Access control integration makes one system the source of truth for who may open which door. Employee identities and status flow from HR and the corporate directory into the access-control system, so a joiner is provisioned and a leaver is revoked automatically. Visitors and contractors receive time-bounded entitlement in that same system, so everyone uses the doors already installed and there is one audit trail rather than several.

The test is simple and most organisations fail it: pick five people who left in the last quarter and check whether their credentials still open a door.

  • One entitlement source, not three lists
  • Leavers revoked by the HR event, not by memory
  • Visitor entitlement that expires by itself
  • Access review evidence an auditor accepts
Speed gates in an office lobby
One set of doors, one audit trail: visitors on temporary entitlement in the system already installed.

Three systems that each think they own the door

In most buildings, three separate records claim to describe who may enter. HR knows who is employed. The directory knows who has an account. The access-control system knows who has a card. They were aligned on the day the building opened and have diverged every day since, because each is updated by a different team through a different process, and only one of them — the card — physically opens a door.

The consequence is orphaned access. Someone leaves, their account is disabled the same afternoon because IT has an automated process, and their access card keeps working for months because revoking it was a manual request nobody raised. Meanwhile visitors and contractors get handled outside the system entirely — a spare card from a drawer, handed over and rarely returned — so the access-control database accumulates credentials that belong to nobody. When an audit asks who currently has access to the server room, the honest answer is that nobody knows.

  • HR, directory and access control diverge because three teams maintain them separately.
  • Account disabled the same day; access card still working months later.
  • Spare cards issued from a drawer become permanent orphaned credentials.
  • Nobody can answer who currently has access to a sensitive area.
  • Access reviews are performed against a list that was never accurate.

Solution overview

Swedish Technology makes the identity lifecycle drive the door. HR or the corporate directory becomes the authoritative source for employees: a joiner triggers provisioning with the entitlements their role requires, a mover has entitlements adjusted rather than accumulated, and a leaver is revoked by the same event that disables their account. The access-control system stays exactly as it is — it is still the thing that opens the door — but it stops being maintained by hand.

Visitors and contractors are provisioned into that same system with entitlement bounded by the visit or the permit, so nothing is issued that does not expire. The spare-card drawer disappears because there is no reason to use it. What comes out the other side is the evidence an audit actually wants: current entitlement per person and per area, when it was granted, by which event, and when it will end.

How the solution works

  1. 1
    Establish the source of truth HR for employment status, the directory for identity and groups, the visitor platform for visitors and contractors. Each owns one thing; nothing owns the same thing twice.
  2. 2
    Map roles to entitlement Role, department and location translated into door groups, so provisioning is a rule rather than a request ticket describing which doors a person needs.
  3. 3
    Provision automatically A joiner in HR becomes a credential and an entitlement set in the access-control system, ready before their first day rather than after it.
  4. 4
    Adjust on change A mover has entitlements replaced rather than added to, which is what prevents the long-serving employee who can open every door in the building.
  5. 5
    Revoke on exit The leaver event revokes physical access at the same moment it disables the account, and the revocation is recorded as evidence.
  6. 6
    Review and evidence Periodic access reviews generated from live entitlement, with exceptions and approvals recorded — which is the artefact an auditor asks for.

Key capabilities

Identity lifecycle to physical access

Joiner, mover and leaver events from HR or the directory driving provisioning, adjustment and revocation in the installed access-control system.

available

Role-based entitlement

Door groups derived from role, department and location, so access follows a rule and least privilege is the default rather than an aspiration.

available

Time-bounded visitor entitlement

Visitors and contractors provisioned into the same system with entitlement that expires with the visit or the permit, removing the spare-card drawer.

available

Orphan detection

Credentials with no matching identity, entitlements with no owner and cards not used in months surfaced for cleanup rather than accumulating silently.

available

Access review

Scheduled reviews generated from live entitlement with owner sign-off and exception recording, producing evidence an auditor will accept.

available

Multi-system consolidation

Several access-control systems across buildings presented as one entitlement view, which is the usual reality in an estate assembled over time.

available
Network cabinet in a building service room
One directory, one access system, one audit trail — the alternative is two lists that disagree about who left.

Reference architecture

An integration layer between identity and doors. The access-control system is not replaced — replacing it is expensive, disruptive and almost never the actual requirement.

Deployment options: On-premise or cloud. The integration layer runs inside the customer network in most cases, because it holds employment status and entitlement data and must reach access-control systems that are rarely internet-facing.

Hardware options

Usually none. The point of this work is to use the doors and readers already installed. Hardware appears only where the existing estate cannot support what is required.

DeviceWhere it is usedSelection notes
Existing controllers and readersThroughout the buildingRetained. Replacing an access-control estate to gain integration is almost never justified, and the migration risk usually exceeds the benefit.
Integration serverCustomer networkRuns the connectors and entitlement engine. Sized by identity volume and door count; must reach both the directory and the access-control systems.
Credential encoderSecurity office or receptionWhere cards are issued locally. Encoding at issue rather than from a pre-encoded batch is what removes the spare-card drawer.
Reader upgradesOnly where a technology gap blocks the requirementFor example, where mobile credentials are required and existing readers cannot support them. Treated as an exception, not a default.

Swedish Technology integrates with access-control systems from established manufacturers; the assumption is retention of the installed estate unless a specific capability is genuinely unavailable.

AI capabilities

Used to find the drift that manual reconciliation never catches.

  • Orphan and anomaly detection — Identifies credentials with no matching identity, entitlements nobody has used for months, and access patterns inconsistent with a person's role — the three signals that most reliably reveal drift.
  • Identity matching across systems — Reconciles the same person represented differently in HR, the directory and access control, including Arabic and Latin spellings, which is the practical obstacle to a single view.
  • Entitlement recommendation — Suggests door groups for a role from what comparable employees actually hold and use, which is how least privilege gets defined without a year-long workshop.
  • Access review prioritisation — Ranks entitlements by risk and staleness so a review focuses on the sensitive areas rather than asking managers to confirm hundreds of routine permissions.

Integrations

This page is entirely about integration. Each of these is designed and built within project scope against documented interfaces.

SystemIntegration point & data exchangedDirection
Microsoft Entra ID / Active Directory Identity, group membership and account status as the trigger for provisioning and revocation, so physical and logical access are governed by the same event. bi-directional
Oracle HCM / SAP SuccessFactors / HRMS Employment status, role, department and location as the authoritative source for who should have access at all. → Oracle E-Business Suite inbound
Access control systems Credential and entitlement provisioning into the installed system, with current state read back for reconciliation and orphan detection. bi-directional
Visitor platform Visitors and contractors provisioned with entitlement bounded by the visit, then automatically revoked. → Smart Office Visitor Management inbound
Permit to work / contractor compliance Entitlement conditional on a valid permit and current induction, revoked when the permit closes. → Contractor Access Management System inbound
SIEM / security monitoring Access events and entitlement changes forwarded so physical access sits in the same monitoring picture as logical access. → SAIF – Cybersecurity outbound

The integrations above are designed and implemented within project scope using vendor APIs, webhooks or standard connectors. They do not imply partnership, certification or endorsement by the system owner unless stated on that vendor's official pages.

Dashboards & analytics

  • Entitlement view — Who currently has access to which areas, from live data rather than from a spreadsheet maintained by hand.
  • Lifecycle health — Joiners provisioned before start date, movers adjusted, leavers revoked — with the lag on each, which is where the real risk shows.
  • Drift and orphans — Credentials without identities, entitlements without owners, and cards unused for a defined period.
  • Audit evidence — Access review status, approvals, exceptions and full entitlement history per person and per area.

Security & deployment

This layer holds employment status and entitlement data, which makes it a high-value target and a candidate for strict segregation. It runs inside the customer network, authenticates to the directory and access-control systems with dedicated service accounts holding least privilege, and every entitlement change it makes is logged with its trigger — the HR event, the visit, the permit — so a change can always be traced to a cause rather than to a person with database access. Break-glass procedures for emergency access are defined explicitly and are themselves logged and reviewed.

Data privacy

Physical access records show where an identifiable employee was and when, which in most jurisdictions makes them employee monitoring data as well as security data. The design position is that access events are retained for security and audit purposes with a defined period, and are not used for attendance, productivity or presence reporting unless the organisation has separately established a basis and told employees.

Under UAE Federal Decree-Law No. 45 of 2021 the employer is the controller for employee access data and the site operator for visitors. In Dubai, SIRA requirements apply to the security systems involved and to who may operate them. Where the same events are forwarded to security monitoring, that onward use is stated rather than implied — an access log flowing into a SIEM is a different purpose from opening a door, and should be documented as one.

Industry use cases

Corporate estate with multiple buildings

Several access-control systems inherited over time presented as one entitlement view, with HR-driven provisioning applied consistently across all of them.

Regulated financial entity

Scheduled access reviews with owner sign-off and exception recording, producing the evidence an internal audit or regulator asks for.

Data centre or critical facility

Entitlement conditional on a current permit, escort rules enforced at the reader, and every entitlement change traceable to its trigger.

Hospital

Clinical, administrative and contractor populations with very different area entitlements, driven from HR and from the contractor compliance system.

Organisation after a merger

Two directories and two access estates reconciled into one entitlement model, which is usually where orphaned credentials are discovered in volume.

Building replacing a spare-card process

Visitors and contractors provisioned with expiring entitlement so the drawer of unaccounted cards is retired rather than managed.

UAE & GCC considerations

UAE workforces have high turnover and a large contractor and outsourced population, which makes leaver revocation both more important and more often missed than in lower-churn markets. Where staff are engaged through a manpower supplier, the leaver event may never reach the client's HR system at all — so contractor entitlement should be driven by the supplier contract and the permit rather than by an HR record that will not be updated.

Names are a practical obstacle. The same person is frequently represented differently across HR, the directory and the access system — Arabic and Latin spellings, different name-order conventions, initials in one system and full names in another — and reconciliation has to handle that rather than assume a clean match. In Dubai, SIRA governs the security systems and personnel involved, and government-linked entities commonly require the integration layer to be hosted in-country.

Implementation approach

  1. 1
    Reconciliation audit Compare HR, directory and access control as they stand today. This produces the orphan count and the leaver-lag figure, and it is usually the finding that justifies the project on its own.
  2. 2
    Entitlement model Roles mapped to door groups with least privilege as the target. Derived from what comparable people actually use rather than from what they currently hold.
  3. 3
    Connector build Integration to HR, directory and each access-control system, built and tested in a non-production environment against real data shapes.
  4. 4
    Leaver process first Automate revocation before provisioning. It carries the risk, it is simpler, and it demonstrates value immediately.
  5. 5
    Visitor and contractor entitlement Time-bounded provisioning enabled so the spare-card process can be retired rather than left running alongside.
  6. 6
    Access review cycle First review run and evidence produced, which is the point at which the organisation can answer the audit question it previously could not.

Why Swedish Technology

  • We keep your access-control system and integrate to it — replacing an estate to gain integration is rarely justified and usually carries more risk than the problem.
  • Leaver revocation is automated first, because that is where the actual exposure is.
  • Entitlement is derived from what comparable roles genuinely use, so least privilege is reached without a year of workshops.
  • Name reconciliation across Arabic and Latin representations is handled explicitly rather than assumed to match.
  • The output is audit evidence, not a dashboard — current entitlement, its trigger, and when it ends.

Limitations & prerequisites

  • Integration depends on each access-control system exposing a usable interface. Some older systems expose none, and those either stay manual or get replaced.
  • Automated provisioning is only as good as the HR data behind it; where HR records are incomplete, the integration surfaces that rather than fixing it.
  • Contractors engaged through suppliers may never appear in HR, so their entitlement must be driven by contract and permit instead — this is a process decision, not a technical one.
  • Least privilege reduces standing access and will generate access requests from people who previously had more than they needed; that transition needs managing.
  • Physical access data is employee monitoring data as well as security data, and using it for attendance requires a separate basis and disclosure.
  • References to SIRA and PDPL obligations are general guidance, not legal advice.

FAQ

Almost never. The installed controllers, readers and doors are retained and the integration layer provisions entitlement into them. Replacing an access-control estate to gain integration carries migration risk and cost that rarely match the benefit, and it is not what the requirement usually is.

By making the leaver event that disables their account also revoke their physical entitlement, and recording the revocation as evidence. Automating this first is deliberate — it is where the exposure is, it is simpler than provisioning, and the result is immediately testable: pick five recent leavers and try their credentials.

A card or entitlement in the access-control system with no matching identity in HR or the directory. They accumulate from spare cards issued informally, contractors who never returned a badge, and leavers who were never revoked. Most buildings that have never reconciled hold more than the security team expects.

They are provisioned into the same access-control system with entitlement bounded by the visit or the permit, and revoked automatically when it ends. That is what allows the spare-card drawer to be retired: there is no longer a reason to hand out an unmanaged credential.

Yes, and that is the normal case in an estate assembled over time. Each access-control system gets its own connector, and the entitlement view is presented across all of them — which is usually the first time anyone can answer who has access to what across the whole estate.

Current entitlement per person and per area, the event that granted it, when it expires, the history of changes, and completed access reviews with owner sign-off and recorded exceptions. That is materially different from a spreadsheet export, which is what most access reviews currently rely on.

Not by default, and not without a separate decision. Physical access records are employee monitoring data as well as security data; using them for attendance or presence reporting requires its own lawful basis and disclosure to employees, and we raise that explicitly at design stage rather than enabling it quietly.

Their leaver events often never reach the client's HR system, so driving their access from HR will fail. Entitlement for supplied staff should be driven by the supplier contract and the permit instead, which both have defined end dates and an owner who has a reason to keep them current.

Discuss your site with an engineer

Tell us the venue, the expected visitor volume and the systems you already run. We reply with a technical view, a realistic scope and the next sensible step — a site survey, a working demonstration, or a full technical and commercial proposal.

+971 56 404 6555 · info@swedishtechnology.com

Sources & evidence

  1. UAE Federal Decree-Law No. 45 of 2021 — Personal Data Protection Law — Governs collection, retention and cross-border transfer of visitor personal data in the UAE.
  2. Dubai SIRA — Security Industry Regulatory Agency — Regulates security systems and licensed security service providers in Dubai.
  3. Microsoft — Entra ID provisioning and lifecycle — Reference for the directory provisioning model this integrates with.

Vendor and product names are trademarks of their respective owners; references are for technical context and do not imply partnership, certification or endorsement.