Properties worry about credentials being cloned and rarely worry about the drawer of recovered bands behind reception. The second is the larger exposure, and the cheaper one to fix.

On this page
  1. What the technology can and cannot do
  2. The exposures that actually occur
  3. What a closure controls, and what it does not
  4. Keys, and how they should be handled
  5. Proportion

What the technology can and cannot do

A credential that only presents an identifier can be read by anyone with a reader, and a system that trusts that number trusts anyone who can reproduce it. A credential that authenticates — proving itself to the reader and requiring the reader to prove itself in return — is a different security model rather than a stronger version of the same one.

Which model a property has is a property of the installation, not of the wristband. It is worth knowing, because it determines whether the physical credential is a key or merely a label.

An operator testing several RFID wristband constructions at an encoding station
MATERIAL + USE / REAL CONSTRUCTION

The exposures that actually occur

Recovered credentials that are never disabled. Staff credentials still enabled after somebody has left. A guest handing a band to a friend at an exit. Reissue stock that anyone behind the desk can reach. And an estate with no numbering, so no question about a specific credential can be answered.

None of those is exotic and all of them are procedural. They are also the exposures that a physical product cannot fix on its own.

The five controls worth having:

  • A route for recovered credentials, with a named person who reconciles them
  • Same-day disabling on a staff departure, with a deputy when that person is away
  • A one-way closure wherever transfer is the loss being controlled
  • Reissue stock held under the same control as cash or master keys
  • Numbering and range labelling, so a question can be contained

What a closure controls, and what it does not

A one-way closure proves the credential has not been unfastened. It does not prove who is wearing it, and it does not stop a guest handing over a cut band if nobody checks the closure.

Physical control and staff procedure work together or not at all, which is why tamper evidence has to be recognisable in two seconds — a control sample at the gate does more than a briefing.

The drawer test

Ask where credentials found by housekeeping go, and who disables them. If the answer is a drawer and nobody, that is the property’s largest credential exposure and it costs nothing to close.

Physical cutaway showing a sealed RFID transponder inside a woven carrier
PRODUCTION + CONTROL / REAL PROCESS

Keys, and how they should be handled

Where a system uses authenticated credentials, the keys belong to the property or its integrator and are handled under that party’s process. Most orders do not require them at all, and nothing about a quotation or a technical review does.

A supplier casual about key handling is telling you how they handle everyone else’s, which is a useful thing to learn early.

Proportion

A locker at a beach club and a guest room have different consequences, and specifying both to the same standard wastes money on one and under-protects the other.

The useful question is what a credential opens and what it would cost if the wrong person held it. That answer sets the technology, the closure and the procedure together, rather than each being decided separately.

Compatibility rule

Compatibility is confirmed against the property’s lock system, credential technology and encoding requirements before production. We do not claim universal compatibility.

Questions this raises

01Should we worry about credentials being cloned?+

Less than about the recovered credentials in a drawer behind reception and the staff credentials still enabled after somebody left. Those are the exposures that actually occur, and they are procedural rather than technical.

02Does a one-way closure make a credential secure?+

It proves the band has not been unfastened, which controls transfer. It does not prove who is wearing it, and it does nothing if nobody checks the closure. Physical control and staff procedure only work together.

03How secure does a locker credential need to be?+

Not as secure as a guest-room credential. Specifying both to the same standard overspends on one and under-protects the other. Ask what the credential opens and what it would cost if the wrong person held it.