{"id":1078,"date":"2026-08-18T07:35:03","date_gmt":"2026-08-18T07:35:03","guid":{"rendered":"https:\/\/qudify.co\/blogs\/?p=1078"},"modified":"2026-09-07T07:15:01","modified_gmt":"2026-09-07T07:15:01","slug":"access-control-integration-with-vms-a-step-by-step-guide","status":"publish","type":"post","link":"https:\/\/qudify.co\/blogs\/2026\/08\/18\/access-control-integration-with-vms-a-step-by-step-guide\/","title":{"rendered":"Access Control Integration with VMS: A Step-by-Step Guide"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"1078\" class=\"elementor elementor-1078\">\n\t\t\t\t<article class=\"elementor-element elementor-element-cef4b1d e-con e-atomic-element e-flexbox-base e-098764d \" data-id=\"cef4b1d\" data-element_type=\"e-flexbox\" data-e-type=\"e-flexbox\" data-interaction-id=\"cef4b1d\">\n    \t\t\t<h1 data-interaction-id=\"b39bf61\" class=\"e-b39bf61-b44191d e-heading-base\"><strong>Access Control Integration with VMS: A Step-by-Step Guide<\/strong><\/h1>\n\t\t\t\t<div class=\"elementor-element elementor-element-570296d elementor-widget elementor-widget-image\" data-id=\"570296d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/1-9.png\" class=\"attachment-full size-full wp-image-1081\" alt=\"Qudify header graphic titled VMS Access Control Integration: A Step-by-Step Guide, illustrating a corporate reception area with a receptionist at a desk checking in a visitor carrying a briefcase, and another person reading on a red sofa.\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/1-9.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/1-9-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/1-9-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/1-9-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/1-9-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-7980e23-cc867f3 e-divider-base\" data-interaction-id=\"7980e23\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"5311e1a\" class=\"e-5311e1a-225b666 e-heading-base\"><strong>Key Takeaways<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-1833b0c elementor-widget elementor-widget-text-editor\" data-id=\"1833b0c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>&#8220;VMS&#8221; is ambiguous, and the ambiguity mis-scopes projects.<\/b><span style=\"font-weight: 400;\"> It means <\/span><i><span style=\"font-weight: 400;\">Visitor<\/span><\/i><span style=\"font-weight: 400;\"> Management System in facilities contexts and <\/span><i><span style=\"font-weight: 400;\">Video<\/span><\/i><span style=\"font-weight: 400;\"> Management System in the surveillance industry. Both integrate with access control. Confirm which one your RFP means before anyone quotes.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Integration is three operations:<\/b><span style=\"font-weight: 400;\"> provision a credential at check-in, stream door events back, revoke automatically when the visit ends.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Automatic revocation is the whole ballgame.<\/b><span style=\"font-weight: 400;\"> Everything else is configuration.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Four connection methods<\/b><span style=\"font-weight: 400;\"> native connector, REST API, PIAM middleware, file sync differ by an order of magnitude in cost, speed, and risk.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Wiegand undoes good software.<\/b><span style=\"font-weight: 400;\"> A perfectly scoped digital pass is theatre if the reader still transmits the card number in plain text.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Integration complexity, not budget, is the top barrier<\/b><span style=\"font-weight: 400;\"> to identity projects (52%, per <\/span><a href=\"https:\/\/newsroom.hidglobal.com\/hids-2026-state-security-and-identity-report-identity-convergence-drives-new-focus-trust-protection\"><span style=\"font-weight: 400;\">HID&#8217;s 2026 research<\/span><\/a><span style=\"font-weight: 400;\">).<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Multi-tenant towers have two access control systems and two owners.<\/b><span style=\"font-weight: 400;\"> Sort out who is the Data Fiduciary before you sort out the API.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Nobody owns this project by default.<\/b><span style=\"font-weight: 400;\"> IT owns the API, Security owns the doors, Admin owns the front desk. Name one accountable person, or it stalls.<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dbe35c1 elementor-widget elementor-widget-text-editor\" data-id=\"dbe35c1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Most buildings already own both halves of the system. A visitor management system at the front desk records who is walking in. An access control system decides which doors actually open. In most buildings, the two have never spoken to each other.<\/span><\/p><p><span style=\"font-weight: 400;\">The result is a gap you can physically walk through. A visitor registers digitally. A guard then pulls a plastic card from a drawer and hands it over. Nobody records which card. Nobody takes it back. The digital log says the visitor left at 4:00 PM. The card in their pocket still opens the third-floor door on Saturday night.<\/span><\/p><p><b>Integrating access control with a visitor management system means three things:\u00a0<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>the visitor&#8217;s check-in automatically creates a credential in the access control system,\u00a0<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>door events flow back into the visitor log, and\u00a0<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>the credential dies on its own when the visit ends.<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Everything in this guide is in service of that third point.<\/span><\/p><p><span style=\"font-weight: 400;\">What follows: the architecture, the four ways to connect the systems, the protocol constraint that decides whether the connection is actually secure, a ten-step implementation sequence, what it costs, and who has to own it.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-794aeec-4ff793f e-divider-base\" data-interaction-id=\"794aeec\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"bbfaaaf\" class=\"e-bbfaaaf-eca6433 e-heading-base\"><strong>What Does \"VMS\" Mean in an Access Control Project?<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-4d07db0 elementor-widget elementor-widget-text-editor\" data-id=\"4d07db0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This is not pedantry. It is the single most common cause of a mis-scoped security purchase.<\/span><\/p><p><b>Visitor Management System<\/b><span style=\"font-weight: 400;\"> governs people at the entrance: pre-registration, host approval, ID capture, consent, screening, digital passes, and the entry-exit audit trail. It answers <\/span><i><span style=\"font-weight: 400;\">who is allowed in, why, and for how long.<\/span><\/i><span style=\"font-weight: 400;\"> This is where Qudify operates, and it is the subject of this guide.<\/span><\/p><p><b>Video Management System<\/b><span style=\"font-weight: 400;\"> governs cameras and footage: live view, playback, analytics, retention, evidence export. It answers <\/span><i><span style=\"font-weight: 400;\">what actually happened at that door.<\/span><\/i><span style=\"font-weight: 400;\"> Milestone XProtect, Genetec Omnicast and Avigilon Control Centre sit here.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"0a0d422\" class=\"e-0a0d422-7a8d5a5 e-heading-base\"><strong>The Division of Labour<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-e9e846b elementor-widget elementor-widget-text-editor\" data-id=\"e9e846b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Access control is the connective tissue both plug into:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Visitor Management decides WHO.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Access Control enforces the DOOR.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Video Management proves WHAT HAPPENED.<\/b><\/li><\/ul><p><span style=\"font-weight: 400;\">A visitor system integrates with access control to issue and revoke. A video system integrates with access control to correlate. Build only one of those links, and you have half a system. Steps 1-8 below build the first link. Step 9 bolts on the second.<\/span><\/p><p><span style=\"font-weight: 400;\">New to the category entirely? Start with our primer on<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/06\/26\/what-is-a-visitor-management-system-and-why-every-indian-office-needs-one-in-2026\/\"> <span style=\"font-weight: 400;\">what a visitor management system is and why every Indian office needs one in 2026<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-6c171c8-849f5be e-divider-base\" data-interaction-id=\"6c171c8\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"14554e6\" class=\"e-14554e6-d52609e e-heading-base\"><strong>Why Integrate at All?&nbsp;<\/strong><\/h2>\n\t\t\t\t\t<h3 data-interaction-id=\"2abdd6d\" class=\"e-2abdd6d-2a7fffc e-heading-base\"><strong>What Breaks Without It<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-fa5c083 elementor-widget elementor-widget-text-editor\" data-id=\"fa5c083\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">An unintegrated front desk fails in a specific way: it verifies identity, then hands over an anonymous key.<\/span><\/p><p><span style=\"font-weight: 400;\">The mechanism is tailgating. In an industry survey <\/span><a href=\"https:\/\/www.securityinfowatch.com\/access-identity\/access-control\/article\/21277663\/close-the-door-on-tailgating\"><span style=\"font-weight: 400;\">reported by SecurityInfoWatch<\/span><\/a><span style=\"font-weight: 400;\">, 48% of respondents said they had experienced a tailgating violation, and around 70% believed a breach at their own facility due to tailgating was somewhat to very likely. The cost estimates are blunt: per the Security, Resiliency &amp; Technology Integration Forum,<\/span><a href=\"https:\/\/www.density.io\/resources\/tailgating-security-breach\"> <span style=\"font-weight: 400;\">41% of security executives<\/span><\/a><span style=\"font-weight: 400;\"> put the cost of tailgating somewhere between $2 million and &#8220;too high to measure&#8221;.<\/span><\/p><p><span style=\"font-weight: 400;\">The deeper problem is that physical access defeats digital defence. A stranger sitting at an unlocked desk renders a great deal of expensive network security decorative.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"53f2623\" class=\"e-53f2623-00137b1 e-heading-base\"><strong>The India Stake<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-5befe72 elementor-widget elementor-widget-text-editor\" data-id=\"5befe72\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Two clocks are running.<\/span><\/p><p><b>Breach cost:<\/b><a href=\"https:\/\/in.newsroom.ibm.com\/2025-08-07-India-Records-Highest-Average-Cost-of-a-Data-Breach-IBM\"> <span style=\"font-weight: 400;\">IBM&#8217;s Cost of a Data Breach 2025<\/span><\/a><span style=\"font-weight: 400;\"> put India&#8217;s average organisational breach cost at \u20b9220 million (about USD 2.51 million), an all-time high, roughly 13% above 2024.<\/span><\/p><p><b>Regulation:<\/b><span style=\"font-weight: 400;\"> The DPDP Rules were<\/span><a href=\"https:\/\/static.pib.gov.in\/WriteReadData\/specificdocs\/documents\/2025\/nov\/doc20251117695301.pdf\"> <span style=\"font-weight: 400;\">notified on 14 November 2025<\/span><\/a><span style=\"font-weight: 400;\"> with an eighteen-month phased implementation.<\/span><a href=\"https:\/\/www.amsshardul.com\/insight\/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules\/\"> <span style=\"font-weight: 400;\">Shardul Amarchand Mangaldas maps three enforcement dates<\/span><\/a><span style=\"font-weight: 400;\">: 14 November 2025, 14 November 2026, and 14 May 2027, when substantive obligations bite. Penalties run to \u20b9250 crore.<\/span><\/p><p><span style=\"font-weight: 400;\">Visitor data name, phone, photograph, ID, purpose, and now a movement history across your building is squarely personal data. The un-integrated model collects <\/span><i><span style=\"font-weight: 400;\">more<\/span><\/i><span style=\"font-weight: 400;\"> of it (photocopied IDs) while proving <\/span><i><span style=\"font-weight: 400;\">less<\/span><\/i><span style=\"font-weight: 400;\"> about it (no consent record, no retention policy, no exportable log). Integration lets you invert both.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"19484fa\" class=\"e-19484fa-49e7f5e e-heading-base\"><strong>What the Market Is Doing<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-efa4c48 elementor-widget elementor-widget-text-editor\" data-id=\"efa4c48\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><a href=\"https:\/\/www.genetec.com\/a\/physical-security-report\"><span style=\"font-weight: 400;\">Genetec&#8217;s 2026 State of Physical Security Report<\/span><\/a><span style=\"font-weight: 400;\">, drawn from 7,368 respondents across six regions, found more than 70% now run unified or integrated systems, and 60% say their main reason for replacing legacy technology is to integrate new capabilities. Genetec&#8217;s VP of Product Engineering, Christian Morin, frames the shift by observing that &#8220;security is emerging as a genuine enabler of business outcomes&#8221;.<\/span><\/p><p><span style=\"font-weight: 400;\">On the identity side,<\/span><a href=\"https:\/\/newsroom.hidglobal.com\/hids-2026-state-security-and-identity-report-identity-convergence-drives-new-focus-trust-protection\"> <span style=\"font-weight: 400;\">HID&#8217;s 2026 State of Security and Identity Report<\/span><\/a><span style=\"font-weight: 400;\"> found 73% rank identity management as their top priority and 74% have deployed or plan to deploy mobile credentials, but 52% name integration complexity as the primary barrier. HID CTO Ramesh Songukrishnasamy describes the winning approach as &#8220;giving stakeholders meaningful solution choice while maintaining robust security.&#8221; In other words: the appetite is there, the wiring is the problem.<\/span><\/p><p><span style=\"font-weight: 400;\">The two markets are converging from different scales.<\/span><a href=\"https:\/\/www.mordorintelligence.com\/industry-reports\/visitor-management-system-market\"> <span style=\"font-weight: 400;\">Mordor Intelligence<\/span><\/a><span style=\"font-weight: 400;\"> sizes the visitor management market at USD 2.39 billion in 2026, reaching USD 4.22 billion by 2031 (12.05% CAGR).<\/span><a href=\"https:\/\/www.marketsandmarkets.com\/Market-Reports\/access-control-market-164562182.html\"> <span style=\"font-weight: 400;\">MarketsandMarkets<\/span><\/a><span style=\"font-weight: 400;\"> puts access control at roughly USD 10.62 billion in 2025, reaching USD 15.80 billion by 2030 (~8.3%). Access control is bigger, slower, and hardware-heavy. Visitor management is smaller, faster, and software-native. The integration layer is where they meet.<\/span><\/p><p><span style=\"font-weight: 400;\">In India, the pressure is physical.<\/span><a href=\"https:\/\/www.jll.com\/en-in\/newsroom\/india-s-office-market-scales-unprecedented-highs-with-gross-leasing-activity-at-83-3-million-sq-ft-for-the-year-2025-jll\"> <span style=\"font-weight: 400;\">JLL recorded a record 83.3 million sq ft of gross office leasing in 2025<\/span><\/a><span style=\"font-weight: 400;\">, with Global Capability Centres taking a 37.7% share. Every one of those floors is a new set of doors, turnstiles and daily visitor flows.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Caveat worth stating plainly: HID and Genetec both publish vendor-run industry surveys, not independently audited studies. Read them as directional signals of where budgets are moving.<\/span><\/i><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-ab66c18-5f1e79c e-divider-base\" data-interaction-id=\"ab66c18\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"29be0fe\" class=\"e-29be0fe-ad8c05f e-heading-base\"><strong>How Does the Integration Actually Work?&nbsp;<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-8673794 elementor-widget elementor-widget-image\" data-id=\"8673794\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/2-6.png\" class=\"attachment-full size-full wp-image-1082\" alt=\"\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/2-6.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/2-6-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/2-6-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/2-6-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/2-6-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"e3ffdb4\" class=\"e-e3ffdb4-81853cf e-heading-base\"><strong>What Happens at Run Time<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-2365f4f elementor-widget elementor-widget-text-editor\" data-id=\"2365f4f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Seven stages, of which only three are new engineering.<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Visitor pre-registers or arrives and checks in.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Consent is captured and recorded.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screening runs against watchlists.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host approves.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>The VMS calls the access control system and provisions a credential<\/b><span style=\"font-weight: 400;\">, scoped to specific zones and a specific time window.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Door events stream back<\/b><span style=\"font-weight: 400;\"> into the visitor record as the visitor moves.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>The credential is revoked<\/b><span style=\"font-weight: 400;\"> on check-out, on timeout, or manually.<\/span><\/li><\/ol><p><span style=\"font-weight: 400;\">Stages 1-4 already happen inside any competent visitor system. Stages 5\u20137 are what integration buys: a credential that is <\/span><i><span style=\"font-weight: 400;\">enforceable at the door<\/span><\/i><span style=\"font-weight: 400;\">, <\/span><i><span style=\"font-weight: 400;\">observable in the log<\/span><\/i><span style=\"font-weight: 400;\">, and <\/span><i><span style=\"font-weight: 400;\">self-terminating<\/span><\/i><span style=\"font-weight: 400;\">.<\/span><a href=\"https:\/\/envoy.com\/access-control\"> <span style=\"font-weight: 400;\">Envoy describes the same pattern<\/span><\/a><span style=\"font-weight: 400;\">: check-in triggers credential distribution based on predefined permissions, and badge events flow back for occupancy visibility.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"ff733c8\" class=\"e-ff733c8-9f05cc7 e-heading-base\"><strong>What Is a \"Credential,\" Exactly?<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-4faccdd elementor-widget elementor-widget-text-editor\" data-id=\"4faccdd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This trips up almost every first-time integration, so be precise. Inside a physical access control system (PACS), three distinct objects are usually involved:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>The cardholder record:<\/b><span style=\"font-weight: 400;\"> the person. Name, ID, photo.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>The credential:<\/b><span style=\"font-weight: 400;\"> the token (card number, mobile ID, QR payload) bound to that cardholder.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>The access group\/access level:<\/b><span style=\"font-weight: 400;\"> the permission set that says which doors, on which schedule.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Your integration must create or update all three, and revoke at least the credential. A common failure is provisioning the credential but never touching the access group, so the visitor exists in the system and can open nothing. The reverse failure deleting the cardholder but leaving an orphaned credential live is worse.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"a087186\" class=\"e-a087186-dea0ebc e-heading-base\"><strong>What Are the Four Ways to Connect the Systems?<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-5e435b5 elementor-widget elementor-widget-text-editor\" data-id=\"5e435b5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Method<\/b><\/p><\/td><td><p><b>How it works<\/b><\/p><\/td><td><p><b>Time to deploy<\/b><\/p><\/td><td><p><b>Risk<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Native\/certified connector<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Pre-built by one or both vendors<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">3\u20137 days<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Low<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">REST API + webhooks<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Your VMS calls the PACS API; PACS pushes events back<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">2\u20136 weeks<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Medium<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">PIAM middleware<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">A broker sits between many VMS and many PACS, enforcing policy centrally<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">1\u20133 months<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Medium (high cost)<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">File\/database sync<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Scheduled CSV drops or direct database writes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Days<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">High<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-00f39b1 elementor-widget elementor-widget-text-editor\" data-id=\"00f39b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">File sync deserves a warning: it is not real-time, it is hard to secure, and it breaks silently. Treat it as a bridge with an expiry date, never as an architecture.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-2b567e7-3135bf3 e-divider-base\" data-interaction-id=\"2b567e7\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"af7fb76\" class=\"e-af7fb76-7f8c5dd e-heading-base\"><strong>Wiegand, OSDP and ONVIF: The Protocol Layer That Decides Security<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-f91e23d elementor-widget elementor-widget-text-editor\" data-id=\"f91e23d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Above the API, everything is software. Below it, physics takes over, and this is where most &#8220;integrated&#8221; systems are quietly insecure.<\/span><\/p><p><b>Wiegand<\/b><span style=\"font-weight: 400;\"> has connected readers to controllers since the 1980s. It is unencrypted, transmits in plain text, is one-way only, cannot supervise the reader for tamper or failure, and imposes distance limits. A card number sniffed off a Wiegand line can be replayed trivially.<\/span><\/p><p><b>OSDP<\/b><span style=\"font-weight: 400;\"> was developed by the<\/span><a href=\"https:\/\/www.securityindustry.org\/industry-standards\/open-supervised-device-protocol\/\"> <span style=\"font-weight: 400;\">Security Industry Association<\/span><\/a><span style=\"font-weight: 400;\"> to replace it. It is a two-way command-response protocol over RS-485, became an international standard (IEC 60839-11-5) in 2020, and, with Secure Channel, uses AES-128 encryption so data is never transmitted the same way twice. Two wires instead of six-plus, multi-drop support for anti-passback, cable runs to 4,000 feet. SIA recommends broad adoption, particularly in high-security and government settings.<\/span><\/p><p><b>ONVIF<\/b><span style=\"font-weight: 400;\"> handles cross-vendor interoperability.<\/span><a href=\"https:\/\/www.onvif.org\/profiles\/onvif-profile-a\/\"> <span style=\"font-weight: 400;\">Profile A<\/span><\/a><span style=\"font-weight: 400;\"> covers access control configuration credentials, access rules, and schedules. Profile C covers door control and event management. Profile D covers peripherals.<\/span><a href=\"https:\/\/www.onvif.org\/profiles\/\"> <span style=\"font-weight: 400;\">Access control systems use Profiles A, C, D, and M<\/span><\/a><span style=\"font-weight: 400;\">; video systems use D, G, M, S, and T. One caveat: conformance supports interoperability for the specified profile features but does <\/span><b>not<\/b><span style=\"font-weight: 400;\"> guarantee two devices from different manufacturers will work together perfectly. Verify against the ONVIF Conformant Products List, then test anyway.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-528cddb-ee95c8c e-divider-base\" data-interaction-id=\"528cddb\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"0437ea4\" class=\"e-0437ea4-e6738a6 e-heading-base\"><strong>Step-by-Step: Integrating Access Control With Your Visitor Management System&nbsp;<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-cb3aa45 elementor-widget elementor-widget-image\" data-id=\"cb3aa45\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/3-6.png\" class=\"attachment-full size-full wp-image-1083\" alt=\"\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/3-6.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/3-6-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/3-6-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/3-6-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/3-6-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"a022e31\" class=\"e-a022e31-d399f03 e-heading-base\"><strong>Step 1: Map Entry Points and Access Zones<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-8680c80 elementor-widget elementor-widget-text-editor\" data-id=\"8680c80\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Walk the building with a floor plan. Record every controlled point: lobby turnstiles, lift lobbies, floor doors, server rooms, labs, warehouses, parking barriers, service entrances.<\/span><\/p><p><span style=\"font-weight: 400;\">Then group them into <\/span><b>access zones:<\/b><span style=\"font-weight: 400;\"> sets of doors sharing one permission. &#8220;Ground floor public.&#8221; &#8220;Floor 4 tenant.&#8221; &#8220;Data centre.&#8221; &#8220;Loading bay.&#8221; Most buildings need four to ten. If you are designing thirty, you are listing doors, not zones.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"c090089\" class=\"e-c090089-f1d33a7 e-heading-base\"><strong>Step 2: Audit the Access Control System<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-629a54d elementor-widget elementor-widget-text-editor\" data-id=\"629a54d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Five facts, and vendors are often vague about all five.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7955423 elementor-widget elementor-widget-text-editor\" data-id=\"7955423\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>What to find out<\/b><\/p><\/td><td><p><b>Why it decides the project<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Controller make, model, firmware<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Old firmware often means no API at all<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Reader-to-controller protocol<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Determines whether the credential is secure in transit<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">API availability and documentation quality<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">An &#8220;API&#8221; that is really a database schema is not an API<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cardholder capacity and credential format<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Some panels cap active credentials; visitors churn fast<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cloud-managed or air-gapped on-premise<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cloud panels integrate in days; air-gapped may need middleware<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c6aca3f elementor-widget elementor-widget-text-editor\" data-id=\"c6aca3f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Ask for the API documentation <\/span><i><span style=\"font-weight: 400;\">before<\/span><\/i><span style=\"font-weight: 400;\"> you sign anything. If it cannot be produced within a week, that is your answer.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"1dc1468\" class=\"e-1dc1468-c437769 e-heading-base\"><strong>Step 3: Pick the Integration Method<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-1c24634 elementor-widget elementor-widget-text-editor\" data-id=\"1c24634\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A decision tree, in order. Stop at the first yes.<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Does a native connector exist for your exact PACS version? \u2192 <\/span><b>Use it.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Does your PACS expose documented credential create\/revoke endpoints plus a webhook or polling mechanism? \u2192 <\/span><b>Build the API integration.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multiple sites, multiple PACS vendors, complex approval policy? \u2192 <\/span><b>PIAM middleware.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">None of the above? \u2192 <\/span><b>File sync, with a written replacement deadline.<\/b><\/li><\/ol><p><span style=\"font-weight: 400;\">Record which you chose and why. That document is what you will argue with in month six.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"d3f47f6\" class=\"e-d3f47f6-cea30e3 e-heading-base\"><strong>Step 4: Design the Credential Model<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-3201690 elementor-widget elementor-widget-text-editor\" data-id=\"3201690\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">What does the visitor physically present at the door?<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>QR on the visitor&#8217;s own phone:<\/b><span style=\"font-weight: 400;\"> nothing to issue, nothing to return, nothing to lose. Needs QR-capable readers or turnstiles. This is the model Qudify is built around.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Mobile credential (Apple\/Google Wallet, BLE\/NFC):<\/b><span style=\"font-weight: 400;\"> excellent experience, needs compatible readers and usually a per-credential licence.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>PIN \/ one-time code:<\/b><span style=\"font-weight: 400;\"> cheap, works with keypads, weakest.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Temporary physical card<\/b><span style=\"font-weight: 400;\"> familiar to guards, and reintroduces every problem you are trying to solve.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Plan for a mixed estate, not a clean cutover: <\/span><a href=\"https:\/\/newsroom.hidglobal.com\/hids-2026-state-security-and-identity-report-identity-convergence-drives-new-focus-trust-protection\"><span style=\"font-weight: 400;\">HID found <\/span><b>84%<\/b><\/a><b> of end users still maintain physical credentials alongside their mobile deployment<\/b><span style=\"font-weight: 400;\">. Your access rules must handle both.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"e589bf1\" class=\"e-e589bf1-b481f39 e-heading-base\"><strong>Step 5: Write the Access Rules<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-784b1ab elementor-widget elementor-widget-text-editor\" data-id=\"784b1ab\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Most integrations get lazy here and create one catch-all &#8220;VISITOR&#8221; level that opens everything. Build a matrix instead.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1705f4e elementor-widget elementor-widget-text-editor\" data-id=\"1705f4e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Visitor type<\/b><\/p><\/td><td><p><b>Zones granted<\/b><\/p><\/td><td><p><b>Time window<\/b><\/p><\/td><td><p><b>Escort<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Meeting guest<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Lobby, lift lobby, host&#8217;s floor<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Appointment \u00b1 60 min<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Interview candidate<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Lobby, HR floor only<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Appointment \u00b1 30 min<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Contractor\/ vendor<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Lobby, service lift, one work zone<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Shift window<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes, in restricted zones<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Delivery\/courier<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Lobby, loading bay only<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">15 min from check-in<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Auditor \/ VIP<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Broad, pre-approved by security head<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Full-day<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Long-term consultant<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Staff zones minus restricted<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Contract end date<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a5f91c8 elementor-widget elementor-widget-text-editor\" data-id=\"a5f91c8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Turn on <\/span><b>anti-passback<\/b><span style=\"font-weight: 400;\"> while you are here. This is the rule that actually addresses tailgating, and it is almost always left off. Anti-passback prevents a credential being used to enter twice without an intervening exit read, so a card cannot be passed back through the turnstile to a second person.<\/span><\/p><p><span style=\"font-weight: 400;\">Pair it with physical enforcement speed gates, one-person-per-credential turnstiles, mantrap vestibules and, in high-consequence zones, occupancy sensors that count bodies against badge events. Integration alone makes tailgating <\/span><i><span style=\"font-weight: 400;\">visible<\/span><\/i><span style=\"font-weight: 400;\">. These rules are what make it <\/span><i><span style=\"font-weight: 400;\">stop<\/span><\/i><span style=\"font-weight: 400;\">.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"3b39dcd\" class=\"e-3b39dcd-2ab2434 e-heading-base\"><strong>Step 7: Configure and Field-Map the Link<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-eeb0210 elementor-widget elementor-widget-text-editor\" data-id=\"eeb0210\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Generate API credentials in the PACS scoped to the <\/span><b>minimum<\/b><span style=\"font-weight: 400;\"> permissions needed: create credential, revoke credential, read events. Never an admin account.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Map fields explicitly:<\/span> <b>visitor_id<\/b><b> \u2192 <\/b><b>cardholder_id<\/b><b>, <\/b><b>access_zone<\/b><b> \u2192 <\/b><b>access_group<\/b><b>, <\/b><b>valid_from<\/b><b>\/<\/b><b>valid_until<\/b><b> \u2192 <\/b><b>activation_date<\/b><b>\/<\/b><b>deactivation_date<\/b><b>.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure the webhook endpoint, or the polling interval if the PACS cannot push.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Add retry logic with exponential backoff, and a dead-letter queue for permanent failures.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Alert on failure; do not merely log it.<\/b><p>\u00a0<\/p><\/li><\/ul><p><span style=\"font-weight: 400;\">Field mapping is where integrations rot. A firmware update renames a field, provisioning starts failing, and nobody notices for a week because the failures went into a log file nobody reads.\u00a0<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"b30e336\" class=\"e-b30e336-e69f495 e-heading-base\"><strong>Step 8&nbsp; Wire Up Revocation<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-8530e4e elementor-widget elementor-widget-text-editor\" data-id=\"8530e4e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><p><span style=\"font-weight: 400;\">This is the step that separates a real integration from a demo. Configure three independent triggers, because relying on one of them means relying on the visitor&#8217;s cooperation.<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Check-out.<\/b><span style=\"font-weight: 400;\"> Visitor scans out; the credential dies immediately.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Timeout.<\/b><span style=\"font-weight: 400;\"> The visitor never scans out; this is the normal case, not the exception. The credential expires at <\/span><span style=\"font-weight: 400;\">valid_until<\/span><span style=\"font-weight: 400;\"> regardless. Make this a hard stop, not a warning.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Emergency revoke.<\/b><span style=\"font-weight: 400;\"> Security can kill any active visitor credential across every door, from one screen, instantly.<\/span><\/li><\/ol><p><span style=\"font-weight: 400;\">Then answer the auditor&#8217;s question before the auditor asks it: <\/span><b>can you produce a list of every currently active visitor credential, right now, in under a minute?<\/b><span style=\"font-weight: 400;\"> If you cannot, your revocation logic is not trustworthy. Build that report before go-live, not after.<\/span><\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"5ceb760\" class=\"e-5ceb760-45f67ec e-heading-base\"><strong>Step 9: Add the Video Layer<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-076638a elementor-widget elementor-widget-text-editor\" data-id=\"076638a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><p><span style=\"font-weight: 400;\">Two capabilities carry most of the value:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Event-linked video:<\/b><span style=\"font-weight: 400;\"> every badge event automatically retrieves the clip from that door at that timestamp. Investigations stop involving manual timeline scrubbing.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Video-verified access<\/b><span style=\"font-weight: 400;\"> at unstaffed or high-security entrances: an operator views a live feed before releasing the door remotely.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">This is where &#8220;VMS&#8221; flips to its other meaning, and where ONVIF Profile A and C conformance start earning their keep.<\/span><\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"378fa5d\" class=\"e-378fa5d-a242a1e e-heading-base\"><strong>Step 10: Break It, Then Pilot It<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-caea7b6 elementor-widget elementor-widget-text-editor\" data-id=\"caea7b6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><p><span style=\"font-weight: 400;\">Do not test the happy path. It works. Test these:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The internet drops mid-day. Does the gate fail open, fail closed, or freeze \u2014 and have you decided which of those you want?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The PACS API returns a 500 on provisioning. Is the visitor stranded at the turnstile with no fallback?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The same visitor is registered twice, by two hosts, on the same day.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A visitor checks in and never checks out. Does the credential expire on schedule?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Fire alarm.<\/b><span style=\"font-weight: 400;\"> Do all doors release, and does the VMS produce a live muster list of everyone currently inside? This is the one your safety officer will actually care about, and it is the strongest single argument for integration in the entire business case.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A visitor&#8217;s phone battery dies before they reach the reader.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Then <\/span><b>pilot one entrance for two weeks<\/b><span style=\"font-weight: 400;\"> before touching the rest of the building. Every organisation that skipped the pilot discovered its edge cases in production, usually during an evacuation drill.<\/span><\/p><p><span style=\"font-weight: 400;\">Finally, train the guards and publish a one-page visitor access policy. The integration is only as good as the person authorised to override it.<\/span><\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-7884ac3-63a315a e-divider-base\" data-interaction-id=\"7884ac3\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"392444a\" class=\"e-392444a-75e2729 e-heading-base\"><strong>The Multi-Tenant Problem Nobody Warns You About<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-6f86cce elementor-widget elementor-widget-text-editor\" data-id=\"6f86cce\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">If you are in an Indian commercial tower, this section matters more than everything above it.<\/span><\/p><p><b>There are two access control systems, not one.<\/b><span style=\"font-weight: 400;\"> The landlord or facility management company owns the ground-floor turnstiles and the base-building PACS. The tenant owns their floor doors and frequently runs a completely different PACS. Neither party controls the full path from street to desk.<\/span><\/p><p><span style=\"font-weight: 400;\">That produces three architectures, and only one of them works:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Landlord-only VMS.<\/b><span style=\"font-weight: 400;\"> Tenants get no visitor data and no control over who is cleared to their floor.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Tenant-only VMS.<\/b><span style=\"font-weight: 400;\"> The lobby turnstile has no idea the visitor exists, so your pre-registered guest still queues at the ground-floor desk. This is the most common and most infuriating configuration.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Federated.<\/b><span style=\"font-weight: 400;\"> The landlord&#8217;s VMS provisions base-building access, the tenant&#8217;s VMS provisions floor access, and the two exchange the visitor record. The visitor scans once and walks through both.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\"><br \/>Before the API conversation, have the contract conversation. <\/span><b>Under DPDP, who is the Data Fiduciary for that visitor&#8217;s personal data, the landlord or the tenant?<\/b><span style=\"font-weight: 400;\"> In most Indian leases today, this is simply unaddressed, which means both parties are exposed, and neither has a documented basis for retention or erasure. Get it written into the lease or facility agreement, along with who honours an erasure request and who holds the audit log.<\/span><\/p><p><span style=\"font-weight: 400;\">Qudify runs a distinct product line for commercial towers precisely because the tenant-of-a-tower problem is structurally different from the single-occupier office problem.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-017441a-d0de2a0 e-divider-base\" data-interaction-id=\"017441a\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"11189b8\" class=\"e-11189b8-62ae808 e-heading-base\"><strong>Diagnostics: Symptom \u2192 Root Cause \u2192 Step You Skipped<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-bcb7289 elementor-widget elementor-widget-text-editor\" data-id=\"bcb7289\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>What you&#8217;ll actually see<\/b><\/p><\/td><td><p><b>Root cause<\/b><\/p><\/td><td><p><b>Go back to<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Visitor cleared at reception, stuck at the turnstile<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Provisioning call failed, and nobody was alerted<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Step 7<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">The active-credential list keeps growing<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No timeout trigger; revocation depends on the visitor checking out<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Step 8<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">A visitor pass opens a door it should not<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">One catch-all &#8220;VISITOR&#8221; access group<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Step 5<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Guards keep overriding the system manually<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No documented fallback, so they invented one<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Step 10<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Provisioning silently stopped working last Tuesday<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Field mapping drifted after a firmware update<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Step 7<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">You cannot answer &#8220;who is in the building right now?&#8221;<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Door events are not streaming back from the PACS<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Step 7 \/ Step 9<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Legal asks for one visitor&#8217;s data and you cannot isolate it<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No retention policy, no deletion mechanism<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Data section, below<\/span><\/p><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"fb58819\" class=\"e-fb58819-2fb2e67 e-heading-base\"><strong>Step 8&nbsp; Wire Up Revocation<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-2aae2f0 elementor-widget elementor-widget-text-editor\" data-id=\"2aae2f0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Measure these <\/span><i><span style=\"font-weight: 400;\">before<\/span><\/i><span style=\"font-weight: 400;\"> you integrate, or you will have no way to prove the project worked.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e84372b elementor-widget elementor-widget-text-editor\" data-id=\"e84372b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>KPI<\/b><\/p><\/td><td><p><b>Target after integration<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Check-in to door-open time<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Under 60 seconds, end to end<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Orphaned credentials (active past expiry)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Zero<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Manual guard interventions per day<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Falling week on week<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Anti-passback\/tailgating events<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Counted, not suspected<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Failed provisioning calls<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Under 1% of check-ins<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Time to export a full audit log<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Minutes, not a day of digging<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-08a3948-95cb117 e-divider-base\" data-interaction-id=\"08a3948\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"84f6dc5\" class=\"e-84f6dc5-112fbbe e-heading-base\"><strong>Data, Consent and Securing the Link<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-a8cb386 elementor-widget elementor-widget-image\" data-id=\"a8cb386\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/4-4.png\" class=\"attachment-full size-full wp-image-1084\" alt=\"\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/4-4.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/4-4-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/4-4-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/4-4-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/08\/4-4-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"aab3d6e\" class=\"e-aab3d6e-32d7670 e-heading-base\"><strong>Collect Less<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-e40f7a2 elementor-widget elementor-widget-text-editor\" data-id=\"e40f7a2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Integration is your chance to collect <\/span><i><span style=\"font-weight: 400;\">less<\/span><\/i><span style=\"font-weight: 400;\">, because you no longer need a paper trail as a fallback.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49236c5 elementor-widget elementor-widget-text-editor\" data-id=\"49236c5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Collect<\/b><\/p><\/td><td><p><b>Skip<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Name, phone, host, purpose, timestamp<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Full ID document photocopies<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Consent record with timestamp and language<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Aadhaar numbers rarely defensible for a one-hour meeting<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Photograph, where genuinely justified<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Home address<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Company, vehicle number where relevant<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Anything you cannot name a deletion date for<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8dfc861 elementor-widget elementor-widget-text-editor\" data-id=\"8dfc861\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The test is one sentence: <\/span><b>for every field you capture, can you state the purpose and the deletion date?<\/b><span style=\"font-weight: 400;\"> If not, remove the field. Photocopying Aadhaar cards at the gate does not make a building safer; it makes it a data breach with a lobby.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"32906a9\" class=\"e-32906a9-6305c46 e-heading-base\"><strong>Retain Less<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-c855220 elementor-widget elementor-widget-text-editor\" data-id=\"c855220\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Bounded retention.<\/b><span style=\"font-weight: 400;\"> Pick a policy (90 days is a reasonable starting point for routine office visits) and let the system enforce it automatically.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Erasure.<\/b><span style=\"font-weight: 400;\"> Requests must be honoured within the timelines the Rules set.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Exportable audit logs.<\/b><span style=\"font-weight: 400;\"> If a regulator asks who entered Floor 6 in March, &#8220;we have a register somewhere&#8221; is not an answer.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\"><br \/>No government &#8220;DPDP-certified&#8221; label exists. When a vendor claims compliance, ask <\/span><i><span style=\"font-weight: 400;\">how<\/span><\/i><span style=\"font-weight: 400;\">. Our<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/07\/01\/best-visitor-management-systems-in-india-2026-a-practical-fact-checked-comparison\/\"> <span style=\"font-weight: 400;\">fact-checked comparison of visitor management systems in India<\/span><\/a><span style=\"font-weight: 400;\"> works through vendor evaluation in detail.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"e0bf9e6\" class=\"e-e0bf9e6-f817653 e-heading-base\"><strong>Secure the Link Itself<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-631e589 elementor-widget elementor-widget-text-editor\" data-id=\"631e589\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The API between VMS and PACS is now security infrastructure. It can open doors.<\/span><\/p><ul><li style=\"list-style-type: none;\"><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS in transit, encryption at rest.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scoped, rotated API keys. Never an integrator&#8217;s personal account.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Signed webhooks<\/b><span style=\"font-weight: 400;\">; otherwise, anything that can reach your endpoint can request a door to be opened.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anomaly alerting: bulk credential creation, provisioning outside business hours, spikes in failed calls.<\/span><\/li><\/ul><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-b266c4f-6854635 e-divider-base\" data-interaction-id=\"b266c4f\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"c13ca47\" class=\"e-c13ca47-526786a e-heading-base\"><strong>What Does It Cost, and Who Owns It?<\/strong><\/h2>\n\t\t\t\t\t<h3 data-interaction-id=\"df02c57\" class=\"e-df02c57-1089cf1 e-heading-base\"><strong>The Cost Structure<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-202073b elementor-widget elementor-widget-text-editor\" data-id=\"202073b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Anyone who quotes a single number before knowing your door count, controller make, and reader protocol is guessing. What you are actually buying:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>VMS subscription<\/b><span style=\"font-weight: 400;\"> per site, per user, or per visit.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Connector or integration licence<\/b><span style=\"font-weight: 400;\"> one-time or annual, if you are using a native connector.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Engineering days<\/b><span style=\"font-weight: 400;\"> if you are building against the API.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Reader\/hardware upgrade<\/b><span style=\"font-weight: 400;\"> only if you want QR or mobile credentials and your readers cannot do them, or you are migrating Wiegand to OSDP. Cost these two separately; they are separate decisions.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Middleware licence<\/b><span style=\"font-weight: 400;\"> for PIAM, and it is usually the largest line item.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Commissioning and training.<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Ongoing<\/b><span style=\"font-weight: 400;\"> key rotation, firmware regression testing, and the runbook nobody budgets for.<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"8aed6c4\" class=\"e-8aed6c4-726f115 e-heading-base\"><strong>The Ownership Question<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-9ade668 elementor-widget elementor-widget-text-editor\" data-id=\"9ade668\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">IT owns the API and the network. Security owns the access rules and the doors. Facilities and Admin own the front desk. HR owns consent. <\/span><b>Nobody owns the integration<\/b><span style=\"font-weight: 400;\">, which is exactly why these projects stall in month two.<\/span><\/p><p><span style=\"font-weight: 400;\">Name one accountable owner before Step 1 and hand them a runbook covering four questions: who rotates the API key, who is paged when provisioning fails, who approves a new access zone, and who signs off the retention policy.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-cb4bd4d-61563c4 e-divider-base\" data-interaction-id=\"cb4bd4d\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"0a2e465\" class=\"e-0a2e465-3c94ead e-heading-base\"><strong>The 10 Questions to Put in Your RFP<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a72fc7 elementor-widget elementor-widget-text-editor\" data-id=\"3a72fc7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Which access control systems do you have a <\/span><b>production<\/b><span style=\"font-weight: 400;\"> connector for? Name the versions.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Show me the API documentation for credential creation and revocation now, not after signing.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">What happens to an active visitor credential if the visitor never checks out?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Can I revoke every active visitor credential across all doors from one screen? Demonstrate it.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Does the credential work on my existing readers, or do I need new hardware?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Where is visitor data stored, and in which country?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">What is the default retention period, and can I change it?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Can I export a complete audit log without raising a support ticket?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">What happens when the internet drops, and what does the guard do in that hour?<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Under DPDP, who is the Data Fiduciary for this data: you or me? Point me to the clause.<\/span><\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-880ca7b-800bb70 e-divider-base\" data-interaction-id=\"880ca7b\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"d0c7b1c\" class=\"e-d0c7b1c-a4ad57f e-heading-base\"><strong>How Qudify Approaches Access Control Integration<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-97c5785 elementor-widget elementor-widget-image\" data-id=\"97c5785\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/07\/5-2.png\" class=\"attachment-full size-full wp-image-173\" alt=\"The Qudify company website homepage showcasing the digital workspace platform that facilitates meeting room scheduling and desk booking, featuring a smartphone screen with a QR code and a &apos;Book a Demo&apos; call-to-action button\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/07\/5-2.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/07\/5-2-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/07\/5-2-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/07\/5-2-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/07\/5-2-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bdd3663 elementor-widget elementor-widget-text-editor\" data-id=\"bdd3663\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Qudify is a QR-first visitor management system built by Qdesq Realtech, running across 500+ live sites for 400+ client organisations <\/span><i><span style=\"font-weight: 400;\">(company-reported figures, not independently audited)<\/span><\/i><span style=\"font-weight: 400;\">. The design constraint is deliberate: the only hardware required is the smartphone the visitor already owns.<\/span><\/p><p><span style=\"font-weight: 400;\">That has three consequences for the integration described above.<\/span><\/p><p><b>There is no card to hand over, and none to chase: <\/b><span style=\"font-weight: 400;\">The pass is a QR code on the visitor&#8217;s own phone. Provisioning is a software event, and expiry is a software event, so Step 8&#8217;s hardest operational problem getting the physical object back simply does not exist to be solved.<\/span><\/p><p><b>Approvals happen over WhatsApp:<\/b><span style=\"font-weight: 400;\"> The Step 6 screening gate stops being a bottleneck, because the host does not have to be at a desk, in an app, or anywhere near the building for a visitor to be cleared.<\/span><\/p><p><b>Consent, retention, and audit are by-products of the check-in, not a separate compliance project.<\/b><span style=\"font-weight: 400;\"> Because the flow is digital end-to-end, the consent record, the retention clock, and the exportable log are generated as the visit happens.<\/span><\/p><p><span style=\"font-weight: 400;\">Which architecture is right for your building still depends entirely on Step 2: what your access control system actually supports. That is a conversation worth having before anyone signs anything.<\/span><a href=\"https:\/\/qudify.co\/\"> <span style=\"font-weight: 400;\">Book a 15-minute walkthrough<\/span><\/a><span style=\"font-weight: 400;\">, and we will work through the integration path for your specific PACS.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-46b70ef-e3a45a4 e-divider-base\" data-interaction-id=\"46b70ef\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"4f73b58\" class=\"e-4f73b58-b4f9057 e-heading-base\"><strong>The Bottom Line<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-a44132e elementor-widget elementor-widget-text-editor\" data-id=\"a44132e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The API calls are not the hard part. The hard part is a set of decisions: which zones exist, what each visitor type may open, how long a credential lives, what happens when the network drops, who owns the data in a shared building, and how little you can get away with collecting.<\/span><\/p><p><span style=\"font-weight: 400;\">Get those right, and the technology follows in weeks. Get them wrong, and you have automated a broken process at speed.<\/span><\/p><p><span style=\"font-weight: 400;\">Start with Step 1. Walk the building. At every controlled door, ask whether a visitor should ever be standing behind it and whether you would currently know if they were.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Working through a specific PACS integration?<\/span><\/i><a href=\"https:\/\/qudify.co\/\"> <i><span style=\"font-weight: 400;\">Talk to the Qudify team<\/span><\/i><\/a><i><span style=\"font-weight: 400;\"> about your entry points, your controllers and your DPDP timeline.<\/span><\/i><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-022778e-07bf17e e-divider-base\" data-interaction-id=\"022778e\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"1238384\" class=\"e-1238384-77e5b45 e-heading-base\"><strong>Frequently Asked Questions<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-27214eb elementor-widget elementor-widget-n-accordion\" data-id=\"27214eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;expanded&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4100\" class=\"e-n-accordion-item\" open>\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"true\" aria-controls=\"e-n-accordion-item-4100\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Who should own an access control integration project internally? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4100\" class=\"elementor-element elementor-element-9dcb9e9 e-con-full e-flex e-con e-child\" data-id=\"9dcb9e9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1358aae elementor-widget elementor-widget-text-editor\" data-id=\"1358aae\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">One named person with authority across IT, Security and Facilities. In practice, the most successful owner is usually the Head of Admin or Facilities, with a security lead and an IT lead formally assigned to them because the front desk is where the process actually lives, even though the API lives in IT.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4101\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4101\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Can one visitor management system integrate with several different access control systems across sites? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4101\" class=\"elementor-element elementor-element-4d0462a e-flex e-con-boxed e-con e-child\" data-id=\"4d0462a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-277eb90 elementor-widget elementor-widget-text-editor\" data-id=\"277eb90\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, and this is the normal case for any multi-site organisation. If the PACS vendors differ by site, you are choosing between building separate API integrations per site or deploying PIAM middleware once. The tipping point is usually around four to five sites, or two or more distinct PACS vendors.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4102\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4102\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Do I need ONVIF conformance if I am integrating over a REST API? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4102\" class=\"elementor-element elementor-element-ade8ae9 e-flex e-con-boxed e-con e-child\" data-id=\"ade8ae9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-df5c6f5 elementor-widget elementor-widget-text-editor\" data-id=\"df5c6f5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">No. ONVIF matters when you need device-level interoperability across manufacturers: a reader from one vendor working with a controller from another, or a video system pulling standardised access events. A direct REST API integration between your VMS and one PACS does not depend on it. Ask about ONVIF when your estate is genuinely mixed-vendor.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4103\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4103\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Does this same integration handle employees, or only visitors? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4103\" class=\"elementor-element elementor-element-9284aed e-flex e-con-boxed e-con e-child\" data-id=\"9284aed\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4065517 elementor-widget elementor-widget-text-editor\" data-id=\"4065517\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Both, and most buyers miss this. The provisioning mechanism that issues a temporary visitor credential is the same mechanism that issues a joiner&#8217;s credential on day one and revokes a leaver&#8217;s on their last day. If you are already building the link, extend it to the HR system, and you close the ex-employee-still-has-access hole at the same time.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4104\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4104\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Do I need to replace my card readers? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4104\" class=\"elementor-element elementor-element-3917c1d e-flex e-con-boxed e-con e-child\" data-id=\"3917c1d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3fa882f elementor-widget elementor-widget-text-editor\" data-id=\"3fa882f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Only if one of two things is true: you want QR or mobile credentials and your current readers cannot read them, or you want the credential encrypted between reader and controller, and you are currently on Wiegand. Those are separate decisions with separate budgets; do not let a vendor bundle them into one number.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4105\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4105\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> How is a QR-based visitor pass secured against someone screenshotting and forwarding it? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4105\" class=\"elementor-element elementor-element-ac4900c e-flex e-con-boxed e-con e-child\" data-id=\"ac4900c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a0c54e4 elementor-widget elementor-widget-text-editor\" data-id=\"a0c54e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">By making it single-use or time-bound, cryptographically signed, bound to one visitor record, and scoped to specific zones and a specific window. A static QR that anyone can forward is not a credential; it is a picture. Ask any vendor which of the two they are selling you.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4106\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"7\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4106\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What is the difference between integration and unification? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4106\" class=\"elementor-element elementor-element-0f1c526 e-flex e-con-boxed e-con e-child\" data-id=\"0f1c526\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-755ec94 elementor-widget elementor-widget-text-editor\" data-id=\"755ec94\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Integration means two systems exchange data through an API layer somebody has to build and maintain. Unification means the data was never separated: one database, one interface, one policy engine. Unification is cleaner where a single vendor covers everything. Integration is the pragmatic reality for almost everyone, because almost nobody gets to rip out working access control hardware.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4107\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"8\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4107\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> How do I prove ROI to a CFO who sees this as a security cost? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4107\" class=\"elementor-element elementor-element-46b916c e-flex e-con-boxed e-con e-child\" data-id=\"46b916c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fa4e328 elementor-widget elementor-widget-text-editor\" data-id=\"fa4e328\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Three numbers travel well: front-desk hours saved per week, the count of orphaned credentials you eliminated on day one (this figure is almost always shocking and it is free to produce), and time-to-produce an audit log for a compliance request. Security teams tend to argue risk. CFOs buy the second and third numbers.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Who should own an access control integration project internally?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"One named person with authority across IT, Security and Facilities. In practice, the most successful owner is usually the Head of Admin or Facilities, with a security lead and an IT lead formally assigned to them because the front desk is where the process actually lives, even though the API lives in IT.\"}},{\"@type\":\"Question\",\"name\":\"Can one visitor management system integrate with several different access control systems across sites?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, and this is the normal case for any multi-site organisation. If the PACS vendors differ by site, you are choosing between building separate API integrations per site or deploying PIAM middleware once. The tipping point is usually around four to five sites, or two or more distinct PACS vendors.\"}},{\"@type\":\"Question\",\"name\":\"Do I need ONVIF conformance if I am integrating over a REST API?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. ONVIF matters when you need device-level interoperability across manufacturers: a reader from one vendor working with a controller from another, or a video system pulling standardised access events. A direct REST API integration between your VMS and one PACS does not depend on it. Ask about ONVIF when your estate is genuinely mixed-vendor.\"}},{\"@type\":\"Question\",\"name\":\"Does this same integration handle employees, or only visitors?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Both, and most buyers miss this. The provisioning mechanism that issues a temporary visitor credential is the same mechanism that issues a joiner&#8217;s credential on day one and revokes a leaver&#8217;s on their last day. If you are already building the link, extend it to the HR system, and you close the ex-employee-still-has-access hole at the same time.\"}},{\"@type\":\"Question\",\"name\":\"Do I need to replace my card readers?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Only if one of two things is true: you want QR or mobile credentials and your current readers cannot read them, or you want the credential encrypted between reader and controller, and you are currently on Wiegand. Those are separate decisions with separate budgets; do not let a vendor bundle them into one number.\"}},{\"@type\":\"Question\",\"name\":\"How is a QR-based visitor pass secured against someone screenshotting and forwarding it?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"By making it single-use or time-bound, cryptographically signed, bound to one visitor record, and scoped to specific zones and a specific window. A static QR that anyone can forward is not a credential; it is a picture. Ask any vendor which of the two they are selling you.\"}},{\"@type\":\"Question\",\"name\":\"What is the difference between integration and unification?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Integration means two systems exchange data through an API layer somebody has to build and maintain. Unification means the data was never separated: one database, one interface, one policy engine. Unification is cleaner where a single vendor covers everything. Integration is the pragmatic reality for almost everyone, because almost nobody gets to rip out working access control hardware.\"}},{\"@type\":\"Question\",\"name\":\"How do I prove ROI to a CFO who sees this as a security cost?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Three numbers travel well: front-desk hours saved per week, the count of orphaned credentials you eliminated on day one (this figure is almost always shocking and it is free to produce), and time-to-produce an audit log for a compliance request. Security teams tend to argue risk. CFOs buy the second and third numbers.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\n<\/article>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Access Control Integration with VMS: A Step-by-Step Guide Key Takeaways &#8220;VMS&#8221; is ambiguous, and the ambiguity mis-scopes projects. It means Visitor Management System in facilities contexts and Video Management System in the surveillance industry. Both integrate with access control. Confirm which one your RFP means before anyone quotes. Integration is three operations: provision a credential [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1088,"comment_status":"open","ping_status":"open","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1078","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts\/1078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/comments?post=1078"}],"version-history":[{"count":7,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts\/1078\/revisions"}],"predecessor-version":[{"id":1146,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts\/1078\/revisions\/1146"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/media\/1088"}],"wp:attachment":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/media?parent=1078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/categories?post=1078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/tags?post=1078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}