Skip to main content

On-Premise Access Control

Overview

Sign In App now integrates with on-premise access control providers directly from Portal 2.0, letting admins provision and manage physical access credentials for visitors without leaving Sign In App. This guide walks through setup and day-to-day use with Paxton, however the same workflow applies to our other supported providers in the list below.

Supported on-premise providers

  • Paxton

  • Genetec

  • Lenel OnGuard

  • C-Cure 9000

Prerequisites

  • An on-premise access control server (Paxton, Genetec, Lenel OnGuard, or C-Cure 9000), with the server URL, username, and password available for configuration.

  • Admin access to Portal 2.0.


Set up your provider

Step 1: Navigate to On premise access control

Go to Manage > On-Premise Access Control.

This is the landing page for any servers you've set up, plus the option to add a new provider. Supported providers listed here: Genetec, OnGuard (Lenel), C-Cure 9000, and Paxton.

Select your provider, enter the server name and server URL and then click Next.

Follow the process to set up a new site. You will need to enter your chosen server name and URL, along with the Username and Password for a user of your chosen access control server with sufficient permissions to manage credentials. This is typically the admin of the account, but if you are unsure please check with your IT dept.

Step 2: Review your Paxton server's Provider Details

Open your configured Paxton server to see the Settings tab: server name, URL, username, and password — the credentials used to connect Paxton to Sign In App.


​From the Settings tab you will also see your Connected sites and be able to set your Preferences for Tap to sign in/out:

Two additional tabs sit alongside Settings: Access Rules and Credentials.

Step 3: Configure Access Rules

Go to the Access Rules tab. This defines which access rules admins can hand out when provisioning credentials — pulled directly from Paxton, so the list reflects whatever rules are defined on your Paxton server (e.g., All Hours, All Doors, Working Hours, or more granular options like specific floors or entrances).

Click on a users name to assign whichever rules are appropriate for the admin/user provisioning credentials. You can also select Add user to add additional users to the list and configure their access rules.

Step 4: Set up Credentials

Go to the Credentials tab and create the credentials you want available to assign to visitors. These are the specific credential records that get associated with a visitor in the Paxton server, combined with the access rules from Step 3 to determine what they can actually access.

Firstly, select Add credentials:

You can then give the credential a name, select the type, and enter the UUID number:

Once your credentials are created, they can then be provisioned to a visitor. This form can also be reached automatically during provisioning if a scanned badge isn't recognised.


Provision a credential during sign-in

From the Activity page, select New Visit and then expand the Access Control Credential option in the sign-in flow. From here you can:

  • Select the credential to assign from the drop down list (or scan to assign)

  • Set the access level (e.g., All Hours, All Doors)

  • Set an expiry date/time (Please note that this will default to 24 hours, but it is fully configurable if you need to change this). Credentials will return themselves automatically at the specified expiry date/time.

Tip: Credentials are scoped to the site. Only unassigned credentials belonging to a connection linked to that visit's site appear in the picker. If you cannot see a credential you created, connected sites is the first thing to check.

Complete sign-in as normal — the credential is now assigned to that visitor.

Scan to assign

Using a USB RFID reader connected to your portal device, an admin can also scan a physical badge during sign in instead of picking from the list.

It reads the badge's card number (and facility code), then either auto-fills/assigns an existing matching credential, or - if the scanned badge is not recognised - you will be taken straight into the 'Add Credential' form with the card number and facility code pre-filled.


Provision a credential to an already-signed-in visitor

If a visitor is signed in without a credential and one is needed afterward, click to open their visit record. The same credential/access level options appear in a modal where you can select the credential from the drop down list (or scan to assign). access level, and set an expiry date/time before clicking Save.

Please Note: The visitor must have an email address. A credential cannot be assigned until the visit has one. Without it, the panel will show a warning instead of the fields.

Scan to assign

Using a USB RFID reader connected to your portal device, an admin can also scan a physical badge for an already signed in visitor instead of picking from the list.

It reads the badge's card number (and facility code), then either auto-fills/assigns an existing matching credential, or - if the scanned badge is not recognised - you will be taken straight into the 'Add Credential' form with the card number and facility code pre-filled.


Return (de-provision) a credential

From the visit record, you can also return an assigned credential, which de-provisions it. Click on a visit record to open the modal, and then under Access credentials click to Return access credential:

Once returned, the credential becomes available again to assign to a new visitor.

Tip: Credentials automatically return themselves at expiry. When the expiry date and time is reached, Sign In App automatically un-assigns the credential and it becomes available again.


Tap to sign in/out

In addition to provisioning access control credentials from Sign In App, you can also use an existing access control credential to automatically sign someone in.

When an employee taps their access control card on a configured door reader, Sign In App will automatically create a sign-in record for them — no manual check-in required. Tapping a configured sign-out reader on the way out will sign them out the same way. This bridges physical entry/exit events with your visitor and employee records, so on-site presence in Sign In App stays accurate without extra steps.

To configure this, head to Manage > On-Premise Access Control > Select your provider > Settings.

Under Preferences, tick Tap to sign in and out and then select your chosen reader from each drop-down list:

Please Note: Tap to sign in/out is currently only available for Paxton, but we will soon be rolling this out to Lenel OnGuard, Genetec, and C-Cure 9000.


On the access control server side

Provisioned visitors and their credentials/access rules appear directly on your access control server (which door(s) they can access and when). This guide covers the Sign In App side only.



Provider-specific configuration notes

Allowing multiple credentials per person (Lenel OnGuard & C-Cure 9000)

OnGuard and C-CURE 9000 limit how many credentials one person can hold at a time. If that limit is one, a visitor who already has a QR credential cannot also be given a physical credential. The assignment is refused and Sign In App shows a message asking you to return the existing credential first. To allow both, raise the limit on your access control server.

Lenel OnGuard & C-Cure 9000

To allow the same person to hold more than one active credential (for example, an Invite QR credential and a physical credential), Lenel OnGuard and C-Cure 9000 must be configured to permit multiple active badges per cardholder.

  • Location: System Administration → Administration → Cardholder Options → General Cardholder Options tab

  • Field: Maximum active badges per cardholder

  • Behaviour: a value greater than 1 permits multiple active badges per cardholder. A value of 1 restricts each cardholder to a single active badge.

Did this answer your question?