Access Control

Multi-Site Access Control Why Badge Systems Fail and Mobile Credentials Win

September 14, 2026 · 8 min read

The Math of Multi-Site Access Control

You've got 8 buildings. 340 employees. 12 visitor check-ins per day. Each location runs its own badge system because the previous integrator set them up independently. When someone transfers between sites, facilities calls IT. IT manually provisions a new badge. That takes 3 days. Meanwhile the employee can't access the second floor at the new building.

Now add a contractor who needs temporary access to three buildings for two weeks. The access control admin at HQ doesn't have visibility into what's happening at the remote site. You find out about it when the contractor shows up and the reader isn't programmed.

This is what happens when you treat each location as an island.

Why Badge-Only Systems Break at Scale

Traditional badge readers tied to on-premise controllers work fine in single buildings. Each location has its own access control server, its own database, its own management interface. The problem emerges the moment you add a second site.

You now have:

  • Separate credential databases that don't talk to each other
  • Multiple admin interfaces (one per location, or a clunky third-party sync tool)
  • No real-time audit trail across all sites
  • Visitor management handled differently at each building
  • Offline operation that works locally but creates sync nightmares when connectivity returns
  • Hardware refresh cycles that don't align
  • Badge replacement logistics across geographies

Add a third site and complexity compounds. You're managing inventory, training facility staff at each location, and coordinating with your security team who wants centralized reporting.

The badge itself becomes a liability. Lost badges need deactivation across all systems. Damaged readers at one site don't affect others, but troubleshooting becomes a phone call to the local facilities manager who may or may not know how to check door logs.

Cloud Access Control Changes the Game

Platforms like Brivo Multi-Site flip this model. One cloud instance. All locations reporting into the same system. Add a user once. They get access at every site where you've provisioned them. No sync delays. No manual database updates.

What actually changes:

  • Credentials become software-defined. Add someone in the morning, they have access by afternoon across all eight buildings.
  • Mobile credentials (via smartphone app or digital wallet) replace physical badges. No manufacturing, no replacement cycles, no lost badge calls at 8 PM.
  • Visitor management integrates into the same platform. A visitor checking in at the lobby gets a time-limited credential that works at their assigned meeting rooms, nothing else.
  • Video verification at the door. Brivo and other modern platforms integrate door cameras so your access control admin can see who's actually at the door when an access attempt fails.
  • Audit trails are unified. Every access event at every site flows into one searchable database.
  • Offline operation still works. If the internet drops at a remote site, the PoE door controller keeps functioning with cached credentials. Sync happens automatically when connectivity returns.

Network and Infrastructure Requirements

This isn't a swap-and-go project. Your IT team needs to be involved from the kickoff.

Internet connectivity at every site. Cloud access control needs reliable uplink. Not necessarily fast (2 Mbps is usually plenty), but reliable. If you've got sites on residential cable internet or spotty wireless, this conversation changes. You may need to upgrade to business-class connectivity or hybrid operation (cloud with local failover). Brivo handles offline scenarios, but you're not getting real-time credential updates if the link is down 40% of the time.

PoE budget for door controllers. Modern cloud access control systems like UniFi Access and Brivo's ecosystem use PoE-powered controllers at each door. That's different from traditional access control where you might have one beefy controller in a server room and long cable runs to readers. Now you need PoE switches at each entrance, or you're running a mix of PoE and traditional readers (which creates maintenance headaches). Calculate your PoE load: each controller draws 10-15W typically. A 48-port PoE+ switch gives you about 740W total. That's enough for 50 doors if you're not running cameras on the same circuit.

VLAN segmentation. Access control traffic should live on its own VLAN, separate from guest WiFi and general office networks. This isn't paranoia. It's because access control systems sometimes get noisy with broadcast traffic, and you don't want a misconfigured camera or printer flooding your credential authentication requests. Set aside a dedicated VLAN (e.g., 50) for access control. Tag it at your core switch and at each location's access switch. Your firewall rules should allow access control servers to reach Brivo's cloud APIs on port 443, nothing else.

Bandwidth per location. A single door controller sends maybe 10-50 KB per access event. With 100 doors and 500 daily access attempts, that's roughly 5-25 MB per day. Not a problem on any modern connection. But if you're running video verification (camera feed pulls when someone denies access), add 1-2 Mbps during peak times. Most sites won't notice it. Just don't put access control on a shared T1 with 40 other buildings.

Badge vs Mobile Credentials: The Real Tradeoff

Mobile credentials (delivered via smartphone or digital wallet) are faster to provision and eliminate physical badge management. But they're not free of friction.

Mobile credentials work best when:

  • Your workforce is 80%+ smartphone-equipped
  • You control the mobile device policy (iOS and Android support, not flip phones)
  • You've got WiFi or cellular coverage at each entrance
  • Visitors are willing to download an app or scan a QR code

Keep badges when:

  • You've got a large contractor or visitor population that changes weekly
  • Outdoor sites with spotty cellular coverage
  • Compliance requirements mandate physical credentials (some manufacturing and pharmaceutical settings still do)
  • Your users are mostly shift workers who share devices

Most multi-site operations run hybrid: mobile credentials for permanent staff, badges for visitors and contractors. Your access control platform should support both. Brivo does. UniFi Access supports mobile but is still building out visitor credential features.

Visitor Management Integration

This is where cloud access control really earns its cost. A visitor arrives at the main lobby. Your receptionist checks them in via a web portal (or iPad app). The system generates a temporary credential. The visitor gets an SMS with a QR code or digital key. They tap their phone at the turnstile or door, and it grants access to only the areas you specified (say, Conference Room B and the restroom on the third floor) for exactly 4 hours.

No badge printing. No manual deactivation at end of day. No badge left behind on a desk.

When integrated with video at the door, your security team can see the visitor's photo (captured at check-in) alongside the live camera feed when they arrive. If someone tailgates, it's visible in the audit log with video proof.

This integration requires that your visitor management system (Brivo has one built in) can push credentials to your door controllers in real time. If you're using a separate visitor system that doesn't integrate, you lose the automation and end up with manual workarounds.

Phased Rollout Strategy

Don't migrate all eight sites at once. Pick your largest or most stable location first. Get the network team comfortable with the VLAN setup, the PoE infrastructure, and the cloud API integration. Run it parallel with the old system for 2-4 weeks. Then cutover.

After you've got one site stable, add the second. By site four, your facilities team knows the mobile credential workflow, your IT team has the network dialed in, and you've hit most of the gotchas.

Budget 2-3 weeks per site for planning, 1 week for hardware installation and testing, 1 week for parallel operation. Total project timeline for eight sites: 3-4 months if you're running them sequentially, or 6-8 weeks if you've got crews working in parallel.

Real Constraints to Plan For

Cloud access control isn't free of failure modes. Your internet goes down, credential provisioning stops until it comes back up. If you've got a remote site with unreliable connectivity, you need local failover (a small on-premise controller that caches credentials and keeps doors working offline). That adds cost and complexity.

Mobile credentials require device management. You'll need MDM or at least a clear BYOD policy. Brivo works with most MDM platforms, but the integration isn't always automatic.

Visitor credentials are only as good as your check-in process. If your lobby staff forgets to deactivate a contractor's access at end of day, they still have a valid credential. Automation helps, but it doesn't replace human oversight.

Hardware refresh cycles still exist. PoE door controllers fail. Readers wear out. Plan for 5-7 year hardware lifecycles per location, and budget for replacement inventory.

Getting Started

Start with a site audit. Count your doors. Map your network topology at each location. Test internet reliability. Then talk to your access control integrator about Brivo or UniFi Access and what a phased rollout looks like for your footprint. The upfront planning saves weeks of rework down the line.

← Back to All Articles