Access control

Biometric access control, on the terminals you already use for attendance

In most Indian workplaces the biometric terminal is already the lock — it sits on the door and decides who gets in. What is usually missing is control of that lock from anywhere except the device's own keypad. That gap is what turns a resignation processed on Friday into someone walking in on Monday.

A biometric access control system decides who can open which door, verified by fingerprint, face or card rather than a shareable key or code. AionHRMS runs access control on the same eSSL, ZKTeco and Realtime terminals that record attendance: lock or unlock any person from the browser and the instruction reaches every terminal at that site, release a door remotely when needed, and see denied entry attempts in the log. Because access and attendance are one system, granting someone entry and putting them on the register is a single action — and revoking a leaver is one click instead of a walk to every device.

One terminal

attendance and door control from the same device

Same-hour

lock a leaver from the browser; every site terminal obeys

Evidence

denied entry attempts recorded, not just successful ones

Remote release

open a door from the dashboard when the situation calls for it

Access and attendance are the same decision

Who may enter and who was present are two views of one fact. Running them as separate systems — an access panel from one vendor, attendance software from another — doubles the enrolment, doubles the leaver process, and guarantees the two disagree.

  • Enrol a person once: the same template verifies their entry and records their attendance
  • Fingerprint, face, RFID card or PIN — whichever methods each door's terminal supports
  • Every punch doubles as an access event, with terminal, time and method recorded
  • One register answers both questions: who came in, and who tried to

Joiners and leavers, as a security workflow

The leaver process is where access control earns its keep. A departed employee, a replaced vendor, a suspended contractor — each is a standing security exception until someone updates every door they could open.

  • Block a person from the dashboard; the instruction propagates to every terminal at the site
  • Unblock just as fast when a suspension lifts or a notice period changes
  • Attendance history is preserved on revocation — you are closing a door, not erasing a record
  • Temporary staff and vendors granted and revoked on the same basis as employees
  • With the API, your HR system can trigger the block itself the moment an exit is processed

Denied attempts are data

Most access systems only remember who got in. The attempts that failed — the ex-employee at the gate, the card tried at the wrong door — are the events a security review actually wants.

  • Failed verifications are recorded with time, terminal and method
  • A blocked person attempting entry is visible the same day, not discovered in an audit
  • Patterns across sites appear in one place, because every site is in one account

What this is, and what it is not

Access control is a wide term, and overclaiming it sells badly and installs worse. Precisely: AionHRMS does people-level access on attendance-class biometric terminals. It is the right shape for offices, plants, schools and multi-site businesses controlling staff entrances. It is not an enterprise physical-security suite.

  • In scope: person-level allow/block per site, remote door release, denied-attempt logging, multi-site control from one account
  • Works with the door locks these terminals drive — the terminal's relay releases the door
  • Not in scope: anti-passback, mantraps, elevator floor control, visitor-management kiosks, CCTV integration
  • If your requirement is an enterprise security platform, we will say so and step aside — and still handle your attendance

One system versus separate access and attendance

AionHRMS (one system)Separate access panel + attendance tool
EnrolmentOnce, for both entry and register.Twice, drifting apart from day one.
Leaver revocationOne click, every terminal at the site.Two systems, two processes, one usually missed.
Denied attemptsLogged alongside attendance, visible anywhere.In the panel's own log, if anyone looks.
Multi-siteEvery site's doors in one account.Per-site panels, per-site software.
CostIncluded — the attendance terminals do the work.A second system to buy, wire and maintain.

Frequently asked questions

Can a biometric attendance machine also control the door?
Most can — eSSL, ZKTeco and Realtime attendance terminals commonly include a lock relay that releases an electric strike or magnetic lock. If your terminal is wired to the door, AionHRMS controls who it opens for: allow and block per person from the browser, with a remote release for the door when needed.
How fast can we revoke a leaver's access?
The same hour their exit is processed. Block them from the dashboard and every terminal at the site receives the instruction — no visit to any device. With the partner API, your HR system can trigger the same block automatically as part of its exit workflow.
Does it support anti-passback or elevator control?
No. Those belong to enterprise physical-security platforms, and we would rather tell you that on the page than after a purchase order. What we do — person-level door access unified with attendance across sites — covers the staff entrances of most Indian workplaces.
What happens to access control when the internet is down?
The terminal keeps verifying and admitting enrolled people locally — the allow/deny list lives on the device. What waits for connectivity is new instructions (a fresh block or unblock) and the upload of buffered events; both apply automatically when the link returns.
Can we give a vendor's staff access for two weeks?
Yes — enrol them like anyone else, and block them the day the engagement ends. Their punches are recorded with method and terminal throughout, which is also the evidence that settles the vendor's invoice.

The terminal is already on the door. Take control of it.

Person-level access, same-hour revocation and a denied-attempts log — on the machines you already own.