Add or edit an access credential¶
Select Add New in Access Credentials, or open an existing credential's action menu and select Edit.
Credential identity¶
Choose Credential Type and, for non-mobile credentials, a Card Format. Enter a positive numeric Credential Number. A format-and-number combination must be unique among active site credentials.
Mobile credentials do not use a card format and consume the site's mobile-credential license allowance. The portal prevents creation when no licenses remain. On an existing credential, card format and number are locked; the Mobile credential type is also locked.
Add a range¶
For a new record, select Add Range to replace the single number with Start of Range and End of Range. The start must be a positive integer and the end cannot be below the start. Mobile ranges are checked against the remaining license count.
Range creation runs in a background thread and attempts each number independently. Refresh and verify the complete expected range afterward; a duplicate or processing failure can leave fewer credentials than requested.
Validity and access¶
Set Valid From and optional Valid To. The editor converts these values between local date/time and UTC using the selected site's configured time zone.
Assign at least one access group. Access is the intersection of credential state, date range, maximum-use limit, and the reader or access-point schedules reachable through those groups.
Removing an access group can require deleting the credential from controllers that no longer have a path for it. TEKControl displays a confirmation before that controller-removal work. Continue only when access should be removed from the affected controllers.
Associate the credential¶
You can associate the credential with:
- a host and optional host vehicle;
- a vendor and optional vendor employee or vehicle;
- an alternate text description.
A host and vendor cannot both be selected. Selecting a host or vendor loads its related records. When a concrete host, vendor, vehicle, or employee is assigned, any prior visitor association is cleared.
Secondary Verification Number, Max Use Count, and Notes are optional numeric or descriptive controls used by supported workflows. Numeric fields must contain valid numbers when supplied.
Save, deliver, and print¶
Saving writes the credential and its access-group associations, records history, marks it as not yet pushed, and invokes integration delivery. A portal success message does not guarantee controller application; inspect the configuration queue.
Save and Print Badge appears only when the selected host type has a badge template and the user can modify credentials. Printing occurs after the save attempt.
Creating a credential with the format and number of a deleted record can restore that record. A mobile credential cannot restore a deleted non-mobile credential with the same identity.
Delete¶
Delete first attempts to send credential removal to the controller integration. The portal record is deleted only when that send routine reports success. If deletion fails, review controller availability and the queue before trying again; do not create a second credential to work around the failure.