Skip to content

Biometric access control

Biometric access control grants or refuses entry to a door, gate or turnstile using a physical trait such as a face or fingerprint instead of a card or PIN. The credential cannot be lent or lost, which is why it is chosen for areas where knowing who entered matters as much as controlling entry.

How do the common biometric credentials compare?

ModalityContact requiredThroughputTypical objection
FaceNoHigh, walk-throughPerceived as surveillance if not clearly scoped
FingerprintYesModerate, one at a timeHygiene, and failure on worn or damaged fingers
IrisNo, but close rangeModerate, requires positioningCost and the need for user cooperation
The three modalities most often deployed on doors, compared on the properties that decide a fit.

Face is chosen for throughput and because it works with the cameras a site often already has. The trade is that a face credential is captured at a distance and without contact, so the boundary between access control and surveillance has to be drawn by policy rather than by the hardware.

Where should biometric templates be stored?

  • On the credential: the template stays on a card or phone the holder carries, and the reader compares against it.
  • On the device: the reader or local controller holds the templates for the doors it serves.
  • On premises: a local server holds them for the site, which is what multi-door and multi-site policies usually require.
  • In a vendor cloud: templates leave the organisation entirely, which several regulators and most defence buyers rule out.

The storage decision is the privacy decision. Everything else about a deployment can be adjusted later; where the templates live determines who can be compelled to produce them, what a breach exposes and which jurisdictions the data has entered.

What must the fallback path cover?

Every biometric system rejects legitimate people sometimes, and some people cannot enrol at all. A deployment without a working fallback converts a routine false reject into someone locked out of their workplace, which is why the fallback is part of the design rather than an exception to it.

  1. Provide a second credential, such as a card or PIN, for anyone the biometric rejects or who cannot enrol.
  2. Define what happens during a power or network failure, including whether doors fail open or fail secure.
  3. Give staff a route to report repeated rejection, since a rising rate for one person usually means a poor enrolment rather than an impostor.
  4. Record fallback use, because a fallback that becomes the normal path is a system that is not working.

Frequently asked questions

What is biometric access control?
Biometric access control grants or refuses entry using a physical trait such as a face, fingerprint or iris instead of a card or PIN. Because the credential cannot be lent or lost, it is chosen where the record of who entered matters as much as controlling whether entry happened.
Is face or fingerprint better for door access?
Face suits high-throughput entrances because it works without contact and at walking pace; fingerprint suits low-traffic doors where a positive contact step is acceptable. The deciding factors are usually throughput, hygiene policy and whether existing cameras can be reused, rather than any accuracy comparison.
Where are biometric templates stored?
Depending on the design: on a card or phone the holder carries, on the reader or local controller, on a site server, or in a vendor cloud. The choice determines what a breach exposes and which jurisdictions the data enters, so it is a privacy decision more than a technical one.
What happens if the biometric system rejects an employee?
A fallback credential should let them in and the rejection should be logged. Repeated rejection of one person almost always indicates a poor enrolment image rather than an impostor, so the practical fix is re-enrolment, not a lower threshold for everyone.
Does biometric access control work during a network outage?
It does if matching happens on the reader or a local controller, which is why on-premise designs are common for doors. Systems that call a cloud service for every comparison stop admitting anyone during an outage, so the failure mode belongs in the requirements.
Do employees have to consent to biometric access control?
In many jurisdictions yes, and consent given as a condition of employment is scrutinised closely. Several biometric privacy statutes require written notice, a stated retention period and a deletion process, and a practical deployment offers a non-biometric alternative to anyone who declines.

Jan Mocary β€” Chief Technology Officer, Ayonix AI

Leads engineering for Ayonix face recognition and the ATLAS agent platform, including their on-premise and air-gapped deployment modes.