Overview
Use Access Control Statistics to review credential usage, authorization decisions and denied attempts. These records help investigate an event; they do not by themselves prove who physically entered. Open Statistics → Access Control in the main navigation.
Key Features:
- Card Inventory: Track total, active, and expired access cards
- Hourly Access Patterns: Visualize card usage throughout the day
- Authorization Analysis: Monitor authorized vs denied access attempts
- Security Monitoring: Track and investigate denied access attempts
- Time Filtering: Analyze patterns across 24h, 7d, 1m, 6m, 4y periods
- Related alerts: Configure supported notifications separately from the statistics view.
Dashboard Metrics
Review total, active and expired credentials together. These counts describe credential inventory; they do not establish equipment health or physical occupancy.
Total Access Cards
- Description
- Complete count of all access cards registered in the system
- Icon
- Blue card symbol
- Includes
- Active, expired, suspended, and deactivated cards
- Represents total card inventory across all users and zones
- Includes both physical RFID cards and virtual access credentials
- Essential for card procurement and inventory management
- Reconcile the inventory after credentials are issued, changed or removed.
Active Cards
- Description
- Number of cards currently authorized for access
- Icon
- Green checkmark symbol
- Status
- Valid, non-expired cards with active permissions
- Check the current authorization, expiry and applicable access schedule.
- Excludes suspended, revoked, or administratively disabled cards
- An active credential does not imply permission for every entrance or time period.
- Compare active credentials with the approved user population; one person may hold more than one credential.
Expired Cards
- Description
- Cards that have passed their expiration date
- Icon
- Yellow/orange clock symbol
- Access
- Verify that the deployed access rules reject expired credentials at each intended entrance.
- Includes cards that expired naturally based on set duration
- Does not include manually suspended or revoked cards
- High count may indicate need for card renewal process
- Check whether the person has another valid credential before concluding that all access is unavailable.
Hourly Access Patterns
The Hourly Entrances bar chart displays access card usage distribution across 24-hour periods, revealing facility access patterns, peak times, and unusual activity windows.
Chart Features
- X-Axis: 24 hours from 0:00 to 23:00 in hourly increments
- Y-Axis: Number of access card uses (automatically scaled)
- Bars: Blue vertical bars indicating access volume per hour
- Hover Tooltips: Shows device name and exact access count (e.g., "Entrance @ 8:00 - 24")
- Grid Lines: Horizontal reference lines for easier reading
Understanding Access Patterns
Use the site’s actual operating schedule to interpret peaks. The following patterns are illustrative examples, not security thresholds.
| Facility Type | Illustrative time window | Pattern |
|---|---|---|
| Office Building | 7:00-9:00, 17:00-19:00 | Morning arrival, evening departure spikes |
| 24/7 Facility | 7:00, 15:00, 23:00 | Three shift changes throughout day |
| Data Center | 9:00-17:00 | Compare with the site’s approved staffing and service schedule |
| Residential | Distributed 6:00-22:00 | Even distribution, individual schedules |
| Healthcare | 6:00-8:00, 14:00-16:00 | Morning staff, afternoon shifts |
Security Anomalies
Watch for unusual patterns that may indicate security issues:
- Activity outside the expected schedule: check approved exceptions and the event details.
- Weekend Activity: Access during closed days may be unauthorized
- Volume Drops: Sudden decrease could indicate system failure
- Unexpected Peaks: Abnormal spikes outside normal hours need review
Access Card Types Distribution
The chart separates authorization outcomes. Compare the categories with event details and the same reporting scope before interpreting a change.
Chart Categories
- Authorized (Green): Successful access attempts with valid, active cards
- Denied (Red): Rejected attempts due to expired, invalid, or unauthorized cards
- Unknown (Gray): Unrecognized cards or system read errors
An authorized-attempt count measures authorization decisions. Use the relevant passage sensor or other approved evidence to confirm physical entry.
Establish a site baseline
Compare the same entrances, credential population and reporting period:
- Authorized: Review successful authorizations against expected site activity.
- Denied: Separate expected policy refusals from errors affecting authorized users.
- Unknown: Check registration, compatibility and reader conditions before assigning a cause.
Warning Signs
Changes to investigate using the site’s review and escalation priorities:
- Rising denials: Compare with credential expiry, permission changes and the normal site pattern.
- More unknown credentials: Check recent credential changes, reader compatibility and unregistered attempts.
- Sudden Spike in Denials: Mass card expiration or system misconfiguration
- Zero Activity: System may be offline or not recording properly
Recent Denied Access Attempts
Use denied-attempt records to review the recorded reason, time and credential. Check the selected period and available history before treating the list as complete.
Table Columns
- User: Name or identifier of person/card attempting access
- Description: Reason for denial (expired card, invalid card, no permissions, etc.)
- Date: Timestamp of denied attempt (YYYY-MM-DD HH:mm:ss format)
- Count: Number of repeated denied attempts; inspect their timing and cause before interpreting intent.
Common Denial Reasons
| Description | Cause | Action Required |
|---|---|---|
| Card Expired | Expiration date passed | Confirm continued authorization before renewing the expiry date. |
| Invalid Card | Card not registered in system | Investigate source, register if legitimate |
| No Access Permission | Card lacks zone authorization | Check the approved access request; change the zone permission only if authorized. |
| Card Suspended | Administratively disabled | Verify reason, reinstate if appropriate |
| Outside Schedule | Access attempted outside allowed hours | Compare with the approved schedule; retain the denial when the rule is correct. |
Investigation Priority
Focus your security investigations on:
- Repeated denials: Check timing, credential state and the reported reason; repetition alone does not establish malicious intent.
- Unknown users: check whether the credential is registered and compatible with the reader.
- Outside approved hours: Compare the attempt with the user’s schedule and authorized exceptions.
- Affected entrance: compare the credential’s behavior at other entrances where it is authorized before attributing the problem to the card.
- Recent changes: check permission, schedule and credential updates that coincide with the first refusal.
- Document Actions: Log all investigations and resolutions
Time Period Filtering
The time period selector allows you to analyze access control patterns across different timeframes, revealing trends and identifying anomalies specific to each duration.
Available Time Periods
| Period | Label | Security Use Case |
|---|---|---|
| 24 Hours | 24h | Real-time security monitoring, daily access review |
| 7 Days | 7d | Weekly patterns, identify unusual weekly activity |
| 1 Month | 1m | Monthly security reports, card expiration trends |
| 6 Months | 6m | Semi-annual audit, seasonal access changes |
| 4 Years | 4y | Historical analysis, long-term security trends |
Analysis Use Cases
- 24h View: Morning security check, investigate overnight activity
- 7d View: Weekly reporting, identify day-of-week patterns
- 1m View: Monthly security audits, card renewal planning
- 6m View: Seasonal staffing analysis, budget forecasting
- 4y View: Facility growth trends, system capacity planning
Filter Effects on Data
When you change the time filter:
- Hourly Entrances chart recalculates for selected period
- Access Card Types distribution updates with period's data
- Denied Attempts table filters to show only period's rejections
- Total/Active/Expired card counts show current inventory (not filtered)
Security Insights & Analysis
Compare equivalent periods before deciding whether activity has changed. Relate changes to staffing, access schedules and work on site.
Use the daily review checklist
Trend Analysis
Compare periods to identify patterns:
- Week-over-week: Spot immediate changes in access behavior
- Month-over-month: Track seasonal variations and staffing changes
- Year-over-year: Measure facility growth and capacity needs
Operational Optimization
- Staff Scheduling: Align security staff with peak access hours
- Reader placement: Combine traffic records with observed queues and reading conditions before changing the entrance.
- Maintenance Windows: Low-activity hours ideal for system maintenance
- Card Issuance: Batch renewals before expiration spikes
Best Practices
Assign a review owner, a review schedule and an escalation path. Use these checks to maintain access records and investigate exceptions.
Daily Security Monitoring
- Review the records since the previous check, including overnight activity.
- Compare denial changes with the site baseline, investigate recorded reasons and follow the agreed escalation priorities.
- Compare after-hours activity with approved access schedules and exceptions.
- Check unknown credentials against registration, reader compatibility and event context.
- Review expired and upcoming credentials. Distinguish planned end-of-access dates from pending renewals, and confirm continued authorization before renewal.
Card Management Excellence
- Set expiry reminders according to the time needed to confirm and renew authorized access.
- Deactivate cards immediately when employee leaves
- Set an access-review schedule and verify that active credentials still belong to authorized users.
- Maintain spare credentials according to expected replacements and delivery lead times.
- Set appropriate expiration periods based on user type (temp vs permanent)
Security Response Procedures
- Establish clear escalation process for security events
- Set up automated alerts for after-hours access attempts
- Document all denied attempt investigations and resolutions
- Coordinate with video surveillance for visual verification
- Follow the site’s approved incident procedure; a count of unknown credentials alone must not trigger an improvised lockdown.
Data Retention & Privacy
- Define access log retention period per regulatory requirements
- Restrict statistics access to authorized security personnel only
- Anonymize data when sharing for operational analysis
- Keep only authorized exports and archives, with their own access controls and retention rules.
- Have the responsible privacy team confirm the requirements applicable to the organization and site.