Skip to content

Access groups

An access group defines where and when an assigned credential can be used. Select Access Group under Physical Access Control Settings, then choose Add New Access Group or an existing group.

Every access group requires a name, System Type, external ID, and at least one valid association for the supported controller types. Description and Default Access are optional.

External IDs

Azure and VertX groups use an available external ID selected from 1 through 500. Other types use a manually entered value. The value maps this portal record to the controller's access-group identity; do not renumber it without planning a controller resynchronization.

Choose associations for the system type

The editor changes association controls by System Type:

System type Supported association
VertX Reader Group + Schedule.
Azure One or more Readers + Schedule, or Access Point/Strike + Schedule.
DSX Legacy Reader Group + Schedule and modern Reader or Access Point/Strike + Schedule. At least one mode is required.
AllBox One or more Readers + Schedule.

For a legacy association, choose a reader group and schedule, then select Add Reader Group / Schedule. For a modern association, select readers or an access point, choose the strike mapping when available, select a schedule, and select Add Association.

Rows are staged in the editor. Use Remove or Undo before saving. The schedule action in a saved row opens the schedule details so you can verify its windows without leaving the access-group editor.

Save and controller-removal impact

Saving makes the displayed association set authoritative. TEKControl compares the old and pending controller coverage. If removing an association would remove assigned credentials from one or more controllers, it displays the affected credential count and asks for confirmation.

Warning

The access group's core fields are saved before this controller-removal confirmation is shown. Canceling the confirmation prevents the association replacement, but a name, description, type, external ID, or Default Access change may already be stored. Reopen the group and verify it after canceling.

If confirmed, TEKControl queues credential removals for controllers that lost coverage, deletes the old association rows, and recreates the rows shown in the editor. A failure during this multi-step process can leave a partially updated record; reopen the group and inspect the configuration queue.

Synchronize access groups

Sync with Controllers appears only for active VertX controllers that have syncable reader-group and schedule associations. Choose the controller and select Sync Now. The operation sends the access-group collection relevant to that controller.

Azure, DSX, and AllBox delivery follows their integration-specific configuration and credential flow rather than this VertX sync action.

Delete an access group

Delete permanently removes the group and its controller mappings. Credentials assigned to the group can lose access. Before deletion:

  1. Identify assigned credentials.
  2. Assign and deliver a replacement group where needed.
  3. Verify the replacement at the controller.
  4. Remove the old assignment and review queued removals.
  5. Delete only after the old group is no longer required.