
Articles / Press
Access Control Site Survey: What to Expect
What Does an Access Control Site Survey Cover?
If you are preparing to replace, expand, or standardize a commercial access control system, the site survey is where assumptions become facts.
A good access control site survey does much more than count doors. It verifies the physical openings, existing hardware, controllers, cabling, network conditions, credential environment, integrations, operating constraints, and other details that determine what the project actually requires.
For an IT Director, Head of Security, Facilities leader, or project owner, that matters because an access control proposal is only as accurate as the information behind it.
What is a commercial access control site survey?
A commercial access control site survey is a structured assessment of the locations, doors, systems, infrastructure, and operating requirements that will affect an access control project.
The goal is to understand the environment well enough to design the right solution and build a realistic scope of work. Depending on the project, the survey may cover one opening, one building, or a representative set of sites in a much larger multisite rollout.
A useful survey should answer questions such as:
- Which doors need controlled access?
- What locking hardware is already installed?
- Are the doors and frames in good working condition?
- What readers, panels, controllers, power supplies, and batteries exist today?
- Can any existing equipment reasonably be reused?
- What cabling is available?
- Where will network connectivity come from?
- How are credentials managed today?
- Does the organization need cloud, on-premises, or hybrid management?
- What video, identity, HR, visitor, alarm, or other integrations are required?
- What happens during an internet, WAN, or power outage?
- Are there opening-specific egress, fire-rating, or life-safety requirements that need coordination?
- How will installation affect normal business operations?
The survey is not the final design by itself. It gives the design team verified information to work from.
Why should an access control site survey happen before the final project scope?
Access control touches too many parts of a building to scope accurately from a spreadsheet alone.
Two doors that look identical on a floor plan may require different work. One may already have compatible electrified hardware and usable cabling. The other may have a mechanical issue, an unsupported reader, no pathway for new cable, a fire-rating consideration, or a different egress configuration.
The same problem appears at the system level. A company may describe its existing environment as “the same system at every office,” only to discover that different locations were installed at different times with different panel generations, credential technologies, power supplies, firmware, and door hardware.
That is why a preliminary conversation can establish direction, but a verified site assessment is often necessary before a complex retrofit scope becomes final.
What should you prepare before the access control site survey?
You do not need a perfect set of records before calling an integrator. If your documentation is incomplete, finding out what is missing is part of the process.
Still, anything you can gather in advance makes the survey more productive.
Useful information may include:
- Building floor plans
- Door schedules
- Existing access control drawings
- Panel and controller lists
- Reader models
- Locking hardware records
- Current credential types
- Network diagrams
- IP addressing or segmentation standards
- Existing video surveillance platform
- Identity provider or directory platform
- HR system used as an employee source of truth
- Current access groups or permission structure
- Known service problems
- Planned renovations
- Construction schedules
- Sites expected to open or close
- Existing support or maintenance records
For a multisite company, a location list is especially useful. Include the site type, approximate door count, operating hours, region, and whether each location appears to use the same or a different access control platform.
Do not delay the conversation because some of this is missing. A strong integrator should help identify what needs to be documented next.
What does the integrator look at first during an access control survey?
The best starting point is the business problem, not the reader on the wall.
Before walking doors, the project team should understand why the organization is considering a change.
Common drivers include:
- An aging or unsupported access control platform
- Inconsistent systems across multiple locations
- Difficulty managing users remotely
- Too many manual onboarding or offboarding steps
- Shared door codes
- A need for better audit history
- Expansion into new facilities
- An acquisition that introduced another security platform
- Repeated hardware failures
- Cybersecurity concerns
- A need to connect access events with video
- A desire to move away from local servers
- A need for mobile credentials
- Poor post-sale support from the existing provider
That conversation changes the survey.
If the main problem is multisite administration, the survey needs to document differences between locations. If the problem is cybersecurity, the architecture, reader communication, software lifecycle, remote-support path, and administrative controls deserve more attention. If the business is opening ten new locations, repeatability and construction coordination become critical.
A survey should be driven by what the company is trying to fix.
How are the physical doors evaluated?
A commercial access control system depends on the physical opening working correctly.
During a survey, the integrator may document:
- Door and frame type
- Door condition
- Alignment
- Latching
- Closer operation
- Existing strike, lock, electrified trim, maglock, or other locking hardware
- Door position switch
- Request-to-exit or other egress-release components
- Panic or exit hardware where present
- Power transfer hardware where applicable
- Automatic operator where applicable
- Fire rating where known
- Existing keying or mechanical override requirements
- Reader location
- Accessibility considerations that affect the opening
This part of the survey matters because access control cannot fix a door that does not reliably close or latch.
A new reader on a badly aligned door can produce a new-looking system with the same old service call.
Life-safety and code note
Electronic access control must be designed around safe, code-compliant egress. Requirements can vary by opening, occupancy, lock type, fire rating, locally adopted code, and the Authority Having Jurisdiction.
The International Building Code’s means-of-egress requirements include specific provisions for electrically locked and access-controlled doors. A site assessment can identify conditions that require coordination, but it is not a code approval. Final hardware and release behavior should be coordinated with the applicable code requirements, the AHJ, and the relevant fire-alarm, door-hardware, electrical, and building teams.
What existing access control equipment is documented?
The survey should create a clear picture of the current system.
That may include:
- Access control software
- Server or cloud platform
- Controllers
- Interface boards
- Readers
- Credentials
- Electric strikes
- Electrified locks
- Request-to-exit devices
- Door-position switches
- Power supplies
- Backup batteries
- Network switches or connections serving the security system
- Cellular equipment where used
- Gateways or hubs for wireless lock systems
- Enclosures
- Cabling
Photos are useful because model numbers and field conditions are easy to misremember later.
The purpose is not to build a museum inventory. It is to determine what the organization has, what condition it is in, what is still supportable, and what fits the target design.
Can the site survey determine what existing hardware can be reused?
It can provide the evidence needed to make that decision.
Existing equipment should not be kept simply because it still powers on. It also should not be discarded automatically because the organization is changing platforms.
A reuse decision should consider:
- Compatibility. Can the component work with the proposed architecture?
- Condition. Is it reliable enough to remain in service?
- Supportability. Can replacement parts, firmware, documentation, and technical support still be obtained?
- Security. Does it meet the organization’s current security requirements?
- Operational fit. Will keeping it make the environment easier or harder to support?
- Lifecycle. Does reuse make sense for the expected life of the new system?
Reader communication is one example. The Security Industry Association’s Open Supervised Device Protocol, or OSDP, supports supervised bidirectional communication and Secure Channel encryption when properly implemented. If a modernization project requires OSDP Secure Channel, an older reader that cannot support the target design may not be a good reuse candidate even if it still reads cards.
The same logic applies to controllers, locks, cabling, power supplies, and credentials.
What happens when the integrator surveys panels, controllers, and cabling?
Panels and cabling often determine how much of a retrofit can stay behind the walls.
The survey may document:
- Panel manufacturer and model
- Controller generation
- Expansion boards
- Enclosure condition
- Power supply
- Battery age or condition
- Available capacity
- Cable type
- Cable condition where visible
- Labeling
- Grounding or installation concerns visible to qualified personnel
- Network connection
- Physical security of the enclosure
- Available pathways for new cable
The team should also verify where panels are located and whether technicians can reasonably access them for future service.
A panel mounted above a ceiling in a difficult-to-access area may technically work but create a poor long-term service experience.
Safety note: Panels and electrical or life-safety-connected enclosures should only be opened by authorized and qualified personnel following site safety procedures.
What network and cybersecurity information is reviewed during the site survey?
For IP-connected access control, the physical survey and the IT conversation need to meet.
The integrator may need to understand:
- Available network drops
- VLAN or segmentation requirements
- DHCP or static addressing standards
- DNS requirements
- Internet connectivity
- Cellular feasibility where proposed
- Firewall and outbound connectivity requirements
- Cloud destinations
- Time synchronization
- Remote-support expectations
- Administrator authentication
- Logging requirements
- Vendor-risk review process
- API or integration requirements
Many cloud-managed architectures can operate primarily through outbound encrypted connections, which may reduce the need for inbound firewall rules. That does not remove the need for cybersecurity review.
IT should still understand the vendor architecture, identity controls, device hardening, administrator roles, logging, remote support, update process, integrations, and connectivity requirements.
If cellular connectivity is proposed, the survey may also need carrier coverage and signal testing. A separate cellular path can reduce reliance on the local business LAN, but the access control platform, administrative accounts, vendor access, cellular equipment, and connected devices still need to be secured.
What should be reviewed about cloud access control during the survey?
Cloud-managed access control still has local field hardware.
Readers, controllers, locks, power supplies, sensors, and other components remain at the facility. The project team also needs to define what happens when internet or WAN connectivity is unavailable.
Questions may include:
- Which users can still enter?
- Which schedules continue locally?
- Are events stored until connectivity returns?
- How much local event storage exists?
- What happens to a credential added during the outage?
- What happens to a credential that was revoked while a controller was offline?
- What happens after a controller restarts?
- Is a secondary WAN or cellular path required at critical locations?
The answers depend on the selected platform and controller architecture. They should be documented rather than assumed.
What integrations should be discussed during an access control site survey?
The survey is the right time to identify integration requirements, even if the final configuration work happens later.
Common integrations include:
- Video surveillance
- Enterprise identity platform
- Enterprise directory
- Identity provider
- HR platforms
- Visitor management
- Intercoms or door stations
- Alarm systems
- Elevators
- Building systems
- Parking or gate controls
The team should define the workflow, not simply write “integrate with video” on a scope sheet.
For example, if access control and video are supposed to work together, ask what the operator should be able to do. Should a denied-access event show the associated camera? Should an operator be able to search video from an access event? Should a door event appear in a central security interface?
Capabilities depend on the selected platforms, licensing, permissions, and camera-to-door configuration.
What credential information should be collected?
A credential strategy can affect every employee and contractor in the organization.
The survey or discovery process should identify:
- Current card technology
- Credential population
- Mobile credential interest
- PIN requirements where used
- Multifactor requirements where supported and appropriately designed
- Lost-card process
- Contractor process
- Visitor process
- Temporary credentials
- Credential printing or issuance workflow
- Whether old and new credentials must coexist during migration
If the company wants mobile credentials, that does not automatically mean every card should disappear on day one.
A mixed credential strategy may make more sense during a phased deployment or for users who cannot use a mobile credential.
How are identity and HR workflows evaluated?
For IT-led projects, the access control survey should include the identity lifecycle.
The team should understand:
- What system creates the employee record
- When a new employee should receive physical access
- Who approves access beyond a baseline role
- How department or location changes are handled
- What happens when an employee transfers
- How quickly terminated users should lose access
- How contractors are created and expired
- What exceptions need manual approval
- How failures are logged and reviewed
Automated offboarding only works when the source system, approval rules, timing, exception process, and integration are correctly designed.
The survey does not need to configure the identity system that day. It should identify the workflow the access control platform will need to support.
What does a multisite access control survey look like?
Surveying 75 locations one by one before making any design decisions is usually inefficient.
A better process is often to identify site archetypes.
For example:
- Corporate office
- Small branch office
- Distribution center
- Manufacturing site
- Retail location
- Mixed-use facility
The project team can survey representative sites in enough detail to understand common patterns and exceptions, then build a standard survey package for the remaining locations.
That package might define:
- Required photos
- Door naming
- Hardware fields
- Controller information
- Network information
- Site contacts
- Local operating hours
- Egress and fire-rating observations that require coordination
- Exceptions from the enterprise standard
The goal is not to assume every site is identical. It is to collect information consistently enough that differences can be managed.
How should business operations affect the survey?
A technically correct design can still be a bad project if installation ignores the way the facility operates.
The site survey should identify:
- Business hours
- Shift changes
- Public entrances
- Shipping and receiving periods
- High-traffic doors
- Clean-room or restricted areas
- Manufacturing shutdown windows
- Construction phases
- Tenant coordination
- Areas where dust, noise, or drilling is restricted
- Security coverage needed during cutover
- Who can authorize temporary door conditions
This information helps the implementation team build a rollout plan around the business instead of forcing the business around the installation.
What should happen after the site survey?
The survey should produce more than a folder of photos.
The project team should be able to turn the findings into a verified design and scope.
Depending on the project, deliverables may include:
- Door inventory
- Existing-hardware inventory
- Photos
- Panel and controller inventory
- Reuse recommendations
- Replacement recommendations
- Network requirements
- Integration requirements
- Credential strategy
- Site exceptions
- Life-safety or code-coordination items
- Preliminary architecture
- Phasing recommendations
- Assumptions that still need verification
- Project scope
For a multisite rollout, the survey may also produce a site taxonomy, deployment standard, pilot recommendation, and repeatable survey template for later locations.
This is where the site survey connects directly to the quote. The more accurately the environment is understood, the less the project needs to depend on broad assumptions.
What should you expect from a good access control site-survey experience?
You should come out of the process understanding your environment better than when you started.
A good integrator should be able to explain:
- What they found
- What is reusable
- What should be replaced
- What remains unknown
- Which decisions belong to IT
- Which decisions belong to Security or Facilities
- Which openings require additional door-hardware or life-safety coordination
- What the recommended architecture is trying to accomplish
- How the project could be phased
- What information is still needed before the final scope
You should not need to become an access control engineer before having that conversation.
The integrator’s job is to make the technical decisions understandable enough for your team to make informed choices.
What should make you question a site survey?
Be cautious if a complex retrofit survey:
- Focuses only on readers and ignores the rest of the opening
- Never looks at the existing panels
- Does not involve IT for an IP-connected system
- Assumes every existing component should be replaced without evaluation
- Assumes every existing component should stay because it still works
- Never asks about outage behavior
- Ignores identity and credential workflows
- Does not document site conditions
- Treats life-safety requirements as a generic one-line checkbox
- Produces no clear record of assumptions
- Does not explain what happens after installation
A survey should reduce uncertainty.
If it creates a quote without creating a clearer understanding of the environment, it did not do enough.
Frequently asked questions about commercial access control site surveys
How long does an access control site survey take?
It depends on the number of openings, the complexity of the existing system, the quality of available documentation, the number of integrations, and whether the site represents a larger multisite rollout. A small office and a large manufacturing facility should not be expected to take the same amount of time.
Do we need drawings before an access control site survey?
No. Existing floor plans, door schedules, and security drawings are helpful, but incomplete documentation should not prevent the assessment from starting.
Does every door need to be surveyed?
For a final retrofit scope, each affected opening may need verification. In a large multisite program, representative sites and standardized survey templates can help establish the design before every remaining location is assessed.
Can a site survey tell us whether existing readers and controllers can stay?
It provides the field information needed to make that decision. Compatibility, condition, supportability, cybersecurity requirements, and lifecycle all need to be evaluated before reuse is recommended.
Is a site survey the same as a code inspection?
No. A site survey can identify conditions that require code or life-safety coordination, but final requirements depend on locally adopted codes and the Authority Having Jurisdiction.
Should IT attend an access control site survey?
IT does not necessarily need to walk every door, but IT should be involved early when the project includes network-connected controllers, cloud management, identity integrations, cybersecurity review, remote access, APIs, or vendor-risk requirements.
What happens after the survey?
The findings are used to refine the system design, document assumptions, identify reusable and replacement equipment, define integrations and network requirements, coordinate exceptions, and build the project-specific scope.
A better project starts with a better understanding of the site
A site survey should make the project clearer before installation begins.
That means understanding the doors, the existing system, the network, the people who administer access, the locations that need to work together, and the operating conditions the installation team will have to respect.
That is part of The Alen Advantage. The relationship starts with expertise before equipment is ordered, continues through expert installation, and stays in place when the system needs service, changes, or expansion later.
You do not need every answer before starting the conversation. Tell Alen Security what you are trying to fix, where the system is installed, and what you know about the current environment. We can help determine what should be assessed next.
Start a commercial access control project assessment with Alen Security.
