Access Control Deployment Checklist
This article provides a checklist of items that should be considered when planning an Access Control project with SAFR.
Collect following information
- Card formats (i.e. Wiegand-26, HID Corp 1000 48 bit, etc.)
- Feature specific dependencies (i.e. Intercom or other features, PACS Integration)
Hardware
- Mounting to 2 or 4-gang box or we can recommend options for temporary mounting
- 55” height to bottom of reader is ideal. 20° Wedge mount available if needed. Lower mount height of 42 to 58"" is supported but anti-spoofing deetection speed will be slower.
- Optionally flush mount for mounting into drywall
- If outdoor, plan for waterproof gang box and conduit as needed and plan. See QuickStart guide for outdoor installation requirements.
- POE Ethernet (or DC power if no POE switch)
- An alternative is to us 2N 2Wire Ethernet to Two-Wire Adapter or equivalent solution to send Ethernet and power over existing available low voltage wiring. Input is either 12V + Ethernet and Output is either POE or Ethernet + 12V.
- 22 gage wiring to panel
- If OSDP – 3 wires will cover it all
- If Wiegand, 3 wires + 1 extra for LED feedback
- With either OSDP or Wiegand, ground is critical. Ground should be to reliable earth ground.
- Optionally run door contact to reader for tailgating detection on exit
- If using external reader, plan for necessary wiring and power
- Option 1: Both SAFR and Ext Reader share same wiring (SAFR 2FA Access modes not supported)
- Option 2: Ext Reader wired into SAFR OSDP or Weigand Inputs
- With either option, external readers must be powered thru panel (SAFR does not provide power)
- Reader should always be grounded to earth ground to avoid issues due to static shock.
Software
- SAFR Server will need PC with at least 4 cores and 16 GB RAM for up to 20 readers.
- If >20 readers, consult SAFR Support or your SAFR Account Manager
- Software will connect access control system to reader for sync’ing person records
- Check that the SAFR and Access Control System software versions support cardholder sync
- Identify any security software or policies that might block SAFR software instlalation or function. It is becoming more commonplace to have software such as CloudStrike prevent installation or some softwares may even block specific calls into Windows DLLs.
- Identify reporting requirements? Will reporting of access denied or tailgating to access control system be required?
Licensing
- SAFR Software license is included with hardware
- If multiple sites with server at each site, 1 license per site is required (still included with purchase of hardware)
- PACS Integration licensing (SAFR license for integration is included but PACS may charge for API connections)
Networking – connectivity from reader to safr software
- https://support.safr.com/kb/default-ports-used-by-safr
- Consider Network connection from SAFR Server to PACS Software or vice versa; varies by integration.
Offsite Preparation
It is recommended to test the complete integration (PACS software - SAFR software - SAFR SCAN -> Panel) before going on site. Ideally with a system that is configured identically to customer system including networking and security software. This will allow you to uncover integration requirements that may require consultation from SAFR Support such as custom card formats. There may still be environmental factors that block installation on site (networking is the most common).
- Install SAFR Software and connect to access control system. Validate cardholder sync and that cardholders arrive in SAFR correctly. Consider the following:
- Confirm expected count of cardholders after full sync completes
- Confirm incremental sync working
- Make change to person name and confirm change in SAFR within 5 seconds
- Make change to credential and confirm change in SAFR within 5 seconds
- Photo is in SAFR and of good quality (See Face Enrollment Guide)
- Credentials are added to SAFR.
- Confirm cardholders with mulitple credentials
- Check credentials that shold not be added to SAFR. If so, see if credential filtering exists for your PACS itegration
- If sync'ing Access Rules and Doors, check they are added to SAFR (as Access Clearances and Zones)
- Validate face matching
- Check person is recognized - If failure, consult SAFR documentation. May be various factors but most likely is person not sync'ed to reader
- Check access granted - Can also be many factors such as failed anti-spoofing checks, access clearances, poor quality enrolled face image. Consult SAFR docs.
- Test in lighting conditions similar to what will exist at site. E.g. outdoors, indoors with strong lighting.
- Wire SCAN to panel and validate
-
- if OSDP, validate secure connection
- Validate access granted
- Validate credentials received by panel
- Enable and test Panel Feedback - Panel feedback is strongly recommended to ensure the most up to date evaluation of access is made for a cardholder - this is especially true if SAFR SCAN door relay is used to open the door.
Many things can cause issues with transmitting credentials to panel. Consult SAFR support if become blocked after reasonable troubleshooting. Consult SAFR documentation. Following articles may be useful:
https://support.safr.com/kb/how-to-interpret-debug-logging-for-access-card-readshttps://support.safr.com/kb/safr-scan-card-format-formats-behavior
Installation time
- Consult SAFR Quick Start Guide for installation and configuration guideance
- Physical mounting – Varies by deployment
- Software – Allocate 2 hours
- Configuration – Varies by integration. As long as reader to panel connection was validated offsite, the most significant factor is lighting but there are many other things that could go wrong. In best case scenario, it may only take 30 minutes per reader.
- Optional functions – video to VMS?, watchlist alerting
- Testing – Have people available to test various required inputs