Access Controller manual Download PDF

Chapter 06

People and fobs

People are the members, staff, residents and contractors who open doors. Each person can hold several fobs and one or more access levels. This chapter covers adding people, photos, finding people, managing fobs, the four ways of getting fob codes into the system, changing many people at once, the trash, importing from a spreadsheet or from an AC8000 backup, the check-a-fob tool and what "inactive" means.

The People page: the desk scan box, search, the add-person toolbar and the list with photos, status, fob count, levels and contact details.
The People page: the desk scan box, search, the add-person toolbar and the list with photos, status, fob count, levels and contact details.

Adding a person

Open People. In the Add person toolbar type the full name and, optionally, an email address and phone number, then press Add. The person is created as active with no fobs and no access levels, and their page opens.

The phone number matters if the person will release doors by phone (chapter 9): the caller ID of their calls is matched against it, on the last nine digits, so 07911 123456, +44 7911 123456 and 447911123456 all match.

The person page

The top of a person's page: photo and details on the left, fobs and access levels on the right. The door release by phone panel sits below (chapter 9).
The top of a person's page: photo and details on the left, fobs and access levels on the right. The door release by phone panel sits below (chapter 9).

Details

Name, email, phone, status (active or inactive) and free-text notes. Press Save after editing.

Photos

A photo is shown on the People list, on the person's page and, most usefully, on the reception screen the moment the person fobs in.

Fobs

The Fobs panel lists every fob on the person with its code and status.

A person's active fobs open doors according to their access levels; revoked fobs are refused with Fob revoked.

Access levels

Tick the levels the person should hold and press Save levels. A person with no levels is refused everywhere with No access level for door. Chapter 7 explains levels.

Door release by phone

Whether the person may release doors from their phone, which doors, and their apartment number and PIN for guests. Chapter 9.

Move to trash

At the bottom of the page. Move to trash takes the person out of service straight away: their fobs stop opening doors within seconds, they disappear from the People list, the keysets, phone release and the resident portal. Nothing is destroyed. They sit in the trash for 30 days, where they can be restored complete with their fobs and access levels, and are then removed automatically. See "The trash" below.

If the person may return sooner, or you only want to suspend them, set them inactive instead: that leaves them on the list and is a single click to undo.

Searching

The Search box on the People page matches name, email, phone or fob code (partial matches allowed). Press Search; Clear shows everyone again. The list shows a photo or initials, name, status, number of active fobs, access levels and contact details. Click a name to open the person.

Export all as CSV in the toolbar downloads everyone as a spreadsheet named people-<date>.csv, with the columns Name, Email, Phone, Status, Fobs, Access levels and Apartment. When a search is active the button becomes Export matches as CSV and exports only what the search found. People in the trash are never exported. Viewers may export as well as admins.

Changing several people at once

Every row on the People page has a tick box, and the box in the header ticks everyone. As soon as anything is ticked a bar appears showing N selected and the actions that can be applied to all of them:

ActionWhat it does
Add level(s)Adds the access levels chosen in the box beside the buttons to everyone ticked, keeping what they already hold. Ctrl-click to pick more than one level.
Remove level(s)Takes those levels away from everyone ticked.
Set active / Set inactiveChanges the status of everyone ticked.
Enable phone release / Disable phone releaseTurns caller-ID release on or off for everyone ticked (chapter 9). It does not change which doors they may release.
Export CSVDownloads just the ticked people as a spreadsheet.
Move to trashMoves everyone ticked to the trash, after a confirmation that names the number of people.
ClearUnticks everything. It changes nothing.

The message afterwards counts the people actually changed, so Set active applied to a mixed selection reports only the ones that were inactive. Keysets are re-pushed once at the end. The search is kept, so you can search "Smith", tick all, add a level, and carry on.

This is the quickest way to run a membership change: search for the group, tick, add or remove the level.

The trash

The Trash button in the People page toolbar shows how many people are in it, for example Trash (3). (The same page is linked from the hint under a person's delete button.) It lists everyone who has been deleted and not yet purged.

ColumnMeaning
NameThe person, with their email underneath.
FobsHow many fobs went with them. They are kept but inert.
Deleted onWhen they were moved to the trash.
Removed inHow many days are left of the 30. next purge means they are due to go at the next sweep.

The automatic sweep runs when the panel starts and every six hours after that, so someone may sit in the trash a few hours past their 30 days before disappearing. Each sweep writes one line to the Log per tenant (Trash purged), and moving to the trash, restoring and deleting permanently are each logged too (chapter 11).

The trash is what makes deleting a person safe: the usual "did we just delete the wrong Smith?" is a click to undo. Log entries are never deleted by any of this; they keep the name recorded at the time.

Getting fob codes into the system

There are four ways to attach a fob code, from the quickest for a single fob to the best for a whole site.

1. Type it

If the code is printed on the fob or known from the old system, type it into Add fob on the person's page. Codes are uppercase hexadecimal. Old systems often show the same fob as a decimal "card number"; use the desk scan box or the CSV import with the decimal option to convert.

2. Scan it at the desk

A USB fob or card reader that acts as a keyboard (a "keyboard wedge" reader) can be plugged into the office computer. On the People page, click into the Scan a fob here box, present the fob, and the reader types the code and presses Enter for you. Tick reader types decimal if your reader outputs decimal numbers rather than hexadecimal.

This is also the fastest way to answer "whose fob is this?" for a fob found on the floor.

3. Enrol it at a door

You do not need a desk reader; any door reader will do.

While a door is listening, the fob presented does not open the door (it is still unknown at that moment) and the scan is logged as Captured for enrolment rather than as a denial, so it does not count towards "denied today". Only one door listens at a time per tenant.

4. Enrolment mode (a batch of fobs at chosen doors)

Enrolment mode is the migration path from a standalone system (Paxton Net2 without an export, an AC8000 whose backup has been lost, and similar) where nobody knows the codes. If you still have the old system's export or backup, use the import wizard instead ("Importing from a legacy system" below). Switch it on at the doors people will badge and every unknown fob presented there is accepted (the door opens) and captured, so members keep coming in as normal while the panel harvests their fobs. Then assign names to the captured codes.

Enrolment mode is started on the Enrolment page, not in Settings. In the Enrolment mode panel:

  1. Tick the doors people will badge. Only those doors accept and capture unknown fobs; every other door on the site is unaffected and keeps refusing them. The doors you used last time are already ticked, so re-arming is one click.
  2. Choose the default access level the people you enrol should end up with, for example Access level: Members. Choose Access level: none to decide later.
  3. Choose how long: for 15 minutes, for 30 minutes (the default), for 60 minutes or for 120 minutes.
  4. Press Start enrolment.

A banner then appears at the top of every page for the tenant reading, for example:

Enrolment mode on at Front, Gym until 14:35 (level: Members) - 3 captured to assign

with a Stop button. The Enrolment page's own panel turns green and shows the same information with Stop enrolment now. The Settings page also shows a green Enrolment mode panel while it is running, with a stop button, but starting is only ever done from the Enrolment page.

Enrolment ends automatically at the time shown, or when you press Stop. Stopping flashes Enrolment stopped - unknown fobs are denied again and keeps your door ticks and level choice ready for next time. Starting and stopping are logged as system events (Enrolment started, Enrolment stopped), and scans accepted this way are logged as granted with the reason Enrolment (auto-accepted).

Warning: at the doors you ticked, any fob of the right format opens the door while enrolment mode is on, including fobs from other buildings and fobs that were revoked on the old system. That is the point of it, but it means you should tick only the doors you are actually standing at, keep the window as short as the job allows, and switch it off as soon as you are done. Picking doors is what limits the exposure: the front entrance can be in enrolment mode while the plant room is not.

The Enrolment page

The Enrolment page: the enrolment mode panel, the enrol-a-fob-at-a-door panel, the captured fobs list with assign and dismiss controls, and the import section.
The Enrolment page: the enrolment mode panel, the enrol-a-fob-at-a-door panel, the captured fobs list with assign and dismiss controls, and the import section.

Captured fobs lists every code captured by enrolment mode, by listening at a door, by phone enrolment or by an unknown desk scan. The count is shown beside the heading.

ColumnMeaning
FobThe code, in hexadecimal.
SeenHow many times that fob has been presented. Re-presenting a fob bumps this rather than adding a second row.
Last seenWhen it was last presented.
WhereThe door it was last presented at. A fob that came from the office reader is marked desk.
Assign toThe controls to give it to somebody.

To assign a fob: choose an existing person, or leave - new person - selected and type a name; choose an access level (the enrolment level is already selected); press Assign.

The access level is applied the same way whether the fob went to a new person or an existing one, and it is added to whatever the person already holds. Assigning a fob therefore never takes access away: enrol a long-standing member at the front door and they keep everything they had plus the enrolment level.

Dismiss drops a captured code you do not want (a visitor's fob, a fob from another site). Captured fobs stay in the list until they are assigned, dismissed or matched by an import; nothing expires them. The dashboard shows an amber "captured fobs waiting to be assigned" banner while the list is not empty.

Tip: the whole point of the default access level is that you never have to come back. Tick the doors, set the level to what a new member gets, and every fob you assign during the window arrives fully set up.

Importing from a legacy system

If the old system can give you its data, bring people and fobs across in one go from the Import people and fobs section of the Enrolment page. Two sources are supported; pick one with the two large buttons at the top of the section:

Whichever source you use, nothing is written to the panel until you press Run import on the preview page, and a fob that already exists is never overwritten.

Import from CSV

  1. Export users to CSV from the old software.
  2. Choose CSV / spreadsheet export, then either choose the file or paste its contents into the box, and press Preview import.
  3. On the preview page, check the detected columns: First name, Surname (or a single Full-name column when there is no first/surname split) and the Token / fob column. Correct any guess with the drop-downs.
  4. Leave Tokens are decimal card numbers ticked for Net2 and most systems that show card numbers in decimal; untick it if the column already holds hexadecimal codes.
  5. Optionally tick the access levels to give everyone imported (see "The preview page" below).
  6. Check the sample rows (the first 12, with any per-row problem flagged) and press Run import.

Format rules:

A minimal file looks like this:

First name,Surname,Token number
Alice,Example,12345678
Bob,Sample,12345679

Import from an AC8000 / iCCard3000 backup

Sites running the AC8000 family of standalone controllers (the PC software is called iCCard3000 or AC8000 depending on the version) usually have no export function, but the software keeps its whole database in a Microsoft Access file and can back it up. That backup contains everything the wizard needs: the people and their card numbers, the readers and doors, and every swipe the system recorded.

Where the backup comes from. In the AC8000 PC software use its backup (or database backup) function; it writes a file with an .mdb extension, typically named after the software and the date, for example iCCard3000-2026-09-07_135352_92.mdb. Copy that file to the computer you use for the panel. If you cannot find a backup, the live database the software uses is the same kind of file and can be copied while the software is closed.

The import wizard after reading a backup: the AC8000 / iCCard3000 source is selected, the file has been read in the browser, and the summary shows how many people and swipe records were found and which doors are named.
The import wizard after reading a backup: the AC8000 / iCCard3000 source is selected, the file has been read in the browser, and the summary shows how many people and swipe records were found and which doors are named.

The steps:

  1. Open Enrolment, scroll to Import people and fobs and choose AC8000 / iCCard3000 backup (.mdb).
  2. Under Backup file (.mdb) choose the file. It is read in your browser, not uploaded: only the people, fob codes and history you go on to confirm are sent to the panel. After a moment a summary appears: how many people with cards were found, how many swipe records and the dates they span, and the door names found in the backup. If any people had a keypad PIN in the old system, the summary says so and reminds you that PINs are not imported.
  3. Choose the Reader format at your doors: Wiegand 34 (8 hex digits) or Wiegand 26 (6 hex digits). This decides how the decimal card numbers in the backup are written as fob codes, and it should match what the readers on the new controllers send. If the backup contains a card number above 16,777,215 (the largest value a 26-bit reader can send) the wizard knows the site's readers must be 34-bit and sets 8 digits for you, with a note in the summary. Otherwise the default is 8 digits; change it to 6 if your readers are Wiegand 26.
  4. Leave Include the swipe history ticked to bring the old log across, or untick it to import people and fobs only.
  5. Leave Rows with the same name are one person with several fobs ticked unless you want every card to become its own person. See "One person, several fobs" below.
  6. Press Continue to preview.

What is read from the backup:

What is not imported:

Status, valid-to dates and notes

The wizard carries across three things beyond the name and the card, and they are worth understanding because they decide who arrives switched off:

Everyone else arrives active. Review the inactive people after the import: some will be genuine leavers to move to the trash, others will be members whose renewal never got recorded in the old software.

One person, several fobs

Standalone systems commonly hold one record per card, so a member who was issued a replacement fob appears twice with the same name. The wizard's Rows with the same name are one person with several fobs option, which is on by default, collapses those into a single person holding both fobs. It is the behaviour you almost always want: one person on the People page, both cards working, one set of access levels.

Untick it (in the wizard, or on the preview page) if the duplicate names are genuinely different people. Each card then becomes its own person, and the AC8000 record number is appended to the name to tell them apart, for example "J Smith 0042" and "J Smith 0117". Rename them afterwards.

The same fob at more than one site

A fob code is unique within a tenant, not across the panel. The same backup can therefore be imported into a second tenant (a test tenant, or a second building of the same operator) and the cards attach there too, independently. A resident who holds one fob for two buildings you manage is a person in each tenant, and revoking them in one has no effect on the other.

The preview page

The preview for a backup import: the columns are already mapped, access levels can be ticked for everyone imported, and the History panel offers to import the swipe records and create the door named in the backup.
The preview for a backup import: the columns are already mapped, access levels can be ticked for everyone imported, and the History panel offers to import the swipe records and create the door named in the backup.

The preview page is the same for both sources. It says how many rows were found (and, for a backup, that they came from the AC8000 / iCCard3000 backup), and shows:

Press Run import (N rows). Until then nothing has been written; you can go Back to enrolment and start again with different options.

What the import does

The result message on the People page reads, for example, Import done: 94 people created, 94 fobs attached, 0 skipped, 0 failed, 644 history records added to the Log. The same numbers are written to the Log as a system event (CSV import, reason import) whichever source was used.

Tip: the panel matches a fob whether it is stored with 6 or 8 digits (0136A9 and 000136A9 are the same fob), so a code imported at the wrong width still opens the door when the reader sends the other form. What no setting can fix is a Wiegand 26 reader presented with a card above 16,777,215: it physically cannot send the high bits. See "Imported fobs are denied at the door" in chapter 17.

Check a fob

Two tools tell you what a fob is and what it does:

Active and inactive

Setting a person's Status to Inactive (all access suspended) stops every fob they hold from opening any door, immediately, without touching the fobs or their levels. The log shows Person inactive for their attempts. They also cannot release doors by phone. Use it for lapsed memberships, suspended accounts and leavers who may come back. Set them back to Active to restore everything exactly as it was.

Inactive people are not counted in the dashboard's "Active people" tile but do appear in the People list with an "inactive" badge.