Header Logo
Log In
← Back to all posts

Volume 30

Aug 03, 2026

Volume 30 | August 15, 2025

This Week’s Featured Articles & Media

Travis Willis | What is KYC
What if your phone could securely prove who you are and unlock doors —no ID badge, no plastic card, no in-person verification needed? This insightful piece explores how digital identity, KYC/KYE, and mobile wallets are revolutionizing physical access control in a way that’s secure, seamless, and privacy-preserving.

Tony Dong | How to Properly Quantify the Risk of Your Investments
This piece explains why common risk metrics like volatility, max drawdown, and value at risk often mislead more than they inform—and how thoughtful, data-driven approaches can offer leaders clearer insight into true investment risk.

Jon Polly | Technology Focused Issue #1 - ONES Technology
Welcome to Issue #1 of "The Art of the Possible – NOW," where emerging tech meets real-world security challenges. This edition highlights how Ones Technology is redefining biometric access control through decentralized credentials, secure presence, and anomaly detection—proving that the future of physical and cybersecurity isn’t coming, it’s already here.

The Access Control Collective | Breaking News Alert
Brivo & Envoy partner to elevate access control, visitor management, and commercial user experience. Read the story below.

The Access Control Collective | ACS LATAM
The Access Control Collective is heading to São Paulo for ACS LATAM 2025! In partnership with Google and with support from HID and ASSA ABLOY, this event is set to be a cornerstone gathering for the region. Don’t miss it. Find the link to register below.

The Access Control Collective x Bloxspring | RAMP: The Conference for Marketing Leaders in Security and Protech
RAMP 2025 is a conference designed specifically for marketers in built environment technology and security—bringing industry leaders together in New York City for a full day of insight, innovation, and meaningful connection.

The Access Control Collective | PhySecJobs.com
Below you will find all of the latest jobs in the physical security industry.

Find them all below!


Good morning kids. Today we are going to talk about KYC. I am realizing that this is a bit of an unknown acronym in the world of physical security along with KYE, yeah I know another acronym but trust me these are easy to understand. And Jonathan Lawry I hope this is one of those "insightful" posts I occasionally make about access control.

KYC stands for "Know Your Customer" and KYE stands for "Know Your Employee" and both of these are important to physical security applications especially as they intersect with mobile and wallet credentials.

Historically we in the physical access space have relied upon our end user clients to validate the identity of their card holders (KYE). They do this by following some sort of badge enrollment process where the end user HR department and physical security department collaborate to verify the badge holder is who they say they are and then they get issued a physical RFID card that may or may not include their picture for identifying purposes (KYE). That card comes with some random number assigned to it which then gets entered into the PACS system. This is an "in person" experience typically. All good so far?

In the financial world and a few related spaces they issue cards remotely. Now in the case of a credit card you really want to know it's going to the right person. And let's face it a credit card is an RFID card...with me so far? This is where Lee Odess has been exploring the intertwined history between the card payments space and physical access space. We started out together but then diverged and now we are coming back together.

Financial Institutions and related industries have digitized the verification process in the form of "KYC" activities. They leverage digital tools to remotely confirm the identity of the recipient card holder. Whole companies have now emerged dedicated to delivering this digital verification process. These are companies like CLEAR. ID.me iProov Veridas there are a lot of them.

You probably have noticed that I like and re-share a lot of content from companies like this and more and more of my content is about IAM/PIAM and identity and that is because it is intersecting with what we are doing in the mobile physical security space. I also post about mDL's and eIDAS and VC's aka Verifiable Credentials. These are all part of the digital toolbox used to validate identity remotely and issue "credentials" to mobile digital wallets from Apple, Google, and Samsung. Wallets BTW that are designed to hold your identity digitally and enable that digital identity to be shared securely.

The major mobile phone companies are collectively working to transform user behavior on a global scale. The mobile phone has become an integral part of most people’s lives, and Apple, Google, and Samsung aim to keep it that way by delivering more services—conveniently and securely (that’s the promise)—via the device in your pocket, purse, or bag. The digital wallet is designed to support four major categories of interactions or transactions: payments, access, identity, and loyalty. Payments were the first service to be successfully deployed and have seen steady global adoption—after all, everyone needs to pay for things. It began with simple “tap to pay” functionality but has since evolved to support more complex user operations.

For example, you can now use your mobile phone to access a service, sign up, and instantly pay using the credit card stored in your digital wallet in just a few steps. No more pulling out your physical card and manually entering 16-digit numbers and security codes into an app or website. Two clicks, and voilà—you’ve made a payment. This is a game-changing capability, paving the way for increasingly frictionless transactions. The real value lies not in the “tap” itself, but in the back-end APIs that connect and streamline these transactions via the wallet securely. 

Digital wallets are increasingly being leveraged to enable secure physical access. Apple, Google, and Samsung are partnering with leading access credential providers—such as LEGIC, HID, Wavelynx, and others—to bring secure digital credentials directly to users’ smartphones. As with payments, the initial emphasis has been on “tap to access.” The benefit for users is clear: simply present your phone to a reader or lock to gain access to a space or location. This capability is designed to replicate and eventually replace the physical RFID card, just as digital wallets are replacing physical credit cards.

So how do we remotely verify we are sending the access credential to the right person? We no longer want or need the employee to come in and go through the in person process but we still need to make sure they are them. In the physical security world our job is to as Lee Odess says “keep the bad people out and let the good people in”. How can we do this if when we onboard the person we don’t actually meet and vet them?

Enter Know Your Employee (KYE) a digital process that allows a business to remotely verify an employee’s identity. With the surge of AI this has now become critical with bad actors using AI to impersonate a hiring candidate in order to gain inside access to a businesses systems. Daily we are seeing examples of how good AI is becoming at spoofing people and deep faking things. Not even your voice is safe anymore as Sam Altman recently pointed out. 

The companies delivering KYE specialize in gathering and validating multiple identity elements to confirm with a high degree of certainty that you are in fact you. One of the most visible companies doing this is CLEAR and they have established a process credible enough to satisfy the high standards of the Transportation Security Administration. Most KYE systems gather a mix of state issued identity documents and biometrics along with a few other data points to ensure the “genuineness” of the identity of the person. CLEAR has also partnered with LinkedIn for the “verify now” feature. 

Now full disclosure I have picked on that feature before and I still remain “unverified” as of this writing. BUT…I will be going through the process soon enough and sharing some insights. This is all of course in the name of education…but back to the topic at hand.

3rd party services like CLEAR are now working with businesses to deliver KYE services to their HR and Security Departments. These digital verifications then can trigger the release of a secure NFC wallet credential for an employee to be deposited into their phone wallet. All of this verification is now also being delivered by Credential Managers like Swiftconnect, Alert Enterprises, any2any and Soloinsight to name a couple of key players. Additionally companies like Safetrust are handling this for major enterprise companies.

But WAIT there IS more! Are we discussing KYC and KYE like it is a Shamwow!? Yes, because the more you wring it out the more it gives you back. AND the beauty of a Shamwow is its re-usable! Okay Travis what are you talking about? I am talking about re-usable digital identities that the Customer owns or the Employee owns. How do they do that you ask? Well it starts with having their verified identity in their phone wallet.

Currently 15 states have implemented digital drivers licenses which are referred to as mDL’s. These are digital versions of your State issued drivers license. How many times and places do you have to present your drivers license? A lot.

Just like the other elements in the wallet though the true benefit is not the “tap to identify” but the back end API’s that link all these transactions together. The digital ID in the wallet is now a trusted and secured identity that can be used to update various systems and remove the manual elements associated with user verification. As a digital wallet user I can remotely, digitally check in someplace, be challenged to identify myself and “double click, face ID or thumb print” etc. to validate myself via the mobile device to the back end system requesting my identity. This can then trigger the deposition of my NFC access credential, aka “access key” for my office, hotel, doctors office, sporting event, school classroom or wherever I need access to into my digital wallet via web provisioning. This now disintermediates the employee RFID card workflow exchange noted at the beginning of this article. 

An additional benefit of this process for the user is that it is “privacy preserving” meaning I can decide what I share, when I share it and who I share it with. Today when I hand over a physical drivers license or passport additional information is present for the recipient to see. By using the digital wallet process the user and access controller gain privacy protections, data protections and a more frictionless experience on both sides of the transaction creating a “win win” situation.

By digitizing your identity and connecting the wallet via APIs you can now validate you are you on the fly as needed by simply interfacing with your phone and possibly its biometric tools onboard in conjunction with the wallet. Just as they have streamlined payments they Apple, Google and Samsung can streamline sharing your identity.

This process is auditable and verifiable electronically to ensure its security integrity. The NFID Foundation was created to help the Access Control Industry be aligned with itself and the larger ecosystem of verifiable credentials. BTW you need to join us at the NFID Foundation, and with that I think I need to write a follow up piece that dives deeper into what is happening there.


If I have to see another color-coded risk matrix with probability plotted on the x-axis and impact plotted on the y-axis, I’m going to lose it.

If you’ve ever wondered why you can’t get executive buy-in for risk management, compliance, cybersecurity, or any other cost center in the middle office, this kind of elementary analysis is a big reason. It doesn’t provide decision-useful insight. It reduces real-world risk to dots in a square.

I’m not asking you to become an expert in the methods I’m about to outline. Most are geared toward investing anyway. But as a senior leader, you have no shortage of smart people working under you who have the skills, drive, and curiosity to push these forward. By enabling them to do so, the entire organization benefits.

Warren Buffett once said that risk comes from not knowing what you’re doing, but many people misinterpret that as “I have industry knowledge and years of experience, so I know what I’m doing, therefore this is low risk.” 

That’s the wrong takeaway. What he meant is that you should support your reasoning not just with experience or gut feel, but with clear logic grounded in evidence. And that starts with data. 

So, this is my take on where things stand: how to properly understand the risks associated with investing, through a more grounded and quantitative lens.

Volatility: The Basic Measure of How Much Returns Fluctuate, Not Whether They’re Good or Bad

Volatility is usually the first number people gravitate toward when assessing risk. It’s a measure of how much an investment’s returns bounce around over time, most often expressed as the standard deviation of returns. 

The chart here shows monthly rolling volatility for a fund tracking the S&P 500 index. It gives you a sense of how stable or erratic an investment in large U.S. stocks tends to be, which is useful for portfolio construction, setting expectations, or comparing two similar funds.

But volatility only tells you how much something moves, not in what direction. A highly volatile investment might have wild swings upward and still outperform over time. Conversely, something with low volatility can steadily lose money and still show up as “safe.” 

Volatility is also backward-looking and assumes a normal distribution, which many real-world investments don’t follow. Don’t mistake low volatility for low risk, or high volatility for recklessness. 

Max Drawdown: The Basic Measure of Worst-Case Losses from Peak to Trough, Not Ongoing Risk or Future Pain

This following chart shows the biggest drop the S&P 500 has experienced from a prior high over the last decade. It’s useful for understanding what kind of pain an investor could have felt if they bought at the top and held through the bottom. 

For example, a 33.7% max drawdown means that at some point, the value of the investment fell by that much before recovering. It tells you historical downside exposure and how much grit someone needed to hang on. It’s a good gut-check for risk tolerance.

What it doesn’t tell you: how often these drops occur, how long the recovery took, or whether the future will look the same. Max drawdown is backward-looking and doesn’t account for the timing, frequency, or duration of volatility. It also doesn’t tell you how an investment performed afterward.

Don’t mistake it for a prediction. It’s a snapshot of the worst case so far, not a forecast of what’s ahead, and it is period specific. 

Value at Risk: The Hypothetical Loss You Could Expect, Not a Guarantee of What You'll Lose

The next chart shows a statistical estimate of how much an investment in a S&P 500 fund could lose in a worst-case scenario over a set period, with a defined confidence level. 

For example, a monthly 95% value at risk (VaR) of 6.63% means there’s a 95% chance you won’t lose more than 6.63% in a single day, with a 5% chance you could lose more. 

What VaR tells you is a probabilistic threshold of potential losses based on historical data or modeled simulations. It’s a tool for setting risk limits, comparing portfolio exposures, and understanding tail risk under normal market conditions.

What it doesn’t tell you is what happens during extreme or chaotic events, how losses behave during crises, or the full distribution of potential outcomes. VaR therefore won’t tell you what your loss is expected to be during that 5% tail risk chance. It just tells you where the threshold starts.

Don’t mistake VaR for a hard ceiling. A 5% chance might sound remote, until that’s the day you’re in. VaR assumes normalcy, which markets tend to violate at the worst possible times. The key to interpreting VaR is understanding it’s about likelihood, not certainty, and should be paired with stress testing.


This is Issue #1 for what I hope is a regular cadence of technology focused insights into the Art of the Possible - NOW.

Why the image of the telescope? A telescope is a device that makes distant objects appear closer, allowing us to see more details in focus. This seemed like a great image for Technology Focused, and it's the cover image on my website (https://www.protechtsolutionspartners.com/).

I have two taglines that I use frequently. 1) The best technology in the world, for the wrong use case, is the wrong technology, and 2) I geek out over security tech and tell people about it.

Hence the reason for this post!

Find the best technology for the right use case!

I was introduced to Ones Technology recently to see what they were doing in the biometric and credentialing space.  Okay, sure, they won the Security Industry Association (SIA) New Product Solutions for both Best in Biometric and Best in Mobile at ISC West 2025.  But everyone has awards, right? That said, they were on the radar, but I have to say thank you to Allan Chester for pushing me to see what Ones Technology was really doing. Onur Sirmatel and TĂĽnay Karatekin did not disappoint.

Ones Technology, a Turkish access control and biometric manufacturer, is merging physical security with cybersecurity.  I’m not talking about having a hardened device; those are table stakes. Ones Technology is using physical credentials layered with biometric data to provide a secure credential.  This credential is being used like a PIV card in the US, where data is cryptographically matched on both the panel and the card.

Here’s a use case.  I have a document, maybe it’s a passport, that I present to another person/entity/etc.  They look at that document, inspect it, but at some point, they have to assume that on the physical look of the document, it is valid.  Let’s think mobile Driver’s License (mDL) here in the States.  But what if there was a way to authenticate credentials by a cryptographic handshake that confirms that the document, mDL, etc., can in no way be counterfeit.  ONES Technology is one of the technologies at the center of this idea.  Imagine being able to have something like a sensitive compartmented information facility (SCIF)-on-the-fly, offering authentication of identities (not just allowing access based on credentials) between individuals at, say, a coffee shop. Salvatore (Sal) D'Agostino, Doug OGorden something you may want to look at.

They have been doing this with both government, airport, and financial clients in Turkey, providing access control to thousands and the ability to scale.

Okay, so does a whole host of other access control companies.

Here’s where it gets interesting.  They aren’t just trying to build a company.  That’s done.  They are building an ecosystem, with partners like LEGIC, Intel Corporation, any2any GmbH , and more manufacturers... maybe even yours.

One of the most intriguing things about the tech that ONES Technology is building, and where I am the most excited, is that they are using a decentralized model.  You, as the credential holder, hold your data.  You, as the credential holder, give over only the amount of data that is minimally required, or that you wish to give (maybe it's more than needed). NFID Foundation PassiveBolt Kabir Maiga, partnerships? I would add in here Travis Willis, CFF but you already know.

Even more intriguing to the conversation was that they are solving real issues that are complex. Not that other companies have not, but let's be honest, there are a number of complex issues that, for whatever the reasons, have not been solved for in our industry. One of the real issues that Ones Technology is solving for is the impossible travel issue - how to prevent a person in New York and the same person in Los Angeles from swiping a reader at the same time.  There are folks, like Joseph Baker who have done this.  It’s not an easy task.  And yet, Ones Technology has developed a technology that ties access control to liveness and location, in what they refer to as secure presence; the outcome is to use a region of interest in the real world to solve for cybersecurity issues.  That may be an industry first.  Now add in that the system can also do anomaly detection.  Like the guy who has access to the site on a Saturday, but hasn’t shown up on a Saturday in the last 4 years.  When he does, he is allowed in, but does that anomaly prompt some additional concern or reason to have a purposeful but friendly conversation?  I've only seen one other technology do this successfully, Davista and Scott Sieracki. While security teams are inundated by false alarms, why would they dispatch on an anomalous alert for someone who has granted access?  Possible insider threat who doesn’t want to carry out their nefarious actions with co-workers around, or simply a project that has become overwhelming for the normal 9-to-5?

In a recent post on LinkedIn, Lee Odess refers to Ones Technology as a mosaic – the taking of small bits and pieces, putting them together to create a beautiful picture.  I’ll take that one step further and say that Ones Technology appears to be making a mosaic inside a mosaic.  What I mean by that is that Ones Technology is a solid company that has been around since 2008, with thousands of deployments.  One mosaic is built, but they are now expanding that ecosystem to encompass the first mosaic into the next one.  There is already a picture there, and it looks great, but with more ecosystem partners coming on board, imagine what that will do.

As my call with Ones Technology ended, someone laughed because I had a grin on my face.  The Art of the Possible is NOW.  It is exciting to see Ones Technology and companies with that mindset becoming Agents of Change, offering a fresh take on what we as a security industry can do. I make no apologies, I want to be an Agent of Change, not to tear down the security industry, but to help change mindsets and focus, before the industry gets left behind. Let's learn from the lessons of old, but be willing to grow using that knowledge.

ProTecht Solutions Partners, LLC is your security advocate: a security technology consulting firm dedicated to helping companies keep people and assets safe.  We realize security technologies are part of a larger solution for most companies, with requirements to bring business intelligence, sustainability, and more. With ProTecht Solutions Partners, LLC, the system you implement is always tailored to the specific needs of your company.


🚨 Breaking News: Brivo and Envoy Announce Strategic Partnership to Transform Access Control and Visitor Management

Brivo and Envoy have joined forces to launch Brivo Visitor Management, powered by Envoy—a fully integrated, scalable solution that combines Brivo’s cloud-based physical security with Envoy’s leading workplace platform.

This new offering unifies visitor management, access control, video intelligence, and intrusion detection, streamlining compliance and creating a seamless, secure check-in experience for organizations of all sizes—from single offices to global enterprises.

This partnership is a standout example of two companies focusing on their strengths:

  • Brivo brings decades of expertise in unified security.

  • Envoy leads in connecting people, spaces, and data.

Together, they’re delivering more than just integration—they’re redefining what a best-in-class, unified solution looks like.

Benefits across the ecosystem:
👉 Channel partners gain a premium, turnkey offering
👉 Commercial customers see improved efficiency and compliance
👉 End users enjoy a smooth, modern, and secure welcome

This collaboration shows how the industry advances—by breaking down silos, combining strengths, and building smarter, more connected solutions.

Kudos to Steve Van Till, John Szczygiel, Larry Gadea, and Mort Jensen on a forward-thinking partnership!

To learn more, click here.




Below are the highlighted jobs and companies this week. New jobs are bolded.

  • Preventia Security 

    - Regional Sales Manager - South - apply here

    - Director of Sales - apply here

  • Lockmasters, Inc. - VP of Specialty Door Division - apply here

  • EyeOTmonitor - Account Executive - apply here

  • HID Global 

    - Senior Product Manager, Government Solutions-North America – apply here

    - Product Manager, Mercury Controllers – apply here

    - Senior Product Manager, Readers – apply here

    - Senior Product Manager, Biometric Readers – apply here

    - Senior Software Engineer Java – apply here
    -Pre-Sales Consultant – apply here
    -Staff Engineer – apply here
    -Channel Account Manager DACH – apply here
    -End User BDM - Emerging Technologies – apply here
    -Director of Quality – apply here
    -Director of Product Management - Readers – apply here
    -Sales Development Representative – apply here
    -Product Manager, Credentials – apply here
    -Business Development Leader, Controller Apps – apply here

  • Kastle - Project Manager, Implementations - apply here

 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 69
Volume 69 | July 24, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE DealTwo decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.Listen here ✍🏻 Ar...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.