{"id":75343,"date":"2026-09-12T16:16:51","date_gmt":"2026-09-12T19:16:51","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=75343"},"modified":"2026-09-12T16:17:17","modified_gmt":"2026-09-12T19:17:17","slug":"people-entry-exit-control-schedules-shifts-access-profiles","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/people-entry-exit-control-schedules-shifts-access-profiles\/","title":{"rendered":"People Entry and Exit Control: Schedules, Shifts, and Access Profiles"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In physical security, people entry and exit control is the application of rules that determine <strong>who may enter or leave an area, through which point, at what time, and under what conditions<\/strong>. The objective is to govern access authorizations for buildings, industrial plants, restricted areas, floors, turnstiles, reception points, and other physical access points \u2014 not to replace the time-and-attendance system used to record working hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a people access control system, schedules, shifts, calendars, holidays, validity dates, and time profiles are part of the authorization. The same credential may be valid for a door during working hours, denied outside the specified window, and enabled again for a previously approved special shift. This behavior must be designed, documented, and tested; it should not arise from improvised adjustments made directly in the software during operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Engineering should treat time as one dimension of permission, alongside identity, area, direction, and authentication method. This makes it possible to control the entry and exit of employees, contractors, visitors, and maintenance teams under different rules, avoiding both unnecessary permanent permissions and restrictions that disrupt operations.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">People Entry and Exit Control Is Not the Same as Time and Attendance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The terms may appear similar because both involve people and schedules, but they solve different problems. <strong>Entry and exit control<\/strong>, in physical security, determines whether passage will be authorized; <strong>time and attendance<\/strong> records working hours for labor and administrative purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A turnstile event may be used by another system as an additional source of information, but that does not automatically turn the security system into a time clock. Emergency exits, tailgating, operator-released access, communication failures, open doors, and alternative routes may make physical access records unsuitable for representing working hours unless a specific architecture and rule set has been designed for that purpose.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Aspect<\/td><td>Physical access control<\/td><td>Time and attendance<\/td><\/tr><tr><td>Objective<\/td><td>authorize or deny physical passage<\/td><td>record working hours and attendance events<\/td><\/tr><tr><td>Primary unit<\/td><td>person + access point + access rule<\/td><td>person + attendance event<\/td><\/tr><tr><td>Use of time<\/td><td>authorization condition<\/td><td>composition of working hours<\/td><\/tr><tr><td>Events<\/td><td>access granted, denied, door open, APB<\/td><td>clock-in, clock-out, breaks, and other labor records<\/td><\/tr><tr><td>Exceptions<\/td><td>emergency, contingency, escort, operator<\/td><td>labor rules and attendance adjustments<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction matters for SEO and for engineering: someone searching for <strong>employee time control<\/strong> may be looking for electronic timekeeping, while someone searching for <strong>people entry and exit control<\/strong> may be looking for physical security. This article addresses only the second intent and explains how schedules become part of the access policy.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Time Must Be Treated as Part of Physical Permission<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Schedules and shifts should originate in the design as physical authorization rules. Defining them in advance reduces manual exceptions, unnecessary 24&#215;7 access, and conflicts between security and operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Learn about Access Control System Design<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A complete permission can be represented as a combination of identity, space, time, and condition. It is not enough to say that \u201cthe employee may access the laboratory.\u201d The requirement must state whether that access is valid 24&#215;7, only on business days, during a shift, within a maintenance window, or until a specified date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One way to structure the logic is:<\/p>\n\n\n\n<figure class=\"a3a-mermaid\"><svg id=\"a3a-diagram-1\" width=\"100%\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"flowchart\" style=\"max-width:min(898.484375px, 100%);height:auto;display:block;margin:0 auto\" viewBox=\"0 0 898.484375 376\" role=\"graphics-document document\" aria-roledescription=\"flowchart-v2\" aria-labelledby=\"chart-title-a3a-diagram-1\"><title id=\"chart-title-a3a-diagram-1\">Formation of a Time-Based Physical Access Rule<\/title><style>#a3a-diagram-1{font-family:Roboto,sans-serif;font-size:15px;fill:var(--a3a-diag-text, #0a0a0a);}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#a3a-diagram-1 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .error-icon{fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .error-text{fill:#000000;stroke:#000000;}#a3a-diagram-1 .edge-thickness-normal{stroke-width:1px;}#a3a-diagram-1 .edge-thickness-thick{stroke-width:3.5px;}#a3a-diagram-1 .edge-pattern-solid{stroke-dasharray:0;}#a3a-diagram-1 .edge-thickness-invisible{stroke-width:0;fill:none;}#a3a-diagram-1 .edge-pattern-dashed{stroke-dasharray:3;}#a3a-diagram-1 .edge-pattern-dotted{stroke-dasharray:2;}#a3a-diagram-1 .marker{fill:var(--a3a-diag-stroke, #2e42a2);stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .marker.cross{stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 svg{font-family:Roboto,sans-serif;font-size:15px;}#a3a-diagram-1 p{margin:0;}#a3a-diagram-1 .label{font-family:Roboto,sans-serif;color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .cluster-label text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span p{background-color:transparent;}#a3a-diagram-1 .label text,#a3a-diagram-1 span{fill:var(--a3a-diag-text, #0a0a0a);color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .node rect,#a3a-diagram-1 .node circle,#a3a-diagram-1 .node ellipse,#a3a-diagram-1 .node polygon,#a3a-diagram-1 .node path{fill:var(--a3a-diag-fill, #eef2fd);stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:1px;}#a3a-diagram-1 .rough-node .label text,#a3a-diagram-1 .node .label text,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-anchor:middle;}#a3a-diagram-1 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#a3a-diagram-1 .rough-node .label,#a3a-diagram-1 .node .label,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-align:center;}#a3a-diagram-1 .node.clickable{cursor:pointer;}#a3a-diagram-1 .root .anchor path{fill:var(--a3a-diag-stroke, #2e42a2)!important;stroke-width:0;stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .arrowheadPath{fill:var(--a3a-diag-stroke, #0b0b0b);}#a3a-diagram-1 .edgePath .path{stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:2.0px;}#a3a-diagram-1 .flowchart-link{stroke:var(--a3a-diag-stroke, #2e42a2);fill:none;}#a3a-diagram-1 .edgeLabel{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .edgeLabel p{background-color:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .edgeLabel rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .labelBkg{background-color:rgba(255, 255, 255, 0.5);}#a3a-diagram-1 .cluster rect{fill:var(--a3a-diag-surface, #f8f8f8);stroke:var(--a3a-diag-border, #e2e8f0);stroke-width:1px;}#a3a-diagram-1 .cluster text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:Roboto,sans-serif;font-size:12px;background:var(--a3a-diag-canvas, #ffffff);border:1px solid hsl(0, 0%, 90%);border-radius:2px;pointer-events:none;z-index:100;}#a3a-diagram-1 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 rect.text{fill:none;stroke-width:0;}#a3a-diagram-1 .icon-shape,#a3a-diagram-1 .image-shape{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .icon-shape p,#a3a-diagram-1 .image-shape p{background-color:var(--a3a-diag-canvas, #ffffff);padding:2px;}#a3a-diagram-1 .icon-shape rect,#a3a-diagram-1 .image-shape rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#a3a-diagram-1 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#a3a-diagram-1 :root{--mermaid-font-family:Roboto,sans-serif;}<\/style><g><marker id=\"a3a-diagram-1_flowchart-v2-pointEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 0 L 10 5 L 0 10 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-pointStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"4.5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 5 L 10 10 L 10 0 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"11\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"-1\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossEnd\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"12\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossStart\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"-1\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><g class=\"root\"><g class=\"clusters\"><\/g><g class=\"edgePaths\"><path d=\"M209.227,34.25L214.327,34.25C219.427,34.25,229.628,34.25,249.487,54.957C269.346,75.664,298.864,117.078,313.624,137.786L328.383,158.493\" id=\"L_A_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_A_E_0\" data-points=\"W3sieCI6MjA5LjIyNjU2MjUsInkiOjM0LjI1fSx7IngiOjIzOS44MjgxMjUsInkiOjM0LjI1fSx7IngiOjMzMC43MDQyNjgyOTI2ODI5LCJ5IjoxNjEuNzV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M189.406,136.75L197.81,136.75C206.214,136.75,223.021,136.75,239.73,140.634C256.439,144.518,273.05,152.287,281.356,156.171L289.661,160.055\" id=\"L_B_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_B_E_0\" data-points=\"W3sieCI6MTg5LjQwNjI1LCJ5IjoxMzYuNzV9LHsieCI6MjM5LjgyODEyNSwieSI6MTM2Ljc1fSx7IngiOjI5My4yODQ2Nzk4NzgwNDg4LCJ5IjoxNjEuNzV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M211.18,239.25L215.954,239.25C220.729,239.25,230.279,239.25,243.359,235.366C256.439,231.482,273.05,223.713,281.356,219.829L289.661,215.945\" id=\"L_C_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_E_0\" data-points=\"W3sieCI6MjExLjE3OTY4NzUsInkiOjIzOS4yNX0seyJ4IjoyMzkuODI4MTI1LCJ5IjoyMzkuMjV9LHsieCI6MjkzLjI4NDY3OTg3ODA0ODgsInkiOjIxNC4yNX1d\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M214.828,341.75L218.995,341.75C223.161,341.75,231.495,341.75,250.421,321.043C269.346,300.336,298.864,258.922,313.624,238.214L328.383,217.507\" id=\"L_D_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_D_E_0\" data-points=\"W3sieCI6MjE0LjgyODEyNSwieSI6MzQxLjc1fSx7IngiOjIzOS44MjgxMjUsInkiOjM0MS43NX0seyJ4IjozMzAuNzA0MjY4MjkyNjgyOSwieSI6MjE0LjI1fV0=\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M434,188L438.167,188C442.333,188,450.667,188,458.333,188C466,188,473,188,476.5,188L480,188\" id=\"L_E_F_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_E_F_0\" data-points=\"W3sieCI6NDM0LCJ5IjoxODh9LHsieCI6NDU5LCJ5IjoxODh9LHsieCI6NDg0LCJ5IjoxODh9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M669.453,188L673.62,188C677.786,188,686.12,188,693.786,188C701.453,188,708.453,188,711.953,188L715.453,188\" id=\"L_F_G_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_F_G_0\" data-points=\"W3sieCI6NjY5LjQ1MzEyNSwieSI6MTg4fSx7IngiOjY5NC40NTMxMjUsInkiOjE4OH0seyJ4Ijo3MTkuNDUzMTI1LCJ5IjoxODh9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><\/g><g class=\"edgeLabels\"><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_A_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_B_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_C_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_D_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_E_F_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_F_G_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><\/g><g class=\"nodes\"><g class=\"node default\" id=\"flowchart-A-0\" transform=\"translate(111.4140625, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-97.8125\" y=\"-26.25\" width=\"195.625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-67.8125, -11.25)\"><rect><\/rect><foreignObject width=\"135.625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Identity or profile<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-E-1\" transform=\"translate(349.4140625, 188)\"><rect class=\"basic label-container\" style=\"\" x=\"-84.5859375\" y=\"-26.25\" width=\"169.171875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-54.5859375, -11.25)\"><rect><\/rect><foreignObject width=\"109.171875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Access rule<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-B-2\" transform=\"translate(111.4140625, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-77.9921875\" y=\"-26.25\" width=\"155.984375\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-47.9921875, -11.25)\"><rect><\/rect><foreignObject width=\"95.984375\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Area or point<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-C-4\" transform=\"translate(111.4140625, 239.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-99.765625\" y=\"-26.25\" width=\"199.53125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-69.765625, -11.25)\"><rect><\/rect><foreignObject width=\"139.53125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Schedule and calendar<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-D-6\" transform=\"translate(111.4140625, 341.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-103.4140625\" y=\"-26.25\" width=\"206.828125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-73.4140625, -11.25)\"><rect><\/rect><foreignObject width=\"146.828125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Conditions and exceptions<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-F-9\" transform=\"translate(576.7265625, 188)\"><rect class=\"basic label-container\" style=\"\" x=\"-92.7265625\" y=\"-26.25\" width=\"185.453125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-62.7265625, -11.25)\"><rect><\/rect><foreignObject width=\"125.453125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Authorize or deny<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-G-11\" transform=\"translate(804.96875, 188)\"><rect class=\"basic label-container\" style=\"\" x=\"-85.515625\" y=\"-26.25\" width=\"171.03125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-55.515625, -11.25)\"><rect><\/rect><foreignObject width=\"111.03125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Log event<\/p><\/span><\/div><\/foreignObject><\/g><\/g><\/g><\/g><\/g><\/svg><figcaption>Formation of a Time-Based Physical Access Rule<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This logic reduces dependence on permanent authorizations. An external technician may receive access for three days; a shift team may use certain doors only during its schedule; a supplier may enter a loading dock within a previously scheduled window; a visitor may have validity limited to the duration of the visit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The challenge is to build rules that are precise enough to control risk and simple enough to remain manageable.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Time Profiles and Access Profiles Must Be Related<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An access profile primarily answers <strong>where<\/strong> and <strong>what<\/strong> a person may access. A time profile answers <strong>when<\/strong> those permissions are active. Some platforms combine both into a single entity; others keep calendars and time schedules separate. The design should not depend on the terminology used by a manufacturer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The requirement should express the expected behavior. For example:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>shift A operators may access the production area between 05:30 and 14:30;<\/li><li>maintenance personnel may access technical areas during normal hours and, when authorized, during an exceptional window;<\/li><li>administrative staff are not authorized to enter operational areas outside normal working hours;<\/li><li>contractors receive validity aligned with the work order;<\/li><li>visitors receive an access window consistent with the appointment and host.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When a time profile is shared by multiple groups, changes must be controlled. Changing a global calendar to solve one specific case can unintentionally authorize dozens or hundreds of people.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Avoid Profile Proliferation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Creating a unique profile for every combination of door and schedule makes operations unsustainable. The design should modularize rules: area profiles, calendars, exceptions, and assignments can be combined under governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The architecture must balance reuse and clarity. Profiles that are too generic grant excessive privilege; profiles that are too specific create duplication and increase maintenance errors.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Shifts Require Explicit Handling of Day Rollover<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">24&#215;7 environments introduce situations that do not occur in a conventional office. A shift may begin at 22:00 and end at 06:00 the next day. If the platform or configuration handles only time ranges within the same day, the rule may behave differently at midnight.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design must test:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>shift start;<\/li><li>access during overnight hours;<\/li><li>date rollover;<\/li><li>end of the access window;<\/li><li>shift change;<\/li><li>planned overlap between teams;<\/li><li>overtime and exceptional extensions.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">It must also define which clock is authoritative. Controllers may operate offline and keep a local clock; servers may use NTP; geographically distributed sites may be in different time zones. A time-based policy is reliable only when the time base itself is reliable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Calendars, Holidays, and Special Days Must Be Part of the Design<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Configuring \u201cMonday through Friday\u201d is not enough. National, state, and municipal holidays, plant shutdowns, collective vacations, maintenance days, and special operations may change the policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An access calendar must define how special days override the normal rule. If December 25 is marked as a holiday, will the standard profile be denied? Do operations teams remain authorized? Does scheduled maintenance use an exception? Who approves the change?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without this definition, two poor responses are common: authorizing everyone \u201cso operations are not blocked\u201d or making manual adjustments on the eve of each holiday. Engineering should define the default behavior and the exception process in advance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Corporate Calendars and Local Calendars<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In multi-site systems, a single calendar may not serve every location. Municipal holidays vary; plants may use different work schedules; logistics centers may operate on weekends while offices remain closed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The system must support local rules without losing central governance. The specification should state whether calendars are global, site-specific, group-specific, or combinable.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Employee Entry and Exit Control by Profile and Need<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The expression <strong>employee entry and exit control<\/strong> is often associated with working hours, but in physical security it also refers to managing who may move through each point of a facility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Employment status alone should not imply unrestricted access. Employees receive permissions compatible with their role, assignment, risk, and schedule. Changes in position, transfers, and termination must modify or revoke those permissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An employee on the night shift may have a different access set from someone in the same role on the day shift, especially when certain areas are closed or operate in a reduced mode. Likewise, on-call and emergency teams may require specific profiles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Integration with HR can automate assignment and employment information, but the physical access logic remains the responsibility of the access policy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Employee Access Outside Normal Hours Requires an Exception Policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Exceptional access is inevitable: corrective maintenance, inventory, incidents, audits, and operational demands may require presence outside the normal window.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The mature solution is not to turn the profile into 24&#215;7 access. The system should allow temporary exceptions, preferably with:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>an identified requester;<\/li><li>a responsible approver;<\/li><li>reason;<\/li><li>authorized area;<\/li><li>start and end;<\/li><li>automatic expiration;<\/li><li>change logging;<\/li><li>subsequent review when necessary.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This approach preserves the normal profile and reduces privilege accumulation. It also distinguishes a deliberate authorization from an informal change made directly in the configuration.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Contractors and Service Providers Need Validity Aligned With the Engagement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For third parties, the time component is even more relevant. Permission may depend on the validity of a contract, work order, training, safety induction, or authorization from the responsible manager.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the work order ends on Friday, the credential should not remain valid indefinitely. The validity of the identity and permissions should follow the shortest applicable period among the relevant requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For recurring work, authorization may need to be recertified periodically. This is safer than granting permanent access to a record that no longer represents an active need.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Visitors and Temporary Access Require Short, Traceable Windows<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">People access control includes visitors, but the workflow differs from that used for employees. Authorization may be linked to a host, appointment, location, period, and purpose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A QR Code, mobile credential, temporary card, or biometric identification may be used as the authentication method, but the security of the rule depends on validity. A temporary credential that remains active after the visit ends is no longer temporary in practice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The access window should accommodate delays and operational tolerances without becoming excessive. There should also be a process for canceling the visit before expiration when necessary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Critical Areas May Require Additional Time Restrictions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not every authorization needs a schedule. In some areas, a person may be authorized at any time. In others, criticality justifies additional controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An electrical room, laboratory, data hall, treasury, or process area may require access only during a maintenance window, only while a team is present, or under dual custody. These conditions should be associated with the profile and operational state, not treated as an informal reminder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The time-based design should be proportional to risk. Overly restrictive rules that generate excessive denials may encourage operators to seek workarounds, while rules that are too permissive reduce the value of the control.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Schedules and Anti-Passback Interact With Presence State<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anti-passback controls entry and exit sequences. Schedules control when a credential may initiate a given passage. When both functions coexist, the design must define priorities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine a person who entered at 21:00 within the valid window and attempts to leave at 06:05, five minutes after the profile has ended. Should exit be denied? In many applications, blocking exit would be inappropriate and may conflict with life-safety requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The system should distinguish ingress policies from egress conditions. A time-based entry authorization should not be mechanically applied to an exit route without specific analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is also necessary to define what happens to presence state during resets, failures, or calendar changes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Emergency Operation Cannot Depend on the Normal Calendar<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Schedule rules are part of property security; they cannot compromise evacuation or other life-safety functions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In an emergency, doors, turnstiles, interlocks, and elevators may assume states defined by specific systems and standards. Access control must interact with those states according to the cause-and-effect matrix.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A calendar cannot keep an exit door locked when safe behavior requires release. Likewise, an exceptional authorization for an emergency response team does not replace the emergency mechanisms defined for the facility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tests must include transition from normal mode to emergency mode and return to normal conditions.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Offline Operation: Who Decides the Schedule When the Server Is Unavailable<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">In 24&#215;7 environments, engineering must coordinate calendars, shift rollover, offline operation, time synchronization, and emergency behavior. Configuration should only implement rules that have already been defined.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">See how A3A designs access control systems<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Modern controllers normally retain part of the rule set locally so that they can continue operating without communication with the server. Under these conditions, the local clock, stored calendars, and permission version become critical.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The specification must answer:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>which rules remain valid offline;<\/li><li>how long the controller operates autonomously;<\/li><li>how date and time are synchronized;<\/li><li>what happens if the clock drifts;<\/li><li>how events are stored and forwarded afterward;<\/li><li>how urgent authorization changes are handled during a network outage.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A distributed architecture may continue authorizing legitimate access during a failure, but it may also retain permissions that have already been revoked until synchronization returns. The risk must be understood.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Time Synchronization Is a Security and Evidence Requirement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Access events are used for investigation, audit, and correlation with video surveillance. If the controller, VMS, server, and identity system have different times, reconstructing a sequence can be difficult.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The infrastructure should provide time synchronization, drift monitoring, and time-zone handling. In distributed environments, an event may be displayed in local time while internal storage follows another standard; operations personnel must understand this behavior.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Official time changes and manual adjustments must also be controlled. Operators should not correct equipment clocks without a record and without assessing the impact on logs and calendars.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">HR and IAM Integration Automates the Cycle, Not the Engineering Decision<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">HR may provide hiring, termination, assignment, role, and shift information. IAM may provide corporate groups and attributes. The access control system can use this data to assign profiles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The integration must distinguish the <strong>identity source<\/strong> from the <strong>physical authorization source<\/strong>. An HR system may indicate that a person changed shifts, but the access control design defines which doors and areas correspond to that shift.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Joiner-Mover-Leaver flow should trigger the creation, modification, and removal of permissions. In the case of a change, the system should avoid simply adding new rights on top of the old ones.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Logs Must Record Schedule-Based Denials and Calendar Changes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An access-denied event should, when technically possible, indicate the cause. \u201cOutside permitted hours\u201d is far more useful than \u201cdenied\u201d for support and investigation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to passage events, the platform should maintain an audit trail of administrative changes: who modified a calendar, which rule changed, when the change took effect, and, where applicable, the justification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This history helps distinguish a technical failure from a policy change. It also supports audits and commissioning processes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Document Schedules and Shifts in the Functional Matrix<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The functional matrix does not need to list every minute of every calendar, but it should establish the logic. It can relate the access point, profile, direction, calendar, out-of-hours behavior, event, and exceptions.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Field<\/td><td>Example requirement<\/td><\/tr><tr><td>Profile<\/td><td>Shift A operations<\/td><\/tr><tr><td>Area<\/td><td>Production \u2013 Zone 2<\/td><\/tr><tr><td>Direction<\/td><td>controlled entry \/ exit according to design<\/td><\/tr><tr><td>Calendar<\/td><td>shift A + operating days<\/td><\/tr><tr><td>Outside window<\/td><td>deny entry and log event<\/td><\/tr><tr><td>Exception<\/td><td>approved temporary authorization<\/td><\/tr><tr><td>Offline<\/td><td>retain local rule for the defined capability<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Calendar details can be delivered in a supplementary table. What matters is that the final configuration can be compared against the approved document.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">How to Specify Entry and Exit Control Without Locking to a Manufacturer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The specification should require functional capabilities: calendars, holidays, shifts, time profiles, validity periods, exceptions, logs, synchronization, and offline operation. It should not reproduce menu names from a specific software product.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Scale limits are also important: number of calendars, rules, users, controllers, and sites. Some products have constraints that become visible only after procurement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Engineering should require relevant administrative changes to be auditable and the system to support positive and negative test cases before acceptance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAT, SAT, and Commissioning Must Test Time Boundaries<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The best tests are not performed only in the middle of the valid window. The transitions themselves must be tested:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>one minute before the start;<\/li><li>at the beginning of the window;<\/li><li>during the valid period;<\/li><li>at the end;<\/li><li>immediately afterward;<\/li><li>at day rollover;<\/li><li>on a holiday;<\/li><li>during a temporary exception;<\/li><li>after the exception expires;<\/li><li>with the controller offline.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Profile changes, termination, and restoration of communication should also be tested. Logs must show why each attempt was granted or denied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This evidence set turns the time policy into a verifiable requirement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Procure an Access Control Design Oriented to Real Operations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Procurement should assess people journeys, shifts, exceptional access, visitors, contractors, critical areas, 24&#215;7 operation, and contingencies before the final architecture is defined.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The deliverable should not be only a floor plan with readers. It is necessary to document the rules that make those readers take decisions: profiles, levels, calendars, schedules, exceptions, integrations, and test criteria.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When \u201cschedule\u201d is left for final configuration, the design loses traceability and operations tend to accumulate exceptions. When it is addressed from the beginning, the facility can control people entry and exit without turning the access-control software into a collection of manual adjustments.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Final Considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">People entry and exit control is a physical-security function. Schedules, shifts, calendars, holidays, temporary access, and time profiles are mechanisms used to activate or limit permissions at specific times.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A sound design separates this function from time and attendance, relates time rules to access zones and profiles, provides governed exceptions, protects offline operation, preserves life safety, and creates evidence for audit and acceptance. The result is a time-based access policy that can be understood, implemented, and tested as engineering.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">FAT and SAT should test the exact time boundaries, including expected denials and exceptions. This turns schedules and calendars into verifiable engineering requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Request an Access Control Design<\/a><\/p>\n<\/div>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Technical references<\/summary>\n<p class=\"wp-block-paragraph\">[1] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60839-11-1:2013 \u2014 Alarm and electronic security systems \u2014 Part 11-1: Electronic access control systems \u2014 System and components requirements. 2013. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/3662\">https:\/\/webstore.iec.ch\/en\/publication\/3662<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60839-11-2:2014 \u2014 Alarm and electronic security systems \u2014 Part 11-2: Electronic access control systems \u2014 Application guidelines. 2014. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/3663\">https:\/\/webstore.iec.ch\/en\/publication\/3663<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. NIST SP 800-53 Rev. 5 \u2014 Security and Privacy Controls for Information Systems and Organizations. 2020. Available at: <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/final\">https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/final<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. Electronic Physical Access Control Systems \u2014 Security Control Overlay of SP 800-53 Revision 5. 2021. Available at: <a href=\"https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/risk-management\/documents\/overlayRepo\/Electronic%20Physical%20Access%20Control%20Systems\/ePACS%20Overlay_v1_SP800-53rev5-April2021.pdf\">https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/risk-management\/documents\/overlayRepo\/Electronic%20Physical%20Access%20Control%20Systems\/ePACS%20Overlay_v1_SP800-53rev5-April2021.pdf<\/a>.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Frequently asked questions<\/summary>\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-controle-de-entrada-e-sa-da-a-mesma-coisa-que-co-79b8a847\"><strong class=\"schema-faq-question\">Is entry and exit control the same as time and attendance?<\/strong> <p class=\"schema-faq-answer\">No. In physical security, entry and exit control authorizes or denies passage through physical access points according to identity, area, schedule, and other conditions. Time and attendance records working hours for labor and administrative purposes.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-um-perfil-de-hor-rio-no-controle-de-acesso-1d396d23\"><strong class=\"schema-faq-question\">What is a time profile in access control?<\/strong> <p class=\"schema-faq-answer\">It is a time-based rule that determines when specific physical permissions are active. It may include days of the week, time ranges, shifts, holidays, and exceptions.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-controlar-acesso-de-funcion-rios-por-turno-c1bbdf05\"><strong class=\"schema-faq-question\">How do you control employee access by shift?<\/strong> <p class=\"schema-faq-answer\">The access profile should be associated with the shift calendar, considering start, end, day rollover, overlap between teams, and exceptions. The rule must be documented and tested at the time boundaries.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-tratar-acesso-fora-do-hor-rio-normal-4f4bc612\"><strong class=\"schema-faq-question\">How should access outside normal hours be handled?<\/strong> <p class=\"schema-faq-answer\">The preferred approach is a temporary authorization with start, end, permitted areas, approver, and automatic expiration, rather than turning the normal profile into 24&#215;7 access.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-feriados-devem-ser-configurados-no-controle-de-a-36522001\"><strong class=\"schema-faq-question\">Should holidays be configured in the access control system?<\/strong> <p class=\"schema-faq-answer\">Yes, when authorization changes on special days. The design should define corporate and local calendars, rule priority, and which groups remain authorized.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-acontece-com-os-hor-rios-se-a-controladora-6430ae5d\"><strong class=\"schema-faq-question\">What happens to schedules if the controller loses communication?<\/strong> <p class=\"schema-faq-answer\">It depends on the architecture. The specification should define which calendars and permissions remain stored locally, how the clock is synchronized, and how events and revocations are handled during offline operation.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-visitantes-podem-ter-acesso-tempor-rio-97c92fb5\"><strong class=\"schema-faq-question\">Can visitors have temporary access?<\/strong> <p class=\"schema-faq-answer\">Yes. The credential may have a validity window aligned with the appointment, host, and authorized areas, with cancellation and automatic expiration.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-testar-hor-rios-no-comissionamento-48e942d0\"><strong class=\"schema-faq-question\">How should schedules be tested during commissioning?<\/strong> <p class=\"schema-faq-answer\">Tests should cover moments before, during, and after the window, day rollover, holidays, exceptions, expiration, and offline operation. The log must demonstrate the cause of grants and denials.<\/p><\/div><\/div>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Supplementary technical materials<\/summary>\n<h4 class=\"wp-block-heading\">Related services<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Access Control System Design<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-sistema-integrado-de-seguranca-eletronica\/\">Integrated Electronic Security Design: Video Surveillance, Access, Intrusion, and Integration<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning: Planning, Testing, Readiness, and Handover<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Main content on the topic<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-controle-de-acesso\/\">Access Control System: Types, Technologies, Standards, and Design<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/niveis-perfis-acesso-zonas-areas-permissoes\/\">Access Levels and Access Profiles: How to Define Zones, Areas, and Permissions<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Related technical content<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/ciclo-vida-credenciais-controle-acesso-emissao-revogacao-expiracao\/\">Credential Lifecycle in Access Control<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/integracao-rh-active-directory-iam-identidade-fisica\/\">Integration Between Access Control, HR, Active Directory, and IAM<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/terceiros-prestadores-contratados-acesso-fisico\/\">Access Control for Contractors and Service Providers<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/gestao-visitantes-controle-de-acesso\/\">Visitor Management Integrated With Access Control<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/anti-passback-controle-de-acesso-soft-hard-global-temporizado\/\">Anti-Passback in Access Control<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/comissionamento-controle-de-acesso-iec-60839\/\">Access Control System Commissioning According to IEC 60839<\/a><\/li><\/ul>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>People entry and exit control with schedules, shifts, calendars, holidays, time profiles, and physical access control design criteria.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"3cdd6cb7-9ca6-4e60-9c98-7bcccc7f0c7d","_a3a_i18n_canonical_slug":"people-entry-exit-control-schedules-shifts-access-profiles","_a3a_lang_url_en-us":"","_a3a_lang_url_es-es":""},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-75343","articles","type-articles","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/75343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/75343\/revisions"}],"predecessor-version":[{"id":75344,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/75343\/revisions\/75344"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=75343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=75343"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=75343"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=75343"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=75343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}