Skip to content

Access-control migration guide

Upgrade access control with a documented transition.

Start with an inventory, confirm what can be retained and test one representative entrance before committing the wider site. Ask the questions below to clarify decisions, evidence and the handover to operators.

Inventory · Pilot · Cutover · Acceptance

Lexoh access equipment installation at Scotiabank Kingston
Scotiabank Kingston — LEXOH access installation.

Keep the site and the records together

What should be decided before the system changes?

Write down the entrances, user groups, operating hours and connected applications affected by the project. Name the owner of the existing system and the people authorized to approve the new scope. Agree which entrances are in the first phase and which remain on the current system.

Inventory physical equipment and access data separately. An approved reader interface does not prove that existing credentials, permissions, event records or integrations can be transferred. Record the evidence required for each decision and leave an item unresolved when the proposed supplier has not confirmed it.

A controlled sequence

Move from evidence to operator handover.

  1. Inventory

    Record exact equipment and the access data the project needs.

  2. Verify

    Classify each component as retain, replace or awaiting evidence.

  3. Pilot

    Test a representative opening against agreed acceptance criteria.

  4. Handover

    Approve the staged cutover, resolve defects and transfer responsibilities.

Retain or replace

What evidence supports a reuse decision?

Keep the manufacturer reference or test record beside the decision. Matching a connector, frequency or marketing label is insufficient to approve a complete credential-to-door path. The supplier must assess the actual combination and its support boundary.

Record the proposed decision for each component and data set
ItemEvidence to requestDecision to record
Reader and credential Exact reader model, credential technology/format and supported controller interface Retain, replace or test; identify the approved credential path
Controller and power Model/version, supported configuration, wiring and available power design Compatible arrangement, required changes and documented interruption behaviour
Door or barrier Condition, connected interfaces and selected installation instructions Retained hardware, preparation work and approved operating/exit requirements
Cabling and network Surveyed routes, terminations, connectivity and access responsibilities Usable existing paths, corrective work and the party completing it
Users and permissions Required fields, approved zones/schedules, source ownership and supported import method Data included, omissions, review owner and verification method
Connected applications Documented interface, version, authentication and support ownership Approved exchange, test evidence and responsibility for future changes

Move the right access rights

Review people and permissions before copying records.

An equipment inventory answers what can be connected. A permission review answers who should still be allowed through each entrance. Before preparing a transfer, have an authorized site owner approve the active users, zones, schedules and end dates. Keep the approved source and the transfer date together so a later joiner or departure is not missed.

Consider a fictional building whose old list includes an employee, a cleaner assigned to evenings and a contractor whose work has ended. Copying all three as unrestricted active users would change the intended access. The migration plan should retain the employee’s approved scope, verify the cleaner’s schedule and exclude or deactivate the contractor according to the owner’s decision.

Agree what should move before testing how it moves
Record to reviewDecision before transferCheck after transfer
Active user and credential Approve the owner, status and credential intended for reuse or replacement. Confirm the correct person and credential are associated without creating an unintended duplicate.
Zones and schedules Approve the required entrances, allowed days and time windows. Test an allowed use and an intentionally excluded entrance or time.
Temporary access Confirm the remaining start and end dates and whether access is still required. Verify the intended validity dates in the destination and test the agreed expiry workflow.
Historical events Decide which records need to remain available and who may consult them. Verify the agreed export or retained reference separately from current access permissions.

Pilot and cutover

What should a representative pilot prove?

Choose an opening that reflects the intended credential, controller and operating conditions. Agree the test window with the site operator and qualified installer. Test with authorized sample credentials and avoid exposing live personal records in shared project documents.

Before extending the rollout, record the expected result, observed result, evidence reference and approver for each check. If a required result fails, leave the item open and decide whether to correct the pilot, change the design or postpone the next phase. Passing one opening does not prove every site configuration.

  1. Normal and rejected access

    Verify the intended user, zone and schedule, an intentionally unauthorized credential and the physical response.

  2. Change and revoke

    Check a permitted credential change and revocation through the supported workflow, including the operator’s available record.

  3. Interruption and recovery

    Use an installer-approved procedure for the selected design. Record behaviour during the agreed condition and the operator’s recovery check.

  4. Assistance and rollback

    Name the contact, stop condition and authorized recovery or return-to-service procedure. A rollback plan is not proof that every change is reversible.

Illustrative planning example

Resolve one uncertain reader before repeating the change.

A fictional office wants to keep its main-entrance reader while replacing the management system. The survey records the reader model, credential type, controller and wiring, but the supplier has not confirmed that combination. The inventory therefore marks the reader 'awaiting evidence', not 'retained'.

The project team requests the relevant documents and a representative test. If the path is confirmed, it records the supporting reference and scopes the pilot. If it is not, the proposal includes a compatible replacement and any credential change.

Keep a phased site understandable

Give operators one clear change procedure while two systems coexist.

A phased rollout may leave the main entrance on the new system while another door stays on the existing one. Create a simple opening map showing which system controls each entrance, which credential users should present and who administers it. Give reception and support the same version so a rejected credential is directed to the correct owner.

For example, an employee may still use both entrances during the transition. When that employee leaves, the operator needs a documented way to remove the relevant access from each system still in service. Record the changes against the same departure request and confirm completion in both places. Do not assume that updating one system updates the other unless that exchange is included and verified.

  • Before each phase

    Confirm the affected entrances, users, working window and approved assistance arrangements. Distribute clear instructions showing when the new procedure starts.

  • During the overlap

    Keep the opening map and change record current. Route a credential problem to the system that controls the affected entrance, with its opening reference and the time of the attempt.

  • At the end of the phase

    Confirm accepted access tests, outstanding work and the next owner. Retire superseded credentials and accounts only when their remaining uses and required records have been resolved.

The operational finish

What should operators receive at handover?

Keep the final equipment inventory, approved configuration references, unresolved defects and acceptance record together. Name who can administer access and who supports the software, physical equipment and integrations after the installer leaves.

Verify the agreed operator actions with the actual roles. Confirm account transfer, support contacts, update responsibility, available exports and the treatment of old credentials and retained data. The agreement must state any record-retention or deletion requirements; this guide does not prescribe a retention period.

  • Record operator training and the person accepting the handover.
  • Confirm the final authority for credential creation, revocation and emergency procedures.
  • Close remaining defects or record their owner, target and operating restriction.
  • Retire old accounts and equipment only through the approved project process.

Project checklist

Questions to ask before retaining an existing access system’s components

Review equipment and data separately with the current system owner and proposed installer. A reuse decision should identify the exact item and supporting evidence.

  1. Which entrances and user groups are affected by the first phase?

    Ask for a phased scope identifying what changes and what remains on the current system. Confirm the operating hours and site contacts for each affected entrance.

  2. What are the exact models, versions and conditions of the existing devices?

    Request an inventory of readers, controllers, locks or barriers and power equipment, with label photographs and relevant documents. Flag unidentified or unsupported items.

  3. What proves that the retained reader, credential and controller work together?

    Ask for the supported format and interface, relevant model documentation and any representative test required. Matching frequency or connectors is not sufficient evidence.

  4. Can the existing wiring, power and network support the proposed arrangement?

    Request a site assessment and a clear list of corrective work. Confirm who supplies and maintains each connection after migration.

  5. Who owns the existing credential system and authorizes changes?

    Identify the party allowed to approve reuse, replacements and any sensitive credential administration. Agree a secure process for technical exchanges.

  6. Which users, permissions and records can actually be transferred?

    Ask for the supported method, required fields and known omissions. Confirm who reviews zones, schedules and active credentials before and after transfer.

  7. Which connected applications need a new interface or configuration?

    Request the documented data flow, supported versions, authentication and integration owner. Ask how changes in either system will be supported.

  8. Which items remain unresolved, and what would require replacement?

    Ask for the evidence still needed, the decision owner and the effect on the proposal. Keep an uncertain component open until its retained or replacement arrangement is confirmed.

Project checklist

Questions to ask before the pilot, cutover and handover

Agree the test plan and responsibilities with the qualified installation team before changing the live system. Use these questions to decide what must be demonstrated and accepted.

  1. Which opening is representative enough for the pilot?

    Ask how it reflects the intended credentials, controller and operating conditions. Confirm what the pilot can establish and which other configurations need separate checks.

  2. What results must the pilot demonstrate before the next phase?

    Request expected outcomes for permitted and rejected access, zones, schedules and credential changes. Agree what evidence and approval will allow the rollout to proceed.

  3. When can the change take place, and how will users be informed?

    Confirm the cutover window, entrances affected, visitor instructions and assistance contact. Ask who approves a schedule change if the site is not ready.

  4. How will interruption and recovery behaviour be demonstrated?

    Request a procedure approved for the selected equipment and site, with named participants. Confirm how local access, available events and restoration will be checked.

  5. What would stop the cutover or trigger the agreed recovery plan?

    Ask for the stop conditions, decision authority and authorized return-to-service procedure. Confirm which changes can be reversed and what restoration would require.

  6. How will old and replacement credentials be checked?

    Request the supported change and revocation process and the checks at affected entrances. Clarify any product-specific steps for phone replacement or encrypted-card reuse.

  7. What must operators receive and demonstrate at handover?

    Ask for training, administrative account ownership, final equipment records and support contacts. Have the intended operator roles perform the agreed everyday actions.

  8. Who accepts the work and follows up on unresolved defects?

    Confirm the approver, evidence retained and owner of each open item. Ask whether an open issue restricts operation or delays the next phase.

Migration questions

Resolve the product-specific questions before cutover.

What happens to a mobile credential when an employee changes phones?

The process depends on the credential product and the deployed system; do not assume an automatic transfer. First confirm whether that mobile method is part of the proposed scope. Ask who revokes the old credential, how the replacement is enrolled and what the operator must test. Record any phone or application requirements and available assistance before issuing the replacement.

Who must provide the credential-key information when existing encrypted cards are reused?

Identify the authorized owner or administrator of the existing credential system and involve the proposed supplier’s technical team. They must confirm the card technology, supported reader/controller arrangement and whether reuse is permitted and technically supported. Share sensitive material only through an approved secure process; keep secret keys out of general project correspondence. Matching frequency alone does not establish compatibility.

Does old access-event history have to be imported into the new system?

Not necessarily. Decide which historical records the organization needs, who must be able to consult them and for how long under its applicable requirements. Then confirm whether the destination supports the intended import or whether an agreed export or retained reference is more suitable. Test that the chosen records can be retrieved before retiring the old service; historical events and current access rights are separate migration decisions.

What should staff receive before their entrance moves to the new system?

Give affected users the entrance reference, change date, credential to use and the contact for assistance. Explain any temporary difference between entrances that change now and those that remain on the existing system. Have reception or the site operator confirm those instructions against the approved opening map. Include an agreed fallback contact so a rejected credential reaches someone who knows which system controls the door.

References and further reading

Prepare the review

Bring the inventory and the unresolved decisions.

LEXOH can review the intended access workflow and project boundaries with your team before the final transition scope is agreed.

Discuss an access upgrade
Call Lexoh 1-888-401-8019