Skip to main content
the-letter-A
Articles / Press

Multi-Site Access Control: Replace Shared Door Codes

For organizations planning multi-site access control, shared door codes are easy to issue, but with that ease comes a major downfall. They are challenging if not downright impossible to manage.

The challenge starts with one employee giving the code to another. Maybe a  vendor sees someone enter it.  A former employee remembers it. A regional manager changes the code, but nobody knows whether every person who needs access got the new one.

For businesses with only one location with lower overall security, that may be manageable. Across 20, 50, or 100 locations, shared codes can become an administrative problem because the organization cannot easily tie entry rights to an individual person.

That does not mean keypad access is universally wrong. It means a company should understand what it gives up when one secret is shared by many people.

There’s a lot of complexities when it comes to commercial security.

What is the main problem with shared door codes?

The problem is you can’t identify easily who’s coming and going. If 30 people know one code, the company may know that the code was used but not which authorized person used it.

It also becomes difficult to remove one person’s access without affecting everyone else.

When an employee leaves, the organization has two choices:

  • Leave the code unchanged and accept that the former employee may still know it.
  • Change the code and redistribute it to everyone who still needs access.

That does not scale well across a distributed business.

When can a keypad code still make sense?

A keypad or PIN can still be appropriate in some designs.

Examples might include:

  • Low-risk shared areas
  • Temporary controlled use
  • A PIN used as a second factor with another credential
  • Operational environments where individual credentialing has been evaluated and another method is justified

The problem is not the existence of a keypad.

The problem is using one persistent shared code as the primary identity model for doors where the organization needs individual accountability, fast revocation, or centralized management.

What does multi-site access control change?

Managed access control assigns access to individual identities or credentials.

Those credentials may be:

  • Physical cards
  • Key fobs
  • Mobile credentials
  • Smart cards
  • Other supported individual credential types

The company can then:

  • Grant access to one person
  • Remove access from one person
  • Restrict access by site
  • Restrict access by schedule
  • Set contractor expiration
  • See individual access events
  • Manage locations centrally

This changes the operational model from “who knows the code?” to “who is authorized?”

A real shared-code problem in national retail

Alen Security documented this exact issue in a 2026 national retail case study.

The retailer had used standalone combination locks across store locations. Codes were shared, rarely changed, and easy to observe. Corporate Security did not have one interface to manage individual access across sites.

Alen designed a Brivo cloud access control deployment using wireless lock readers and centrally managed credentials. At the time the case study was published, five locations were active, ten additional stores were planned for 2026, and the rollout was expected to reach roughly 50 readers by year end.

The useful part of the example is not the brand name.

It is the change in control model.

Instead of rotating one shared secret, regional or corporate administrators can manage an individual’s credential.

Do you have to run new wire to every door?

Not always.

Different access control architectures can fit different openings.

Options may include:

  • Traditional wired reader and controller
  • Wireless electronic lock
  • Intelligent lockset
  • Existing compatible cabling and hardware
  • Retrofit reader using available infrastructure

Wireless can be attractive in finished retail or office environments where new cable would be disruptive.

But wireless does not mean infrastructure-free.

A wireless design may still require:

  • Batteries
  • Gateways
  • Network or cellular connectivity
  • Commissioning
  • Firmware management
  • Battery-replacement planning
  • Compatibility review

The right question is not “can we avoid wire?”

It is “what architecture fits this opening and the way we need to manage it?”

How should a company phase multi-site access control across its locations?

Start with the places where shared codes create the most exposure or administrative burden.

Examples:

  • Employee back entrances
  • Stock rooms
  • Manager offices
  • High-value storage
  • Warehouse entrances
  • Server or communications rooms
  • Areas with high employee turnover

Then consider site readiness.

A small pilot can test:

  • Credential issuance
  • Regional administration
  • Lost-card procedure
  • Offboarding
  • Wireless connectivity if used
  • Battery maintenance
  • User training

Use the pilot to establish the repeatable store or site standard.

How should individual credentials be assigned?

Start with identity ownership.

Every credential should be tied to a person or defined non-person identity under company policy.

For people, record:

  • Name
  • Employee or contractor ID
  • Location
  • Role
  • Sponsor where applicable
  • Start date
  • End date where applicable
  • Credential
  • Access profile

Avoid creating a new form of shared identity inside the electronic system, such as one generic “Store Staff” card passed among employees.

If accountability is the reason for the upgrade, preserve individual identity all the way through the workflow.

Cards, fobs, or mobile credentials?

Any of them may work.

The decision depends on:

  • User population
  • Reader compatibility
  • Phone policy
  • Replacement process
  • Distribution model
  • Existing credential standard
  • Contractor needs
  • Offline behavior

Mobile credentials can be attractive for distributed sites because they may be issued remotely through supported platforms.

Physical cards can still be a better fit for some workers and environments.

A mixed model is often reasonable.

How does multi-site access control change offboarding?

This is where individual credentials show immediate value.

When one employee leaves:

  • Deactivate that identity.
  • Revoke that credential.
  • Leave everyone else’s credential unchanged.

If the access platform integrates with an identity or HR workflow, some of that process can be automated, depending on platform support.

Even without automation, the administrative action is more precise than changing a shared code across the whole location.

How should regional managers be given access-control rights?

Distributed businesses often need local or regional administration.

Define roles such as:

Corporate Security

Enterprise visibility and policy control.

Regional Security or Operations

Manage assigned locations only.

Store or Site Manager

Limited tasks such as temporary credential activation, depending on company policy.

Do not give local administrators broader rights than they need.

In a multi-site access control program, the system should support the organization’s operating structure rather than forcing everything through headquarters.

What happens if a credential is lost?

The process becomes individual.

For a lost card:

  • Employee reports the loss.
  • Credential is disabled.
  • Replacement is issued.
  • Access profile transfers according to policy.
  • Old credential remains inactive.

For a lost phone using a mobile credential, the organization may also involve IT or device-management procedures.

The old credential should be revoked through the access platform, not assumed safe because the phone has a lock screen.

How does multi-site access control improve auditability?

Individual access events can answer questions such as:

  • Which credential was presented?
  • When?
  • At which door?
  • Was access granted or denied?
  • Was the door forced or held open afterward?

That is more useful than knowing only that someone entered the correct four digits.

Video integration can add context where the selected platforms support it.

The goal is not surveillance for its own sake.

It is having evidence when a security event needs investigation.

How should temporary and contractor access work?

Temporary workers are one reason shared codes spread.

An individual access-control system can provide time-limited access instead.

Define:

  • Sponsor
  • Start date
  • End date
  • Site
  • Door group
  • Schedule
  • Credential type

Set expiration where the platform supports it.

A contractor who needs two days of stock-room access should not leave with a code that still works six months later.

Should every store or site be converted at once?

No.

A phased rollout can prioritize:

  • Highest-risk sites
  • New stores
  • Renovations
  • Sites with repeated code problems
  • Sites with compatible infrastructure
  • Regions with local management ready for the new process

Create a standard after the pilot, then apply it consistently.

This is how a local security fix becomes an enterprise program.

What should IT review in a distributed access-control design?

Even if the goal is replacing door codes, the new system may touch:

  • Cloud services
  • Network connectivity
  • Cellular connectivity
  • Administrator identity
  • Mobile apps
  • APIs
  • Entra ID or Okta
  • Remote support

IT should review:

  • Network paths
  • Authentication
  • Administrator roles
  • Vendor access
  • Logging
  • Updates
  • Integration security

If cellular is used to avoid dependence on a store LAN, that can simplify local coordination. It does not remove the access-control platform from cybersecurity review.

What about life safety on doors being converted?

Replacing a combination lock with electronic access can change the opening.

If electric locking is added, the design needs the correct egress and hardware arrangement.

The 2024 International Building Code and UL’s access and egress locking guide describe several electrically locked egress configurations.

Life-safety and code note: Requirements depend on the opening, occupancy, lock type, fire rating, locally adopted code, and Authority Having Jurisdiction. A retrofit assessment should identify what needs coordination before the electronic locking design is finalized.

What should a shared-code replacement project document?

For every location:

  • Doors being converted
  • Existing lock type
  • New lock or reader type
  • Credential model
  • Administrator roles
  • Network or cellular connection
  • Battery requirements if wireless
  • Door schedule
  • Egress hardware
  • Fire-alarm interaction where applicable
  • Photos
  • Test results

For the program:

  • Credential policy
  • Offboarding process
  • Lost-credential process
  • Contractor process
  • Regional administration
  • Exception process
  • Maintenance schedule

That prevents each location from inventing its own version of managed access.

Define what success looks like after the codes are gone

A successful conversion is not measured only by the number of keypads replaced. The project should improve how the organization grants, changes, reviews, and removes access.

Useful measures can include:

  • How quickly a terminated user’s access is removed
  • Whether individual access events can be tied to an authorized identity
  • How many locations are managed from the intended central platform
  • How long it takes to issue or revoke a credential
  • Whether temporary access expires as intended
  • Whether local managers still create unmanaged workarounds
  • Battery or device-health exceptions at wireless openings
  • Door-prop, forced-door, or access-denied trends where those events are monitored

During transition, some locations may temporarily keep both shared codes and individual credentials. If so, document why, who still needs the code, when it will be removed, and who owns that decision. Otherwise a temporary fallback can quietly become permanent and erase much of the accountability the new system was meant to create.

Frequently asked questions about replacing shared door codes

Are shared keypad codes always insecure?

No. Their suitability depends on the use case and required assurance. The main limitation is that one shared code makes individual revocation and accountability difficult.

Can existing keypad locks be kept?

Possibly. The organization may keep them at doors where shared code access remains appropriate while converting doors that require individual identity, centralized management, or auditability.

Can wireless access control replace shared codes without new door wiring?

At some openings, yes. Wireless lock systems can reduce new door cabling, but batteries, gateways, connectivity, commissioning, and lifecycle maintenance still need to be planned.

Can mobile credentials replace shared codes?

They can in supported systems, giving each authorized person an individual credential. Reader compatibility, phone policy, enrollment, and fallback procedures should be evaluated.

Can corporate Security manage several locations from one system?

Many enterprise access control platforms support centralized and delegated administration. Verify the platform’s site structure, permissions, connectivity, and licensing.

Shared codes solve distribution. Managed credentials solve control.

If the same code has been passed through years of employees, contractors, and store managers, changing it one more time may not fix the underlying problem.

Alen Security can assess the doors, existing locks, wiring, wireless options, network conditions, and administration model, then help build an individual credential approach that works across distributed locations without assuming every site needs the same retrofit.

Talk with Alen Security about replacing shared door codes.