Skip to content

Access Control Statistics in Lexoh Security Center

Use Lexoh Security Center reports to examine credential activity, denied attempts and access patterns within a selected period.

Review access statistics

Overview

Use Access Control Statistics to review credential usage, authorization decisions and denied attempts. These records help investigate an event; they do not by themselves prove who physically entered. Open Statistics → Access Control in the main navigation.

Key Features:

  • Card Inventory: Track total, active, and expired access cards
  • Hourly Access Patterns: Visualize card usage throughout the day
  • Authorization Analysis: Monitor authorized vs denied access attempts
  • Security Monitoring: Track and investigate denied access attempts
  • Time Filtering: Analyze patterns across 24h, 7d, 1m, 6m, 4y periods
  • Related alerts: Configure supported notifications separately from the statistics view.
Security Priority: Access control statistics are critical for facility security. Regular monitoring helps identify unauthorized access attempts, card misuse, and potential security breaches before they escalate.

Dashboard Metrics

Review total, active and expired credentials together. These counts describe credential inventory; they do not establish equipment health or physical occupancy.

Total Access Cards

Description
Complete count of all access cards registered in the system
Icon
Blue card symbol
Includes
Active, expired, suspended, and deactivated cards
  • Represents total card inventory across all users and zones
  • Includes both physical RFID cards and virtual access credentials
  • Essential for card procurement and inventory management
  • Reconcile the inventory after credentials are issued, changed or removed.
Inventory Tip: Plan spare credentials from your hiring, visitor and replacement needs, supplier lead time and issuance process.

Active Cards

Description
Number of cards currently authorized for access
Icon
Green checkmark symbol
Status
Valid, non-expired cards with active permissions
  • Check the current authorization, expiry and applicable access schedule.
  • Excludes suspended, revoked, or administratively disabled cards
  • An active credential does not imply permission for every entrance or time period.
  • Compare active credentials with the approved user population; one person may hold more than one credential.
Best Practice: Regularly audit active cards to ensure they match current personnel. Deactivate cards immediately when employees leave or credentials are compromised.

Expired Cards

Description
Cards that have passed their expiration date
Icon
Yellow/orange clock symbol
Access
Verify that the deployed access rules reject expired credentials at each intended entrance.
  • Includes cards that expired naturally based on set duration
  • Does not include manually suspended or revoked cards
  • High count may indicate need for card renewal process
  • Check whether the person has another valid credential before concluding that all access is unavailable.
Renewal Alert: Set a reminder period that leaves time to confirm continued authorization and issue a replacement. Renewal must follow the approved access policy.

Hourly Access Patterns

The Hourly Entrances bar chart displays access card usage distribution across 24-hour periods, revealing facility access patterns, peak times, and unusual activity windows.

Chart Features

  • X-Axis: 24 hours from 0:00 to 23:00 in hourly increments
  • Y-Axis: Number of access card uses (automatically scaled)
  • Bars: Blue vertical bars indicating access volume per hour
  • Hover Tooltips: Shows device name and exact access count (e.g., "Entrance @ 8:00 - 24")
  • Grid Lines: Horizontal reference lines for easier reading

Understanding Access Patterns

Use the site’s actual operating schedule to interpret peaks. The following patterns are illustrative examples, not security thresholds.

Facility Type Illustrative time window Pattern
Office Building 7:00-9:00, 17:00-19:00 Morning arrival, evening departure spikes
24/7 Facility 7:00, 15:00, 23:00 Three shift changes throughout day
Data Center 9:00-17:00 Compare with the site’s approved staffing and service schedule
Residential Distributed 6:00-22:00 Even distribution, individual schedules
Healthcare 6:00-8:00, 14:00-16:00 Morning staff, afternoon shifts
Office Building
Peak: 7:00-9:00, 17:00-19:00
Pattern: Morning arrival, evening departure spikes
24/7 Facility
Peak: 7:00, 15:00, 23:00
Pattern: Three shift changes throughout day
Data Center
Peak: 9:00-17:00
Pattern: Compare with the site’s approved staffing and service schedule
Residential
Peak: Distributed 6:00-22:00
Pattern: Even distribution, individual schedules
Healthcare
Peak: 6:00-8:00, 14:00-16:00
Pattern: Morning staff, afternoon shifts

Security Anomalies

Watch for unusual patterns that may indicate security issues:

  • Activity outside the expected schedule: check approved exceptions and the event details.
  • Weekend Activity: Access during closed days may be unauthorized
  • Volume Drops: Sudden decrease could indicate system failure
  • Unexpected Peaks: Abnormal spikes outside normal hours need review
Security Alert: Where supported, configure notifications for the site’s actual closed periods and test delivery to the responsible team.

Access Card Types Distribution

The chart separates authorization outcomes. Compare the categories with event details and the same reporting scope before interpreting a change.

Chart Categories

  • Authorized (Green): Successful access attempts with valid, active cards
  • Denied (Red): Rejected attempts due to expired, invalid, or unauthorized cards
  • Unknown (Gray): Unrecognized cards or system read errors

An authorized-attempt count measures authorization decisions. Use the relevant passage sensor or other approved evidence to confirm physical entry.

Establish a site baseline

Compare the same entrances, credential population and reporting period:

  • Authorized: Review successful authorizations against expected site activity.
  • Denied: Separate expected policy refusals from errors affecting authorized users.
  • Unknown: Check registration, compatibility and reader conditions before assigning a cause.
Interpretation: There is no universal success percentage that proves security. An authorization event alone does not confirm a person or vehicle physically passed through the entrance.

Warning Signs

Changes to investigate using the site’s review and escalation priorities:

  • Rising denials: Compare with credential expiry, permission changes and the normal site pattern.
  • More unknown credentials: Check recent credential changes, reader compatibility and unregistered attempts.
  • Sudden Spike in Denials: Mass card expiration or system misconfiguration
  • Zero Activity: System may be offline or not recording properly
Action Required: Use the site’s escalation criteria to prioritize review. Verify the reason and the user’s authorization before changing a credential or permission.

Recent Denied Access Attempts

Use denied-attempt records to review the recorded reason, time and credential. Check the selected period and available history before treating the list as complete.

Table Columns

  • User: Name or identifier of person/card attempting access
  • Description: Reason for denial (expired card, invalid card, no permissions, etc.)
  • Date: Timestamp of denied attempt (YYYY-MM-DD HH:mm:ss format)
  • Count: Number of repeated denied attempts; inspect their timing and cause before interpreting intent.

Common Denial Reasons

Description Cause Action Required
Card Expired Expiration date passed Confirm continued authorization before renewing the expiry date.
Invalid Card Card not registered in system Investigate source, register if legitimate
No Access Permission Card lacks zone authorization Check the approved access request; change the zone permission only if authorized.
Card Suspended Administratively disabled Verify reason, reinstate if appropriate
Outside Schedule Access attempted outside allowed hours Compare with the approved schedule; retain the denial when the rule is correct.
Card Expired
Cause: Expiration date passed
Action: Confirm continued authorization before renewing the expiry date.
Invalid Card
Cause: Card not registered in system
Action: Investigate source, register if legitimate
No Access Permission
Cause: Card lacks zone authorization
Action: Check the approved access request; change the zone permission only if authorized.
Card Suspended
Cause: Administratively disabled
Action: Verify reason, reinstate if appropriate
Outside Schedule
Cause: Access attempted outside allowed hours
Action: Compare with the approved schedule; retain the denial when the rule is correct.

Investigation Priority

Focus your security investigations on:

  1. Repeated denials: Check timing, credential state and the reported reason; repetition alone does not establish malicious intent.
  2. Unknown users: check whether the credential is registered and compatible with the reader.
  3. Outside approved hours: Compare the attempt with the user’s schedule and authorized exceptions.
  4. Affected entrance: compare the credential’s behavior at other entrances where it is authorized before attributing the problem to the card.
  5. Recent changes: check permission, schedule and credential updates that coincide with the first refusal.
  6. Document Actions: Log all investigations and resolutions
Response Protocol: Follow the site’s approved response and escalation procedure. Preserve the relevant event reference and involve authorized staff before reviewing video or changing permissions.

Time Period Filtering

The time period selector allows you to analyze access control patterns across different timeframes, revealing trends and identifying anomalies specific to each duration.

Available Time Periods

Period Label Security Use Case
24 Hours 24h Real-time security monitoring, daily access review
7 Days 7d Weekly patterns, identify unusual weekly activity
1 Month 1m Monthly security reports, card expiration trends
6 Months 6m Semi-annual audit, seasonal access changes
4 Years 4y Historical analysis, long-term security trends
24 Hours
Label: 24h
Use Case: Real-time security monitoring, daily access review
7 Days
Label: 7d
Use Case: Weekly patterns, identify unusual weekly activity
1 Month
Label: 1m
Use Case: Monthly security reports, card expiration trends
6 Months
Label: 6m
Use Case: Semi-annual audit, seasonal access changes
4 Years
Label: 4y
Use Case: Historical analysis, long-term security trends

Analysis Use Cases

  • 24h View: Morning security check, investigate overnight activity
  • 7d View: Weekly reporting, identify day-of-week patterns
  • 1m View: Monthly security audits, card renewal planning
  • 6m View: Seasonal staffing analysis, budget forecasting
  • 4y View: Facility growth trends, system capacity planning

Filter Effects on Data

When you change the time filter:

  • Hourly Entrances chart recalculates for selected period
  • Access Card Types distribution updates with period's data
  • Denied Attempts table filters to show only period's rejections
  • Total/Active/Expired card counts show current inventory (not filtered)
Analysis Tip: Start with the period relevant to the issue, then compare equivalent operating days. Available history depends on retained records, permissions and the deployed configuration; a filter label does not guarantee that duration of stored data.

Security Insights & Analysis

Compare equivalent periods before deciding whether activity has changed. Relate changes to staffing, access schedules and work on site.

Use the daily review checklist

Trend Analysis

Compare periods to identify patterns:

  • Week-over-week: Spot immediate changes in access behavior
  • Month-over-month: Track seasonal variations and staffing changes
  • Year-over-year: Measure facility growth and capacity needs

Operational Optimization

  • Staff Scheduling: Align security staff with peak access hours
  • Reader placement: Combine traffic records with observed queues and reading conditions before changing the entrance.
  • Maintenance Windows: Low-activity hours ideal for system maintenance
  • Card Issuance: Batch renewals before expiration spikes
Integration with Other Systems: Correlate access control data with video surveillance, time tracking, and visitor management for comprehensive security oversight.

Best Practices

Assign a review owner, a review schedule and an escalation path. Use these checks to maintain access records and investigate exceptions.

Daily Security Monitoring

  • Review the records since the previous check, including overnight activity.
  • Compare denial changes with the site baseline, investigate recorded reasons and follow the agreed escalation priorities.
  • Compare after-hours activity with approved access schedules and exceptions.
  • Check unknown credentials against registration, reader compatibility and event context.
  • Review expired and upcoming credentials. Distinguish planned end-of-access dates from pending renewals, and confirm continued authorization before renewal.

Card Management Excellence

  • Set expiry reminders according to the time needed to confirm and renew authorized access.
  • Deactivate cards immediately when employee leaves
  • Set an access-review schedule and verify that active credentials still belong to authorized users.
  • Maintain spare credentials according to expected replacements and delivery lead times.
  • Set appropriate expiration periods based on user type (temp vs permanent)

Security Response Procedures

  • Establish clear escalation process for security events
  • Set up automated alerts for after-hours access attempts
  • Document all denied attempt investigations and resolutions
  • Coordinate with video surveillance for visual verification
  • Follow the site’s approved incident procedure; a count of unknown credentials alone must not trigger an improvised lockdown.

Data Retention & Privacy

  • Define access log retention period per regulatory requirements
  • Restrict statistics access to authorized security personnel only
  • Anonymize data when sharing for operational analysis
  • Keep only authorized exports and archives, with their own access controls and retention rules.
  • Have the responsible privacy team confirm the requirements applicable to the organization and site.
Operating policy: Define site-specific review thresholds, investigate unknown credentials and denied attempts, and document the response process. Appropriate targets depend on the facility, credential population and operating policy.
Call Lexoh 1-888-401-8019