Start with user groups, not doors
- Define staff, contractor, and visitor roles first.
- Set access windows by routine, not one-off exceptions.
- Build restricted-area logic around safeguarding needs.
Permission model that scales
- Use role templates instead of individual door-by-door edits.
- Standardise emergency override rules.
- Keep temporary credentials time-limited and auditable.
Day-to-day admin workflow
- Add/remove users with clear approval steps.
- Record permission changes in a simple log.
- Review inactive credentials on a scheduled cycle.
Handover checklist for teams
- Quick-start guide for reception/admin users.
- Escalation path for lockouts and urgent changes.
- Regular review cadence with service provider.

