, ask security to investigate an alarm, and ask the system administrator to produce an access report.


The installation isn't ready for sign-off until the team can perform those actions without relying on the installer's laptop or personal knowledge. Record defects, owners, retest results, and outstanding risks.


The project handover should include:


  • As-built information: Door schedules, wiring routes, controller locations, reader types, and interfaces.

  • Credential records: User groups, active credentials, temporary permissions, and administrator accounts.

  • Operating procedures: Lost credentials, visitor exceptions, forced doors, alarms, outages, and emergency access.

  • Training evidence: Attendance, administrator competence, reception instructions, and escalation contacts.

  • Maintenance information: Warranty details, support routes, firmware responsibilities, replacement parts, and inspection requirements.


The implementation team should also provide a clear route for future changes. If facilities staff can't add, amend, audit, and revoke permissions independently, the building has bought a dependency rather than a manageable control.



Maintaining Systems and Auditing Access Rights


The difficult work starts after installation. Staff change departments, contractors finish projects, tenants move suites, and temporary credentials remain active unless someone removes them. A reader can keep working while the permission model becomes inaccurate.


Make access reviews part of normal administration


Access-rights audits, access-attempt logs, controlled provisioning, and prompt removal for leavers should sit within the building's normal administration. Add these tasks to the facilities calendar and connect them to HR, tenant, and contractor notifications. That gives joiner-mover-leaver governance a practical connection to the doors, readers, and credentials installed on site.


Each approver should confirm:


  • Current role: Does the person still work for the organisation or supplier?

  • Required zones: Does the permission match the person's present duties?

  • Time condition: Should the credential work outside normal hours?

  • Credential status: Has a card, fob, mobile identity, or PIN been lost or shared?

  • Administrative privilege: Does the user still need high-level system access?

  • Temporary records: Are contractor and visitor permissions closed?


Frequent staffing changes call for event-driven revocation, not only an annual review. Revoke access when someone leaves or changes role, then schedule periodic checks of the full permission set. SIA-licensed security staff can support exception handling and incident follow-up, but facilities or system administrators must retain clear approval and audit responsibility.


Maintain the physical and digital layers


Readers, locks, request-to-exit devices, door contacts, batteries, controllers, network links, backup power, and emergency interfaces need planned inspection. The maintenance schedule should name the responsible person, define failure conditions, record the remedy, and set the escalation time.


Keep records that support incident investigation and internal assurance. Log access attempts, forced-door alarms, lost credentials, visitor exceptions, administrator changes, and system outages. Retire old cards, fobs, PINs, and controllers through a controlled process. Remove them from active databases rather than leaving them in a drawer.


A clean access database is a security control. It shows who should enter each zone, which approval supports that permission, and when the organisation must review or revoke it. That evidence links daily door operation to accountable identity management.


Building a Long-Term Access Governance Strategy


Access control should sit inside the building's operating model, alongside fire safety, contractor management, reception procedures, and maintenance. An integrated facilities management approach can help define how security, reception, concierge, cleaning, and building operations share responsibilities without blurring accountability.


Assign a named access-control owner. Give that person authority to approve standards, maintain the door schedule, coordinate with HR and tenant representatives, review audit reports, and escalate unresolved risks. Make joiner-mover-leaver actions part of the normal onboarding and offboarding workflow, including temporary staff and third-party contractors.


A durable governance checklist includes:


  • Named ownership: One accountable facilities or security lead.

  • Documented permissions: Role-based access with recorded approvals.

  • Visitor control: Pre-registration, identification, escorting where required, badge issue, and closure.

  • Licensed staffing: Clear role definitions and SIA compliance checks.

  • Regular assurance: Access reviews, incident reporting, maintenance records, and administrator review.

  • Planned refresh: Replacement decisions based on supportability, risk, integration, and building changes.



Solomon's Facilities Management provides SIA-licensed security, reception and concierge staffing, visitor management, CCTV monitoring, patrols, and incident logging for London commercial and residential buildings. To connect your door hardware with accountable day-to-day access governance, visit Solomon's Facilities Management and discuss your site requirements with the team.


Comments


290b12_d6b14ae5707b49d1b85231d152625b37~mv2.jpg

SOLOMON'S FACILITIES MANAGEMENT

Get a quote for security guards or FM services in London — free, within 24 hours

SOLOMON'S FACILITIES MANAGEMENT

Social Media Accounts

bottom of page