Skip to main content

Access groups

An access group says who may pass where and when: its members (cardholders) may pass each of its doors during the schedule chosen for that door. A cardholder can be in several groups; their access is everything their groups give.

Creating groups and choosing their doors needs the Tenant admin role. Adding and removing members needs Operator or Tenant admin (Roles and permissions).

Create a group​

Open Access groups and choose New access group. Enter a Name (1–100 characters, unique in the tenant) and an optional Description, and choose New access group. The list shows each group with its number of members and doors.

On the group's page, Rename changes the name; Delete removes the group (Its members lose the access it gave them.).

Doors and schedules​

Doors and schedules lists every door of the tenant with its Controller. Tick the doors the group may pass, pick the Schedule for each, and choose Save doors (Doors saved: controllers are updated.). A group can have up to 500 doors.

Create a schedule first if there is none (Schedules and holidays). One door has one schedule per group; to give a group two time windows on the same door, put both windows in one schedule.

Members​

Members lists the group's cardholders. Search with Search cardholders…, choose Add next to a cardholder to add them, and the remove button to take them out (Members updated). You can also choose a cardholder's groups when you add or edit the cardholder (Cardholders and cards).

Who may pass​

A controller holds, for each card that may pass one of its doors, the doors and schedules that apply. A card is on a controller only when all of these hold:

  1. the card is Active (not blocked or lost) and assigned to a cardholder;
  2. the cardholder is Active and inside their validity period (Valid from / Valid until);
  3. the cardholder is a member of a group that has one of the controller's doors.

At a reader, the controller then decides:

SituationEvent
The card is not on the controllerUnknown card
The card has no grant for this doorAccess denied: no access to this door
Today is a holiday and no holiday window of the card's schedules for this door is openAccess denied: holiday
No window of the card's schedules for this door is open nowAccess denied: outside the schedule
A window is openAccess granted; the lock is released for the door's unlock time

A card that has been blocked, or whose cardholder is suspended or outside the validity period, is removed from the controllers, so it reads as Unknown card. Validity periods are checked every minute: when one starts or ends, the cardholder's controllers receive a new configuration.

Every change to a group, its doors or its members sends a new configuration to the controllers concerned. See Configuration sync.

Delete a group​

Open the group and choose Delete, then confirm. Its members lose the access it gave them; the affected controllers receive a new configuration.