Skip to content

Issue, restrict and revoke access credentials

A guide for authorized Lexoh administrators managing physical cards and digital codes, from enrolment and access checks to replacement and revocation.

Match the credential to the reader

A Lexoh access credential is an identifier associated with configured access rules. Reading the identifier and authorizing entry are separate steps. Before issuing a card or code, confirm the holder, compatible readers, permitted entrances, validity period and required account conditions. Use the enrolment controls available in your installed version and administrator role.

A credential format alone does not establish its security level or offline behavior. Check the exact card or code, reader, controller and configured validation rules together.

Dynamic QR code

The displayed value changes over time. Confirm the refresh interval, acceptance window and clock requirements. A code can still be photographed or copied; expiry and replay checks determine whether a captured value is accepted. Test a current code, an expired capture and a revoked credential.

Static QR code or barcode

A fixed code can be displayed or printed when that format is supported. Verify the exact barcode format, decoded value and scanner compatibility. A copy may carry the same access value, so restrict distribution and apply deliberate validity and use limits.

Physical card or RFID credential

Radio-frequency identification (RFID) credentials require a compatible reader and enrolment format. Confirm the frequency, card technology and value expected by the reader interface. Preserve meaningful leading zeros and format information. A printed card number is not necessarily the value the reader reports.

Create a traceable credential record

If staged or inactive issue is supported, confirm how it works before using it. Saving a record does not by itself prove that every controller has received the new permissions.

  1. Confirm the holder’s identity and approved access with the responsible administrator. Select the correct site and record the reason for issue.
  2. Choose a supported credential type and follow its enrolment procedure. Keep the required credential value intact; use a separate name or description for a friendly label.
  3. Check for an existing record before creating another. Associate the intended holder or account and confirm who may change that association.
  4. Set status, validity dates, schedules, zones and any supported limits. Review the actual field meanings, including blank or zero values, before saving.
  5. Verify configuration receipt and test both an allowed and a denied request at the intended reader before distribution. Record the decision and corresponding event.

Check limits and account conditions

Use allowance and single-use access

If configured, identify which event consumes a use: a read, authorization, entry or another recorded action. Test the last permitted use, the next attempt and the intended exit workflow. Check whether a rejected read or retry affects the allowance.

Occupancy and group limits

Confirm whether the allowance belongs to one credential, one holder or a shared group. Test two credentials against a shared limit and review the entry/exit events that update the count. A credential limit alone does not prevent another vehicle from following through an open barrier.

Subscriptions and vehicle associations

Where access depends on a subscription, test the relevant renewal, payment-failure, cancellation and expiry cases. If license plate recognition (LPR) is configured, confirm whether the plate and card are both required or provide alternative access methods. Associating a vehicle with a card does not by itself establish two-factor authentication.

Verify validity, weekly hours and exceptions

Set a deliberate start and expiry for the approved access period. Confirm the site time zone, controller clock and whether the start and end boundaries are included. Expiration may prevent use without changing the displayed status field; verify both the access result and the record state.

Review daily periods, selected weekdays and holiday exceptions together. For an overnight interval, test each side of midnight and the applicable calendar day. For continuous access, use the documented setting rather than assuming identical start and end times mean a full day.

Test immediately before activation, at activation, at the last allowed moment and at expiry. Repeat relevant cases at a reader that was disconnected, using the approved test procedure, to establish how updates and cached permissions are handled.

Distinguish access zones from organizational labels

A zone identifies an area or grouping used by the configured access model. Confirm which actual readers and entrances belong to it and whether permissions are direct or inherited. Test a permitted entrance and a restricted entrance; the zone name alone does not prove coverage.

Tags are organizational labels unless a configured rule explicitly uses them. A “Visitor” label does not replace expiry or status settings. Check what changes when a tag is added or removed, and who is authorized to make that change.

Illustrative policy: a temporary visitor may enter the visitor car park and lobby during the approved visit, but not the staff entrance. This table describes expected checks for that policy, not an installed configuration.

Illustrative visitor-credential acceptance checks
Test conditionExpected result
Valid visitor credential at visitor entrance during the visit Access allowed
Same credential at staff-only entrance Access refused
Same credential after its approved expiry Access refused
Revoked original after replacement and update receipt Access refused
Approved replacement at its assigned entrance Access allowed

Keep the test outcome separate from the policy

Record the actual decision, event reference and configuration version or update evidence. If the result differs, investigate assignments and matching rules before adding broader permissions.

Deliver and test the actual credential

Digital delivery

Use an enabled delivery method and verify the recipient’s address or number. A sent message is not proof of receipt or working access. Check that the credential opens on the supported device. Use a mobile-wallet option only when confirmed for the installed version and credential type.

Printed credentials

Use a supported print or export layout. Preserve the complete code, proportions and clear surrounding margin. Confirm printer compatibility and test the real paper or card at the installed reader. Do not print a changing code and assume the copy will remain valid.

Screen presentation

Test brightness, reflections, reading distance and the original credential display. A screenshot of a dynamic code may already be expired. Do not substitute a displayed number for a QR code unless the reader explicitly supports that input.

Holder instructions

Explain the permitted entrances, validity period, any use limits and how to report loss. Ask the holder not to forward or share the code or delivery link. Keep the approved fallback procedure available for a failed read or connection loss.

Revoke the original when replacing a lost credential

Issuing a replacement does not, by itself, cancel the original. If a card, printed code or delivery link is lost or shared, confirm the holder’s identity and follow the site’s revocation procedure.

  1. Identify the original record and disable or revoke it using an authorized account. Record the reason, time and operator.
  2. Check the relevant controllers’ update status, including equipment that was offline. If receipt cannot be confirmed, follow the site’s incident procedure rather than assuming the old credential is rejected.
  3. Issue the approved replacement with the intended permissions. Avoid carrying forward obsolete zones, dates or group membership.
  4. Using the supported verification method or an approved test, confirm rejection of the original and operation of the replacement at its assigned entrances.
  5. Review the holder’s other credentials and remove only access that is no longer authorized. Retain the history needed to explain the change.

Read access events in context

Check event time, time zone, device, credential reference, decision and synchronization state. Events from disconnected equipment may arrive later. An access-granted decision is not proof of physical passage; inspect the passage or detector record where available.

Review only records available within your permissions and the installation’s retention period. Confirm which event types and filters exist. Payment records, occupancy changes and entry/exit history may come from different workflows and should not be treated as interchangeable.

When export is available, verify the date range, filters, columns and number of records. After opening the file, check identifier formatting, leading zeros and timestamps. Share the minimum necessary records through the approved support or internal review channel.

Separate a reading failure from an access refusal

Retest after an approved correction and document the result. Review the same workflow when readers, credential types, access policies or connected services change.

  1. Record the exact time and reader. Determine whether the credential was read, whether an authorization decision exists and whether the equipment responded.
  2. For a read failure, verify the card or code format, the original display or print quality, and reader status. Follow the model-specific cleaning and setup instructions.
  3. For a refusal, check status, validity, schedule, zone assignment, account conditions and any consumed or shared limit. Confirm receipt of recent permission changes.
  4. Use an authorized test credential to distinguish a reader problem from a record or configuration problem. Do not grant unrestricted access merely to see whether the failure disappears.
  5. If the issue persists, send support the device and event references, expected outcome and observed result. Include relevant configuration details without exposing a usable credential.

Review the complete credential workflow

Check schedules, zones and reader configuration together. For support, provide the time, device and event reference. Remove active codes, secrets and unnecessary personal information from attachments.

Call Lexoh 1-888-401-8019