What to ask before choosing access control software
TL;DR: Choosing access control software based on a nice demo is easy; choosing one that works in your company's real day-to-day operation requires asking the right questions before signing. This checklist covers record keeping, notifications, specific use cases, behavior when the network fails, data ownership, support, and implementation, the areas where problems tend to show up after signing, not before.
Most access control software demos look good: clean interface, fast scanning, instant notification. The problem is not in the demo, it is in the questions nobody asks before signing the contract, which end up surfacing weeks later once the system is already in production and switching providers becomes harder. This checklist is meant to be used before, not after.
Questions about record keeping
What exactly gets documented on each entry: just the visitor's name, or also who authorized them, at what time, and for how long that record gets kept. If you need to reconstruct the entry history for a specific date for an audit, how long does it take to get that information and in what format is it delivered. Whether the record distinguishes between types of access (occasional visitor, recurring vendor, staff), or lumps them all together, which complicates any later analysis.
Questions about notifications and response times
How quickly the host gets notified when their visit arrives, and what happens if that person does not respond in time, is there a backup protocol or does the visitor wait indefinitely. Whether the system can notify more than one person (for example, the host and security at the same time) or only one. And whether notifications depend on the visitor or host having an app installed, or also work through other channels.
Questions about specific use cases
How does the system handle a vendor who visits every week, is there a frequent pass that avoids repeating the full registration every time, or is every visit treated like the first one. What happens if the company has more than one office, can reports be consolidated or does each office stay isolated. And how is a visitor without a smartphone handled, does the provider offer a real alternative or does the whole process depend on an app. These use-case questions tend to reveal more about a provider than any feature listed on their product page.
Questions about what happens when the network fails
This is the set of questions that almost never appears in a demo, because demos assume the connection always works. In a real building it does not. Ask what happens at the gate or front desk when the building's internet goes down: can the guard keep verifying and registering entries, or does the entire process stop until the connection comes back. If entries keep getting recorded locally during the outage, how and when does that information sync once connectivity returns, and is there any risk of losing records from that window.
Then ask what happens when the failure is not the building's connection but the provider's platform. Is there a defined contingency protocol that the guard can follow, or does every site improvise on its own at the moment the system stops responding. A provider that has thought about this will answer with a concrete procedure; a provider that has not will answer with a vague reassurance.
And finally, ask about the smaller everyday failure: the resident or visitor whose phone is dead, out of battery or left at home. Is there a real fallback path to get that person in or out, or does the whole design assume everyone always carries a working smartphone. The answer says a lot about whether the system was designed for ideal conditions or for how buildings actually operate.
Questions about data ownership and exit
Every month of operation adds more entry records, names, photos, vehicle plates, and authorization history. Before signing, ask who owns that history: the client or the provider. If you decide to change providers or stop using the system, can you export that history, in what format, and how long does the export take. A provider that treats the data as yours will have a straightforward answer; a provider that treats it as leverage will not.
Also ask what happens to personal data once the contract ends: is it deleted, retained, and for how long, and who is responsible for executing that deletion. Since access control records contain information about who entered and left a building and when, the answer to this question matters for privacy compliance, not just for convenience.
And confirm the contract mechanics themselves: contract length, how renewal works, how much notice is required to cancel, and whether any part of the setup creates lock-in. These are uncomfortable questions to raise with a provider you are about to hire, which is exactly why they are easier to ask now than later.
Questions about support and escalation
Ask what support looks like when something breaks outside business hours, because access control problems rarely wait for them. If the gate scanner stops responding on a Saturday night, what channel does the guard or administrator use, is support available in your language and time zone, and what is the expected response path. A system that controls building entry deserves the same support expectations as any other critical piece of infrastructure.
Also clarify who is responsible for what when a problem appears: the software provider, the hardware installer, or the building's own staff. When those boundaries are not written down, the failure gets passed around, and the gate stays unattended while each party says it is the other's job.
Finally, ask what happens when new guards or front desk staff join. Do they receive training from the provider, or does every new hire depend on the administrator teaching them personally. A system that only one person on your team knows how to use is a vulnerability, not an asset. Learn how ArmorPass answers these questions in the corporate access control section and in features.
Questions about implementation and staff training
How long does full implementation take, from signing the contract to the front desk or security team being able to use it without outside help. How complex is training, does it require formal sessions or can staff learn it in minutes on their own. And what happens during the transition, is there a period where the previous process keeps running in parallel, or is the cutover immediate.
A summarized final checklist
Before signing, confirm you have a clear answer to: what gets recorded and for how long, who receives notifications and what happens if they do not respond, how a recurring vendor and a multi-site company get handled, what happens at the gate when the network fails, who owns the entry history and what happens to it at contract end, and how long real implementation takes (not the demo version). If any of these questions does not have a direct answer from the provider, it is worth requesting it in writing before moving forward.
Frequently asked questions
How much should access control software cost? Cost varies depending on the number of users, sites, and included features, so the useful comparison is not just the monthly price but what that price includes: record keeping, notifications, support, and updates, versus what it would cost to keep running a manual process with more staff.
How long does it take to implement an access control system? For a single-site company, typical implementation takes days, not months, because it does not require changes to the building's physical infrastructure, only staff training and initial setup of users and rules.
What if the current provider does not have an answer to some of these questions? That is a signal to evaluate alternatives before renewing the contract, especially if the missing answers are about record keeping (how complete and accessible the history is) or about specific use cases like recurring vendors.
Does the front desk's physical infrastructure need to change? Not in most cases. A good access control system layers on top of the existing process (front desk, guard, door), adding digital verification and automatic record keeping without requiring construction or structural changes.
What is the single most revealing question on this list? "What happens when the internet goes down." Every provider has an answer for when the system works; the ones worth hiring also have a clear answer for when it does not, including what the guard does in that exact moment and what happens to the records created during the outage.