01
The decision: credential, door hardware and topology
The credential choice sets the security floor. Legacy proximity credentials are convenient and trivially cloneable; encrypted smart credentials resist copying; mobile credentials remove the card entirely and introduce a dependency on the user's phone and on an enrolment process; biometrics remove the credential but raise a personal-data obligation that has to be answered before, not after, deployment. A site that mixes visitor cards, staff credentials and contractor access needs that mix designed rather than accumulated.
Door hardware is the decision that is hardest to change afterwards, because it is mechanical. Whether a door fails secure or fails safe on power loss, whether it uses a magnetic lock or an electric strike, whether it needs a request-to-exit device, a door-position sensor or both — all of that is determined by the door's fire and egress role and by what the leaf and frame can physically accept. Retrofitting an electric lock into an existing frame is frequently the constraint that decides the design.
Topology is the third choice: controllers on the network with local decision-making, or a centralised architecture that stops working when the link does. On a multi-building campus with variable connectivity, controllers that hold their own credential database and decide locally are the difference between a network fault being an inconvenience and being a lockout.
