The Hidden Work of Access Control: The Thousands of Decisions Behind Every Open Door
The Hidden Work of Access Control: The Thousands of Decisions Behind Every Open Door

Most people experience access control in less than a second.
They tap a card. A door unlocks. They walk through. The interaction feels effortless.
What they don't see is the extraordinary amount of work required to make that moment happen safely, consistently, and reliably.
Across higher education, access control professionals spend their days balancing security and convenience, managing exceptions, auditing permissions, coordinating across departments, responding to emergencies, and maintaining systems that support thousands of students, faculty, staff, contractors, and visitors.
The technology may be visible. The work behind it usually is not.
Access Control Isn't Really About Technology
One of the most common misconceptions about access control is that it is primarily a technology function.
Steve Goodman of Brigham Young University believes that's exactly backwards.
"The biggest misconception is that access control is primarily a technology problem. In reality, it is a people, policy, governance, and risk management problem that happens to use technology as a tool."
Grant Culham from the University of Alberta encounters a similar misunderstanding.
"People think it's a single thing, or that it's somehow on their card."
In reality, access decisions are often driven by enrollment status, employment records, residence contracts, departmental approvals, event schedules, and institutional policies.
The card is simply the final piece of a much larger process.
Royce Tidwell of the University of Mississippi adds another important perspective.
"Access control is not the end all in security. It is necessary to couple it with other means such as video cameras and ensuring that equipment works."
Access control is not a standalone solution. It is one part of a larger security ecosystem that includes surveillance, alarms, emergency response procedures, audits, and governance.
The Infrastructure Most People Never See
The hidden work begins long before a permission is granted.
Eric Christensen of Johnson County Community College points out that most people never see the physical infrastructure required to support modern access control.
"People often don't realize that every access-controlled door on campus has anywhere from 10 to 16 wires weaving through the door, hinge, frame, or card reader all the way back to a head end tucked away in a closet."
Nor do most people realize the investment involved.
"The minimum cost for a standard electrified mortise lock is around $2,500, and if you need a crashbar, it jumps to at least $5,000, per bar."
When institutions talk about expanding access control, they are discussing far more than installing a card reader. They are investing in critical campus infrastructure that requires ongoing maintenance, upgrades, planning, and support.
As Culham noted, campuses often operate multiple access control systems simultaneously because different facilities require different integrations and operational capabilities.
Higher Education Runs on Exceptions
If standard permissions are the easy part of access control, exceptions are where most of the work happens.
- Faculty need after-hours access.
- Researchers need access to specialized labs.
- Contractors need temporary permissions.
- Student employees require access outside of standard roles.
- Retiring employees need transition periods.
- Events require buildings to remain open longer than usual.
- Departments request unique accommodations.
In higher education, there is almost always a reason why someone doesn't fit neatly into a standard access group.
As Goodman explains:
"Every exception may be legitimate, but every exception also introduces additional risk and administrative overhead."
Jay Bonney of Mercer University sees this every day.
"Standard permissions are more of a set-it-and-forget-it rollout. Exceptions can eat up a lot of work time in a day."
Deanna Cibery-Schaab of Western Connecticut State University perhaps summarized the challenge most directly:
"Access control is not intended to be flexible, and therefore frictions are inherent and expected, particularly in higher education where exceptions are the rule."
The hidden work of access control is often the work of carefully evaluating those exceptions while maintaining institutional security.
The Job Is Often Finding a Safe Way to Say Yes
One theme appeared consistently across every institution represented in this article - Access control professionals are not trying to prevent people from doing their jobs. They are trying to help people do their jobs safely.
Goodman explains:
"Our goal should not be to say 'no.' Our goal should be to find safe, practical, and sustainable ways to say 'yes' whenever possible."
But finding that safe "yes" often requires significant coordination.
At Western Connecticut State University, Cibery-Schaab described receiving a Saturday text message from an event director who had forgotten to request a building unlock for a dance recital.
The access control team remotely adjusted the building schedule and the event proceeded without disruption.
At Mercer University, Bonney described the extensive discussions that occurred when data closets were removed from broad master-access plans due to cybersecurity concerns.
At George Washington University, Emily Dieker regularly works through requests involving facilities personnel, IT staff, safety teams, and specialized research spaces where operational needs must be balanced against unique risks.
What appears simple from the outside often requires careful review behind the scenes.
Security and Convenience Are Constantly Competing
One reality every access control professional understands is that security and convenience do not always align.
Dieker puts it plainly:
"When convenience butts heads with security, you need to lean into the security side."
Bonney echoes that sentiment:
"Access control is a security inconvenience and it is okay to not keep doors unlocked."
Sometimes the challenge is not deciding whether someone should have access. It is deciding how much access they should have, when they should have it, and for how long.
At Johnson County Community College, Christensen recalls a request that initially seemed straightforward.
A dean proposed giving all instructors access to all classrooms. After review, the team discovered many classrooms contained hazardous materials, expensive equipment, automotive lifts, welding equipment, railroad training equipment, and specialized simulators.
The result was more than a week of reviewing over 1,000 access-controlled doors to determine what access could be granted safely. What sounded like a simple request became an exercise in balancing accessibility, safety, compliance, and risk.
Scheduling Is Security
Another hidden aspect of access control is schedule management. Most people assume buildings simply lock and unlock automatically. What they don't see are the countless schedule adjustments made throughout the year.
At the University of Mississippi, Tidwell spends a significant amount of time managing exceptions to normal schedules.
"A lot of time goes into managing schedule updates with opening early or closing late exceptions."
These adjustments may seem routine, but they help prevent buildings from remaining unsecured after events conclude.
As Tidwell explains:
"We prefer to ensure we have the doors scheduled to lock back down after the event. Our worry is that someone will forget to lock it back."
The public sees a building open when needed. The access control team sees dozens of decisions that ensured it would also be secure afterward.
Access Control Becomes Critical During Emergencies
Many people think access control is about locking doors.
Access control professionals think about emergencies.
At the University of Alberta, Culham noted that the ability to move buildings from open public access to credential-required access can significantly improve security during protests or large public gatherings while creating minimal disruption for students.
At George Washington University, Dieker emphasized how quickly access control systems can become critical tools during emergencies.
"Being able to quickly and remotely lock and unlock doors and make changes to access are game changers in emergencies."

Christensen described how Johnson County Community College uses emergency classroom lock functions, campus-wide lockdown capabilities, and dispatch notifications as part of its emergency response strategy.
The college tests these systems regularly to ensure they perform as expected when needed.
Future plans include deeper integration between access control and video surveillance systems so dispatchers can immediately view camera feeds associated with alarms and incidents.
As Goodman explains, modern access control systems are increasingly tied to intrusion detection, alarm monitoring, investigations, emergency response, and situational awareness.
When functioning properly, much of this capability remains invisible.
Audits May Be More Important Than Access
Granting access is important. Removing access is equally important.
Many contributors highlighted auditing, reporting, documentation, and governance as some of the most important—and least visible—aspects of their work.
Goodman noted:
"Most coordinators do an excellent job granting access when needed, but removing access when roles change or responsibilities end can be much more challenging."
At BYU, ongoing governance initiatives are focused on improving approvals, recertifications, auditing, and accountability.
At Mercer University, access requests require formal approval processes involving supervisors, department heads, and deans.
At Johnson County Community College, sensitive areas such as police facilities, vaults, human resources offices, and data centers generate regular reports showing who has access and who has used it.
As Goodman reminds us:
"One of the core principles of security is trust but verify."
The hidden work of access control is often less about granting permissions and more about continuously validating that those permissions remain appropriate.
No One Does This Work Alone

Access control may sit within a particular department, but successful programs are built through collaboration.
- Facilities teams maintain hardware.
- Human Resources manages employee transitions.
- Housing offices manage residential access.
- IT teams support integrations and infrastructure.
- Emergency management teams develop response plans.
- Police departments respond to incidents.
- Academic departments approve specialized access.
- Building coordinators manage local needs.
As Goodman observed:
"Effective access management requires partnerships across the institution because no single department has complete visibility into every operational need."
That collaboration becomes especially important during emergencies.
Cibery-Schaab recalled how Western Connecticut State University leveraged years of planning and infrastructure investment during the COVID pandemic to manage access remotely for faculty, staff, emergency medical personnel, and National Guard operations.
Without those systems in place, the university's response would have looked very different.
The Work Nobody Notices

Every day, access control professionals make thousands of decisions.
- They review requests,
- Manage exceptions,
- Audit permissions,
- Coordinate approvals,
- Support events,
- Maintain schedules,
- Prepare for emergencies,
- Protect sensitive spaces,
And ensure the right people have access to the right places at the right times.
Most of that work happens quietly.
In fact, the greatest compliment an access control team can receive may be the one Christensen described:
"The greatest compliment an access control program can receive is often silence."
Because when access control works well, people don't think about readers, permissions, audits, approvals, schedules, integrations, or emergency response plans.
They tap their credential. The door opens. And they move on with their day. Exactly as intended.

Special thanks to this blog post’s contributors:
- Jay Bonney, Mercer University
- Eric Christensen, Johnson Country Community College
- Grant Culham, University of Alberta
- Emily Dieker, George Washington University
- Steve Goodman, Brigham Young University
- Deanna Cibery-Schaab, Western Connecticut State University
- Royce Tidwell, University of Mississippi