Access credentials¶
Select Access Credential under Physical Access Control Settings. The grid is the site's operational credential inventory and shows credential number, format, association, valid and expiration dates, credential type, access groups, maximum-use count, active status, and last read.
Search and filter¶
The primary search supports:
- Credential Number, with optional From and To values for a range;
- Association, for the linked person, organization, vehicle, employee, or alternate association.
Advanced filters include:
- valid-date or expiration-date range;
- last used before, or Never Used;
- card format and credential type;
- credential status;
- deleted-record visibility;
- one or more access groups, or No Access Group Assigned.
Never Used and Last Used Before are mutually exclusive. Access Group selection and No Access Group Assigned are also mutually exclusive. Select Apply after changing popover filters; Reset clears the advanced filters. Primary search updates automatically.
Deleted credentials are excluded by default. Include them when investigating a number that appears to be in use or when confirming whether a later creation restored an old record.
Review a credential¶
Open a row's action menu to edit or view credential history. The history records credential lifecycle and material field changes; general entity audit information can provide additional record-level evidence.
Before changing a credential, confirm:
- the site and card format;
- the associated host, vendor, vehicle, or employee;
- validity and expiration in the site's time zone;
- active and deleted state;
- every assigned access group and its controller coverage;
- whether the latest controller command succeeded.
See Add or edit a credential for individual changes.
Select credentials for a bulk action¶
The grid supports multi-selection, including an effective select-all selection. The Selected counter shows the set that the bulk operation will use. Recheck the filters and count immediately before opening Bulk Actions.
Many bulk actions run in the background. The initial success notification means processing started, not that every credential was updated or every controller accepted the command. Refresh the grid when processing finishes and inspect Configuration queue.
See Imports and bulk actions for controller requirements and operation-specific behavior.
Credential state versus controller state¶
| Portal state | Meaning |
|---|---|
| Active | The credential is enabled in TEKControl; date, access-group, use-count, and controller rules can still deny access. |
| Inactive | TEKControl should not authorize the credential; controller removal or update must still be delivered. |
| Deleted | The record is logically deleted and normally excluded from the grid. Its number can be restored under defined conditions. |
| Pushed/queued | Delivery was attempted or queued; review the command result rather than relying on the flag alone. |
Always test the resulting behavior at an affected opening when the change is security-sensitive.