Skip to main content
the-letter-A
Articles / Press

Access Control Migration: How to Avoid Multi-Site Mistakes

Planning a legacy access control migration across multiple locations means coordinating people, systems, and site schedules while keeping doors operating. A clear plan helps IT, security, and facilities teams assess existing conditions, test the approach, and roll out a consistent access control standard.

At first, an access control site migration may seem straightforward. By the fiftieth location, the quality of the plan becomes obvious. A multi-site migration magnifies every decision. Across locations, a confusing credential policy can cause the same problem in dozens of offices. Poor naming conventions make reports harder to read at each new location. Just as important, a pilot that misses a network dependency can allow the same issue to surface across an entire region.

So a 100-location migration should not be managed as 100 separate installations. It should be run as one program with repeatable site deployments inside it.

How do you plan a legacy access control migration across multiple locations?

A successful migration does four things at the same time:

  • Moves the organization toward a defined access control standard.
  • Keeps locations operating during the transition.
  • Gives IT and Security clear governance over identities, systems, and support.
  • Leaves accurate documentation behind at every site.

The exact hardware matters, but the rollout method matters just as much.

What should an access control migration program charter define?

Before equipment is ordered, document what the migration is supposed to accomplish. Examples:

  • Replace unsupported systems.
  • Consolidate multiple platforms.
  • Move from local administration to central administration.
  • Add mobile credentials.
  • Improve user offboarding.
  • Reduce local server dependencies.
  • Integrate access events with video.
  • Create consistent security standards for new offices.
  • Improve service documentation.

As a result, that statement becomes the test for every later decision. If a proposed shortcut saves time but preserves the exact fragmented administration the project was meant to remove, it is not really a shortcut.

What should you inventory before a legacy access control migration?

You cannot sequence locations intelligently if you do not know what is at each location. For every site, record:

  • Number of controlled openings
  • Access control platform
  • Controller family
  • Reader type
  • Credential technology
  • Locking hardware
  • Door condition
  • Power supplies
  • Network environment
  • Cellular coverage if proposed
  • Fire/life-safety interfaces
  • Video integrations
  • User population
  • Business hours
  • Site contact
  • Construction or renovation plans
  • Known service issues
  • Lease or landlord constraints

Then score sites by complexity and urgency. A simple model can use categories such as:

  • High urgency / low complexity
  • High urgency / high complexity
  • Low urgency / low complexity
  • Low urgency / high complexity

That gives the program a rational starting point.

How should you choose a pilot site for a legacy access control migration?

The first location should teach the team without putting the business at unnecessary risk. A phased migration approach lets the project team use smaller or representative locations to capture lessons before larger, more complicated sites. The objective is to learn early, update the deployment standard, and avoid repeating the same issue across dozens of facilities. A useful pilot should include enough real-world conditions to test:

  • Credentials
  • Access groups
  • Door schedules
  • Remote administration
  • Network connectivity
  • Offline operation
  • Integration workflows
  • Service procedures
  • Documentation
  • Training
  • Alerting

The pilot is where the standard meets reality. Expect to change something. If the pilot produces no adjustments at all, either the team planned unusually well or it did not look closely enough.

How do site archetypes make access control rollouts more repeatable?

A portfolio of 80 locations rarely contains 80 completely unique sites. Group them. For example:

  • Small office
  • Large office
  • Retail site
  • Warehouse
  • Manufacturing facility
  • Data center or high-security site
  • Leased building with landlord-controlled perimeter

For each archetype, define a starting bill of materials, network pattern, credential approach, administrative model, and commissioning checklist. That reduces design time without pretending every door is identical.

What belongs in a pre-installation package for each location?

Every location should enter installation with the same information package. It should include:

  • Approved site survey
  • Door list
  • Floor plan
  • Hardware schedule
  • Panel locations
  • Network requirements
  • IP or cellular plan
  • Cable requirements
  • Life-safety coordination items
  • Credential plan
  • Integration requirements
  • Work hours
  • Change-control requirements
  • Site contact information
  • Test plan

This package prevents field teams from making design decisions that should have been made earlier.

Which IT requirements should be confirmed before installation?

IT dependencies are among the easiest ways to lose a day on a multi-site rollout. Before installation, confirm:

  • Network drops
  • VLAN requirements
  • DNS
  • DHCP or static addressing
  • Firewall rules
  • Outbound connectivity
  • Certificate requirements
  • SSO configuration
  • Administrator accounts
  • Vendor remote-support method
  • Cellular coverage if used
  • Security review status

If cloud-managed controllers primarily use outbound encrypted connections, that may simplify the network conversation. It does not eliminate the need to document and approve the architecture. NIST’s Zero Trust guidance is relevant here because it treats identity, device, and resource access as separate security decisions rather than assuming the local network is inherently trusted.

How should life-safety requirements be handled during migration?

Door access cannot be scheduled like ordinary IT equipment. An electrically locked opening can interact with panic hardware, fire alarm, sprinkler signals, request-to-exit devices, delayed egress, emergency release, and other building systems. The 2024 International Building Code contains several specific locking arrangements for egress doors, and UL’s current guide to access and egress locking configurations explains how those arrangements differ.

Life-safety and code note: A rollout standard can require consistent review, but final requirements depend on the opening, occupancy, lock type, fire rating, locally adopted code, and Authority Having Jurisdiction. Site assessment and installation do not replace local approval where required. This coordination belongs before installation, not at final inspection.

Which access control cutover model fits each site?

A site migration can use several cutover models.

Door-by-door cutover

Each opening is moved individually while the rest remain on the old system.

Panel-by-panel cutover

A group of doors moves when its controller is replaced or converted.

Site cutover

The entire location changes during a planned window.

Parallel operation

Old and new systems operate together for a defined period.

The best model depends on the site. For each one, define:

  • Who can enter during work
  • How credentials are handled
  • How temporary access is granted
  • How doors are secured if work pauses
  • Who approves completion
  • How rollback would work if a serious problem appears

How can you schedule a multi-site rollout around business operations?

Different businesses have natural work windows. A manufacturing company may have a planned shutdown. By contrast, a retailer may allow work overnight, while a corporate office may prefer weekends. For a new office, commissioning may be easiest before employees move in. Alen upgraded two facilities for a domestic food manufacturer during a planned two-week holiday shutdown. The 2026 case study documents the full access control, video, and alarm upgrade within that operating window.

That approach worked because the security project followed the business schedule. For a large migration, maintain a calendar that includes:

  • Site construction dates
  • Lease events
  • Peak business periods
  • Blackout dates
  • Holiday shutdowns
  • IT change freezes
  • Local permitting or inspection timing
  • Hardware lead times

The best technical design can still fail as a program if it lands at the wrong time operationally.

How should credentials be handled during a migration?

Credential migration is often underestimated. A 50-site project may involve thousands of employees, contractors, temporary workers, and visitors. Decide:

  • Will existing cards remain temporarily?
  • Are new cards being issued?
  • Are mobile credentials being introduced?
  • Can the same credential work on old and new systems during transition?
  • Who handles enrollment?
  • How are lost credentials handled?
  • How are terminated users removed from both environments?

If two systems will coexist, define which identity source governs each one. This avoids a situation where someone is deactivated in the new platform but remains active in the old one for three months.

What data should move from a legacy access control system?

The access control database may contain years of:

  • Users
  • Credentials
  • Access levels
  • Schedules
  • Holidays
  • Door names
  • Alarm rules
  • Reports
  • Event history

However, not all of it should automatically move. A migration is a chance to clean the environment. Ask:

  • Which users are still active?
  • Which access groups are still needed?
  • Which schedules are still valid?
  • Which old cards should be retired?
  • How much event history needs to be retained?
  • What must remain available for audit purposes?

If the old database is messy, blindly copying it can move years of bad administration into a new platform.

What should an access control site acceptance test include?

Installation completion should mean more than “the reader beeped.” Test at least:

  • Authorized entry
  • Denied entry
  • Door position monitoring
  • Forced-door event
  • Held-open event
  • Request-to-exit operation
  • Lock operation
  • Power-loss behavior
  • Backup battery behavior
  • Fire-alarm release where applicable
  • Offline controller operation
  • Event reporting
  • Credential update
  • Remote administration
  • Video association, if used
  • Identity integration, if used

Record the result. If a site later has a problem, the company should know what was tested and when.

How should teams manage punch-list items across locations?

Small issues become permanent if the program immediately moves to the next site. Examples:

  • Reader label missing
  • Door closer needs adjustment
  • Camera association incorrect
  • Panel photo not uploaded
  • Access group mapping incomplete
  • Local administrator not trained
  • Battery date not recorded

A site is not complete until the punch list is closed or the remaining item has an approved owner and due date. This is ordinary project discipline, but it becomes much more valuable across 100 locations.

What documentation should each migrated site leave behind?

Every site should leave behind:

  • As-built drawing
  • Door list
  • Panel list
  • Reader list
  • Locking hardware record
  • Network information
  • Egress component record
  • Power supply information
  • Battery information
  • Photos
  • Test results
  • Configuration notes
  • Approved exceptions

Ultimately, the company should be able to hand that package to a service technician who has never visited the site. That is the test.

How should you group sites into rollout waves?

Once the pilot is complete, group sites into waves. A wave may be based on:

  • Geography
  • Site type
  • Construction schedule
  • Existing platform
  • Hardware availability
  • Business unit
  • Urgency

Each wave should have entry criteria. For example:

  • Survey complete
  • Hardware approved
  • Network ready
  • Security review complete
  • Credential plan ready
  • Site date approved
  • Permitting path confirmed where needed

If a location is not ready, move it out of the wave rather than forcing the schedule.

What changes when an access control rollout reaches 50 or 100 locations?

Governance becomes more important than individual installations. At larger scale, track:

  • Sites surveyed
  • Sites ready
  • Sites installed
  • Sites accepted
  • Open punch items
  • Exceptions
  • Hardware substitutions
  • Credential migration status
  • Documentation completeness
  • Service issues after cutover

Over time, patterns will emerge. If three sites in one wave have the same lock issue, fix the archetype before the next 20 locations repeat it.

What does a real multi-site access control rollout look like?

Alen Security is managing a national rollout for an architecture, engineering, and construction firm with approximately 140 offices. At the time Alen’s 2026 case study was published, 50 locations had been completed. The rollout is phased around each office’s construction or renovation schedule. That is the important part.

The program is not trying to force every office into one artificial deployment date. It uses a common platform and repeatable process while fitting installation into the timing of each site.

Frequently asked questions about multi-site access control migration

Should every site be migrated in the same way?

No. The program should use consistent standards and testing, but site type, construction, door hardware, operating hours, and local requirements can change the installation method.

How many locations should be included in the pilot?

There is no fixed number. The pilot needs enough variety to test the standard without exposing the organization to unnecessary scale before lessons are learned.

Can access control migrations happen during normal business hours?

Sometimes. Other locations require evenings, weekends, shutdowns, or door-by-door sequencing. The cutover plan should be based on operations and door security requirements.

Should data from the old access control system be migrated automatically?

Not without review. A migration is a good time to remove inactive users, outdated access groups, old credentials, and unnecessary configuration.

What is the biggest risk in a 100-site migration?

Repeating an unresolved design or process problem across many locations. That is why pilots, archetypes, acceptance testing, and documented exceptions matter.

Planning an access control rollout across multiple locations?

The goal is not to install the same thing 100 times. It is to build a process that gets smarter as the rollout grows. That is part of what Trusted… Everywhere means in a multi-site deployment: the quality of the standard, installation, documentation, and support should hold as the program expands.

Alen Security can help inventory your sites, define the standard, choose pilot locations, coordinate IT and construction requirements, and manage a phased deployment around the way your business actually operates. Talk with Alen Security about a multi-site access control rollout.