Header Logo
Log In
← Back to all posts

Volume 49

Aug 03, 2026

Volume 49 | February 27, 2026

This Week’s Featured Articles, Media, & Breaking News

✍🏻 Articles

Danny Smith | The Campus Identity Transformation: What Physical Access Control Providers Need to Know
The OneCard era is ending, and providers who don’t address identity complexity risk being displaced.
Read below

Ivan Kravchenko | How iOS Lock Screen Widgets Change Mobile Access for Good
A closer look at how lock screen triggers reshape credential strategy beyond Apple Wallet.
Read below

Johan Fagerström | Evidence correlation with Adjacency Groups
What happens when security systems understand physical relationships instead of just recording events.
Read below

Jon Polly | Avoiding the Noise
How to avoid Shiny Object Syndrome and make smarter tech decisions at ISC West.
Read below

Aastha Sharma | The Badge Is Dead. Your Phone Is the Key. Over 200 Companies Made It Official.
What Aliro 1.0 means for interoperability, vendor choice, and the next decade of access control.
Read on LinkedIn

🎙 Secured Podcast

Episode 5 | The One-Card Campus Model Is Collapsing. Here's What's Next.
A breakdown of earnings shakeups, the “Visa layer” for access control, and the four buyer mindsets reshaping the industry.
Listen now.

Live from Intersec Dubai: Ryan Kaltenbaugh (M.C. Dean)
Why 2025 was a turning point, from Middle East growth to large-scale infrastructure opportunities.
Listen now.

🚨 Breaking News

Breaking: Aliro 1.0 specification has just been released

Breaking: dormakaba announces a strategic investment in SwiftConnect

Breaking: HighlandTech introduces Electra, an AI agent operating system built for physical security

Breaking: dormakaba reports H1 FY2025/26 results

Breaking: Deep Sentinel integrates with UniFi/Ubiquiti Inc. turning existing cameras into live-guard security systems

Breaking: Spintly raises $8 Million Series A funding

Scroll down to go deeper â†“


Campus identity infrastructure is undergoing a fundamental shift right now. For Physical Access Control Providers, this transformation represents both opportunity and complexity. Understanding what's happening on the other side of the door has never been more critical.

The OneCard Model Is Breaking Down

For decades, campuses turned to OneCard systems believing they were investing in a unified, streamlined solution. What many have come to realize is that unified came with a cost: a closed-loop system that locked them into proprietary stacks bundling credentials, payments, and access control with little room to adapt, switch providers, or evolve. That era is ending. Disaggregation, the separation of identity infrastructure from the applications that depend on it, such as payments, dining, parking, and physical access control, is no longer a theoretical alternative. The Transact/CBORD merger has accelerated what was already underway: institutions actively exploring how breaking apart these bundled systems delivers cost savings, operational efficiency, and genuine flexibility to choose best-in-class solutions independently. For physical access control providers, this shift is both a warning and an opportunity.

The Strategic Reality

When institutions modernize their identity infrastructure, they’re asking questions that go beyond the specification of hardware: How do we achieve true interoperability when we have three different access control systems across our campuses, none of them talking to each other, and credentials that work in one building but not another? That's the reality many institutions are living with today.  How do we support cards, mobile credentials, and biometrics from one platform? How do we integrate identity independently with dining, parking, and other campus applications, giving us the choice to select whatever solutions we want and change providers when it makes sense?

With OneCard systems, institutions are limited to whatever applications the OneCard provider offers or approves. With independent identity infrastructure, they can choose from a portfolio of solution providers, each with differentiating value and scope, and switch when better options emerge.

Here's what matters: your expertise is at the door, the hardware, readers, cameras, and systems that grant access. But behind every credential is an identity ecosystem. How it was issued, whether as a physical card, mobile wallet, or biometric, how it's managed across its lifecycle, and how it authenticates to every application it touches, dining, parking, printing, and building access, that's the world your customers are navigating. If you can't address it, your competitors will. Partnering with an identity expert, one who has spent 26 years managing the full credential lifecycle across every modality, system, and campus application, removes complexity for your customers while enabling you to offer a more complete, differentiating solution that deepens customer relationships and protects your business from competitive threats.

The Credential Reality Most Vendors Miss

The mobile credential deployment reality is more complex than vendors often acknowledge, and we know this firsthand. Over 26 years and tens of thousands of technical identity integrations, we've seen what works, what doesn't, and what institutions are actually dealing with on the ground. It requires significant investment in reader infrastructure, staff training, user education, and ongoing support. Few institutions will go digital-only. Most will operate hybrid environments for years, if not indefinitely. And that hybrid reality has to be effectively supported, not ignored.

This is where having a full-stack identity expert matters. Some credential management platforms focus exclusively on the software layer, automating workflows and connecting systems, but stop short of the physical credential infrastructure institutions still depend on. They don't support card issuance, printer hardware, or the service and support that keeps physical credential programs running, assuming institutions will simply abandon decades of physical infrastructure. In almost every deployment, multiple credential types coexist and need to be supported simultaneously.

What Makes an Identity Partner Different

At ColorID, we don't compete with access control providers, we enable them. The distinction matters:

  • We’re agnostic to credential modality. Deploying mobile wallet credentials takes significant time, effort, and expense. Institutions need partners who can support a flexible, affordable pathway that fully manages physical credentials as they coexist with digital and biometrics, not force a binary choice that doesn’t reflect operational reality.

  • We unify disparate systems. Many institutions operate multiple access control platforms across different buildings, campuses, or affiliated facilities. We provide centralized credential management and true interoperability across those disparate systems, something most access control providers can’t or don’t want to do. Geographic dispersion creates unique complexity, whether campuses are across town or across the world. One platform managing all credential types (cards, mobile, biometric) across all locations and all access control systems makes your solution more valuable, not less.

  • We integrate beyond access control. Through CardExchange® Cloud, credentials authenticate to dining, parking, vending, transportation, printing, any application that uses credentials. We work with best-in-class partners in each category or integrate with systems institutions already have.

  • We support your customer relationships. By removing the complexity of identity infrastructure from your customers’ plate, you can focus on what you do best while offering a more complete solution. This differentiation strengthens your competitive position and deepens customer relationships.

What This Means in Practice

When access control providers and ColorID work together effectively, the results are tangible. Your customers get unified credential management without you having to become identity experts, and you're able to offer comprehensive solutions that hardware-only competitors simply cannot match. Solving the full identity challenge creates stickier, more strategic customer partnerships, and addressing it proactively prevents competitors from using identity infrastructure as a wedge to displace you.

The access control providers winning in this market are the ones building ecosystems of best-in-class partners. Those who recognize that comprehensive identity infrastructure strengthens rather than threatens their position will be the ones their customers choose and stay with.

Physical Access Control Providers have a choice in this shifting market. You can try to expand into identity management and compete with specialized platforms that have decades of experience. Or you can partner with identity experts who make your access control solutions more valuable by handling what happens on the other side of the door.

This is what disaggregation enables. This is what your customers expect. And this is where the market is headed. 


Apple’s introduction of lock screen widgets starting with iOS 18 has opened a new chapter for mobile access control. For the first time, users can initiate secure access flows directly from the lock screen, reducing the entire door‑opening process to a single tap. This usability leap makes mobile credentials faster, more intuitive, and more attractive for organizations seeking a smooth, wallet‑free access experience – without compromising security.

One‑Tap Access Experience

Before lock screen widgets, a typical mobile access flow involved multiple steps: Wake the phone → Open the app → Select the action → Present the device to the reader With lock screen widgets, this friction disappears. A single tap instantly activates the app in the background, prepares the credential, and readies the device for contactless presentation. The result is a true one‑tap access experience that feels as natural as using a physical badge, while retaining the flexibility and control of an app‑based solution.

Beyond NFC: Lock Screen Widgets as a Unified Access Control Surface

While NFC HCE is a key enabler, lock screen widgets are not limited to NFC‑based credentials. The same widget concept can also be applied to BLE‑based credentials, simplifying the opening flow and enabling faster, more reliable access without requiring users to navigate through the app. This is particularly valuable in environments where BLE is already deployed or preferred for hands‑free or proximity‑based access scenarios. Beyond individual access technologies, lock screen widgets function as a unified trigger for access‑related workflows. Because the underlying logic resides within the mobile app, a single widget interaction can initiate coordinated actions across multiple systems rather than performing a single isolated operation.

Typical scenarios enabled through widgets include:

  • Instant door unlocking via NFC HCE or BLE

  • Passage or office modes that keep doors unlocked during defined schedules (e.g., 8am–5pm)

  • Unlocking a door while automatically disarming an intrusion system

  • Arming the intrusion system when leaving a secured area

  • Activating predefined “entry” or “exit” modes that coordinate access and security states

Up to four widgets can be placed on the lock screen simultaneously, transforming it into a compact but powerful control surface for daily security operations. Frequently used actions become instantly accessible, while complexity remains encapsulated within the app logic.

With a dedicated mobile app security solution, organizations retain full control over which capabilities appear on the lock screen and how they behave, without being constrained by wallet‑level limitations. This positions lock screen widgets as a flexible, app‑driven interface for modern mobile access and security experiences, independent of any single access technology.

Strategic Advantages Over Wallet‑Based Access

Unlike wallet‑based solutions, in‑app mobile credentials activated via widgets:

  • Do not require provisioning through Apple services

  • Do not require Apple integration or reader certification

  • Avoid recurring wallet licensing fees

Because the credential resides inside the organization’s own app, full control is retained over:

  • Credential lifecycle management

  • User experience design

  • Data usage and privacy

  • Feature updates and long‑term roadmap

From a hardware perspective, NFC HCE supports readers operating under the ISO 7816‑4 standard with only minor firmware‑level adjustments. If a reader already supports NFC HCE on Android, enabling it for iOS typically requires only a small update with no hardware replacement.

Regional Availability and Market Reality

It is important to note that NFC HCE on iOS is currently enabled within the European Economic Area (EEA). For many readers, particularly those based in the United States, this regional scope is a critical context point.

At the time of writing, global NFC HCE availability on iOS is not yet clearly regulated or formally communicated by Apple. Organizations planning international deployments should therefore carefully assess regional platform capabilities and consider hybrid strategies that combine NFC, BLE, and app‑driven workflows to ensure consistent user experiences across markets.

How It Works Without Changing the Security Model

Lock screen widgets streamline the initiation of the access process, but the underlying security architecture remains unchanged. Credentials continue to be protected by established app‑level security controls, cryptographic mechanisms, and policy enforcement.

What changes is usability: faster activation, fewer steps, and reduced friction at the point of entry, all while maintaining full control and security.

More details about this capability, including how it works in practice and a video showcase of the flow, are available in our recent article: â€śNFC HCE Evolved: Instant Access Through iOS Lock Screen Widgets”.


Late last year, YourSix launched its Peripherals offering as part of the YourSixOS platform.  The year prior, we introduced Access Control. Together, peripherals and barriers (such as  doors) enrich security operations within YourSixOS by providing additional sources of  evidentiary data. 

With the introduction of Adjacency Groups, this evidence can now be intelligently  correlated by defining adjacency—that is, specifying which security things (peripherals,  barriers and cameras) are installed in close physical proximity to one another. 

Adjacency Groups inform YourSix applications, including Matrix and Inspect, about which  security things are related by proximity. This enables the applications to automatically  assemble contextual, ad-hoc views of relevant evidence when an event is being  investigated. 

Consider a doorbell button connected to YourSixOS as a peripheral. When the button is  pressed and no one was available to answer, a local branch manager can in retrospect  locate the activation event in the YourSixOS event log. From that event, the manager can  directly access an adjacent camera to verify whether the visitor was a delivery person or  another individual, and call said person up. 

While the doorbell button workflow may be simple, it illustrates the significance of  correlation. Historically, security systems have operated as collections of siloed signals:  an access event in one interface, a camera feed in another, a sensor alert somewhere else,  leaving operators to manually piece together the narrative. Adjacency Groups remove that  friction. By explicitly defining physical relationships between peripherals, barriers and  cameras, YourSixOS shifts the burden of correlation from the human to the platform. 

Proximity becomes intelligence. 

When a door is forced, the nearest camera isn’t searched for; it’s already presented. When  a badge is denied, the surrounding context is assembled automatically. When a peripheral  is triggered, the system doesn’t just record the event; it understands which other security  things are likely relevant and brings them forward instantly.

This isn’t just about efficiency. It’s about clarity under pressure. It’s about reducing  cognitive load at the exact moment decisions must be made. It’s about transforming raw  events into coherent situational awareness. 

Adjacency Groups are a foundational step toward a broader vision: security systems that  don’t merely capture data, but understand relationships. By digitally modeling physical  proximity, we allow software to reason more like an experienced operator by anticipating  what evidence matters before someone has to ask. 

Because ultimately, the goal isn’t more data - it’s situational awareness through better  context. And in security operations, context is the difference between reacting to events and truly understanding them.


Have you ever seen something with an online retailer that sounded amazing, was on sale, and you just couldn’t
live without it? You ordered it, it showed up, and flopped miserably. Yeah, me neither.

The security industry is running full steam ahead to ISC West, or for this technology geek, it’s like a big kid candy store; maybe for you too as well. It's easy to get lost in the show and to fall victim to the Shiny Object (or Widget) Syndrome (SOS). I want to discuss this in a broad spectrum, and the pitfalls that companies that have bought shiny objects face.

Think of middle school band. Some of you remember that first day. For me, I was going to play trumpet. The director tells everyone to pull out that brand new instrument, maybe for the first time, even opening the case. A room filled with bright, shiny instruments. All tooled with care and precision to make the most joyful music. Some instruments are big, others small, some more expensive, some value lines, some owned, others rented. The director stands up on the podium, baton in hand, and tells everyone to play. The horror. Ears bleeding. These instruments that were designed to make beautiful music, screeching, barking, and just making noise. That is the outcome of SOS when the object is the wrong object.

I’m not saying that shiny objects are bad or wrong. I love new and emerging tech, maybe more than most. I see where it solves problems. But even I will have to be on my guard at ISC West not to be swept away by the shiny objects, because a room full of shiny objects just makes noise. When shiny objects are thrown into the mix without planning, they create roadblocks instead of optimization for the organization. They create chaos when the reason the shiny object was selected was to help bring order.

Something I say all the time. Maybe you’ve heard me say it, some probably too much. “The best technology in the world, for the wrong use case, is the wrong technology” – Jon Polly.

Steps to Remember
For those going to ISC West, or for those who are looking for new technologies, remember these steps to help prevent falling victim to Shiny Object Syndrome.

There are four underlying drivers for SOS, and if anything, we learned from GI Joe, knowing is half the battle.

#1 – Dopamine Hit: ISC West is held in Las Vegas every year. For the masses its 3-4 days of education, show walking, visiting with old friends, making new friends, countless happy hours and dinners, late nights and early mornings, and manufacturers willing to pay the tab. I’m a big kid in a candy store and can always use 3 more days of ISC West to see it all; and NO ONE needs an additional three more days of ISC West. All this to say, for these three or four days, the dopamine valve is left on at full blast. What is dopamine? It’s the neurotransmitter that releases a chemical into the brain when we experience reward or pleasure.

Something I say all the time. Maybe you’ve heard me say it, some probably too much. “The best technology in the world, for the wrong use case, is the wrong technology” – Jon Polly.

Steps to Remember
For those going to ISC West, or for those who are looking for new technologies, remember these steps to help prevent falling victim to Shiny Object Syndrome.

There are four underlying drivers for SOS, and if anything, we learned from GI Joe, knowing is half the battle.

#1 – Dopamine Hit: ISC West is held in Las Vegas every year. For the masses its 3-4 days of education, show walking, visiting with old friends, making new friends, countless happy hours and dinners, late nights and early mornings, and manufacturers willing to pay the tab. I’m a big kid in a candy store and can always use 3 more days of ISC West to see it all; and NO ONE needs an additional three more days of ISC West. All this to say, for these three or four days, the dopamine valve is left on at full blast. What is dopamine? It’s the neurotransmitter that releases a chemical into the brain when we experience reward or pleasure.

#2 Fear of Missing Out (FOMO): Product relseases, press releases, and carefully scripted sales teams. The message, "This is new, it's exciting, why don't you already have this implemented?" One concept of ISC West is to drive FOMO.

#3 – Lack of Planning: As I mentioned before, what is the goal of ISC West? What are you trying to solve for? For me, it really is every possible use case, but for most, it is solving for very specific use cases. Have those use cases identified, honed, and know what makes them successful. What Key Performance Indicators (KPIs) need to be met or outcomes created? In other words, have the musical score for your concert ready.

#4 – Emotional Decision Making: Most companies exhibiting at ISC West bring one engineering resource (maybe) to the 5, 10, 30 sales team members they bring to ISC West. You can dig into the technology, but their goal is to create an emotional response so that you will go back and write a PO on the Monday after the show. Don’t fault them, it’s business. Be smarter. Do the research. Start the conversation at ISC West, but avoid the impulse decision to purchase. Go back and make sure what they are selling solves your use case.

Have a blast at ISC West. I know I will. Please, come find me. Let’s connect. But go to wherever home is and take all the information and sales pitches, slow down, and see which technologies solve the use cases. Maybe a technology you saw that was amazing sits in a drawer for the next use case.


Podcast | Secured: Episode 5
In Episode 5 of Secured, Lee breaks down the diverging stories behind Dormakaba, Allegion, and ASSA ABLOY’s latest earnings, explores the rise of a “Visa layer” for access control through SwiftConnect and Aliro 1.0, and examines why ecosystem models like LEAF and AI agents are reshaping the intelligence layer. He also introduces the four buyer mindsets driving this transition, and where the real revenue is hiding. Listen now.


Podcast | Secured: Live from Intersec Dubai 2026: Ryan Kaltenbaugh (M.C. Dean)
Recorded live at Intersec Dubai, Ryan Kaltenbaugh, Head of Global Sales at M.C. Dean discusses how 2025 became a turning point, fueled by the Middle East’s rise and growing opportunities in large-scale security and critical infrastructure. Listen now.


Webinar | Designing The Future of Security
Most security failures don’t happen at install, they happen at design. Join the Secure Building Council and 4Liberty on March 5 for the first session in a 4-part webinar series on building smarter, safer security programs from the start. Register here.


Breaking News | PSA Network and The Access Control Collective release State of Security Integrators 2026 Report

The State of Security Integrators 2026 report, built from PSA’s Financial Metrics Survey and insights from 116 integrators, offers a rare, data-driven look at where the industry is growing, and where it still needs to evolve. Access the report here.

The PhySec Collective Breakfast is a community-first gathering bringing 300+ physical security operators, builders, and leaders together before ISC West, with proceeds benefiting FAST. Sponsored by Grid Squared Systems, YourSix, Sharlic, PDQ, PassiveBolt, Acre Security, Brivo, Connectivity Standards Alliance, HID, and SwiftConnect. Register here.


ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 7–8, and sign up here to be notified first when registration goes live.


 

 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 69
Volume 69 | July 24, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE DealTwo decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.Listen here ✍🏻 Ar...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.