{"id":79270,"date":"2026-09-15T13:26:31","date_gmt":"2026-09-15T16:26:31","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=79270"},"modified":"2026-09-15T18:25:01","modified_gmt":"2026-09-15T21:25:01","slug":"access-levels-profiles-security-zones-areas-permissions","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/access-levels-profiles-security-zones-areas-permissions\/","title":{"rendered":"Access Levels and Access Profiles: How to Define Zones, Areas and Permissions"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Access levels, access profiles, security zones and access permissions are complementary ways to transform the physical risk of a facility into objective authorization rules. In a well-designed system, the question is not simply whether a person \u201chas access,\u201d but <strong>to which areas, in which direction, under which conditions, with which credential, for what period and with which exceptions<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A coherent architecture begins with physical zoning and asset criticality. Public, controlled, restricted and critical areas should not receive the same treatment; each transition between zones creates a point at which identity, authentication and authorization must be evaluated. The access profile then groups permissions compatible with a role, relationship or operational need, avoiding individual door releases without a traceable logic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This approach is especially important in industrial plants, corporate buildings, hospitals, Data Centers, substations, logistics centers and public facilities. The larger the number of people, doors, floors, third parties and exceptions, the greater the risk that a permission policy will grow in a disorderly way. The design must transform the security policy into a verifiable, documented and testable structure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Access level, access profile, security zone and permission: what is the difference?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The terms often appear together, but they do not mean the same thing. Treating them as synonyms creates ambiguities that later reappear in software configuration, the functional matrix, acceptance testing and daily operations.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Concept<\/td><td>Question it answers<\/td><td>Application example<\/td><\/tr><tr><td><strong>Security zone<\/strong><\/td><td>What level of protection is required for a physical area?<\/td><td>reception, administrative area, laboratory, electrical room, data hall<\/td><\/tr><tr><td><strong>Restricted area<\/strong><\/td><td>Which environment requires specific authorization for entry?<\/td><td>server room, sensitive archive, vault room, critical storeroom<\/td><\/tr><tr><td><strong>Access level<\/strong><\/td><td>How far may a given group progress through the physical hierarchy?<\/td><td>general, restricted, critical access<\/td><\/tr><tr><td><strong>Access profile<\/strong><\/td><td>Which set of permissions will be assigned to a person or role?<\/td><td>electrical maintenance, operations, cleaning, escorted visitor<\/td><\/tr><tr><td><strong>Access permission<\/strong><\/td><td>Which concrete action is authorized?<\/td><td>enter through door P-023, use the elevator to the 8th floor, access the parking garage<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The zone describes the space and its criticality. The profile describes the rule assigned to the identity. The permission materializes that rule in access points, directions, floors, schedules or functions. The access level is a way to organize progression between areas, but it should not become an abstract classification disconnected from actual risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In small facilities, these concepts may seem excessive. In environments with dozens or hundreds of doors, however, they are what prevents authorization from being managed as a manual list of exceptions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The design should start with risk and assets, not the organization chart<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Zones and profiles should not originate from software parameterization. Access Control Design must transform risks, flows and assets into traceable permissions, avoiding excessive access and exceptions without governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Learn about our Access Control Design service<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A recurring mistake is to create profiles directly from company departments: \u201cFinance,\u201d \u201cIT,\u201d \u201cEngineering,\u201d \u201cMaintenance,\u201d and so on. The organization chart helps explain roles, but it does not replace the physical analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two people in the same department may have different access needs. One maintenance engineer may need to enter electrical rooms and technical areas while another, in an administrative role, may not. Likewise, professionals from different departments may share the same operational need, such as access to a loading dock or operations center.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The engineering process should follow a different logic:<\/p>\n\n\n\n<figure class=\"a3a-mermaid\"><svg id=\"a3a-diagram-1\" width=\"100%\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"flowchart\" style=\"max-width:min(1781.703125px, 100%);height:auto;display:block;margin:0 auto\" viewBox=\"0 0 1781.703125 68.5\" role=\"graphics-document document\" aria-roledescription=\"flowchart-v2\" aria-labelledby=\"chart-title-a3a-diagram-1\"><title id=\"chart-title-a3a-diagram-1\">From physical risk to verifiable access permissions<\/title><style>#a3a-diagram-1{font-family:Roboto,sans-serif;font-size:15px;fill:var(--a3a-diag-text, #0a0a0a);}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#a3a-diagram-1 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .error-icon{fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .error-text{fill:#000000;stroke:#000000;}#a3a-diagram-1 .edge-thickness-normal{stroke-width:1px;}#a3a-diagram-1 .edge-thickness-thick{stroke-width:3.5px;}#a3a-diagram-1 .edge-pattern-solid{stroke-dasharray:0;}#a3a-diagram-1 .edge-thickness-invisible{stroke-width:0;fill:none;}#a3a-diagram-1 .edge-pattern-dashed{stroke-dasharray:3;}#a3a-diagram-1 .edge-pattern-dotted{stroke-dasharray:2;}#a3a-diagram-1 .marker{fill:var(--a3a-diag-stroke, #2e42a2);stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .marker.cross{stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 svg{font-family:Roboto,sans-serif;font-size:15px;}#a3a-diagram-1 p{margin:0;}#a3a-diagram-1 .label{font-family:Roboto,sans-serif;color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .cluster-label text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span p{background-color:transparent;}#a3a-diagram-1 .label text,#a3a-diagram-1 span{fill:var(--a3a-diag-text, #0a0a0a);color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .node rect,#a3a-diagram-1 .node circle,#a3a-diagram-1 .node ellipse,#a3a-diagram-1 .node polygon,#a3a-diagram-1 .node path{fill:var(--a3a-diag-fill, #eef2fd);stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:1px;}#a3a-diagram-1 .rough-node .label text,#a3a-diagram-1 .node .label text,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-anchor:middle;}#a3a-diagram-1 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#a3a-diagram-1 .rough-node .label,#a3a-diagram-1 .node .label,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-align:center;}#a3a-diagram-1 .node.clickable{cursor:pointer;}#a3a-diagram-1 .root .anchor path{fill:var(--a3a-diag-stroke, #2e42a2)!important;stroke-width:0;stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .arrowheadPath{fill:var(--a3a-diag-stroke, #0b0b0b);}#a3a-diagram-1 .edgePath .path{stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:2.0px;}#a3a-diagram-1 .flowchart-link{stroke:var(--a3a-diag-stroke, #2e42a2);fill:none;}#a3a-diagram-1 .edgeLabel{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .edgeLabel p{background-color:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .edgeLabel rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .labelBkg{background-color:rgba(255, 255, 255, 0.5);}#a3a-diagram-1 .cluster rect{fill:var(--a3a-diag-surface, #f8f8f8);stroke:var(--a3a-diag-border, #e2e8f0);stroke-width:1px;}#a3a-diagram-1 .cluster text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:Roboto,sans-serif;font-size:12px;background:var(--a3a-diag-canvas, #ffffff);border:1px solid hsl(0, 0%, 90%);border-radius:2px;pointer-events:none;z-index:100;}#a3a-diagram-1 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 rect.text{fill:none;stroke-width:0;}#a3a-diagram-1 .icon-shape,#a3a-diagram-1 .image-shape{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .icon-shape p,#a3a-diagram-1 .image-shape p{background-color:var(--a3a-diag-canvas, #ffffff);padding:2px;}#a3a-diagram-1 .icon-shape rect,#a3a-diagram-1 .image-shape rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#a3a-diagram-1 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#a3a-diagram-1 :root{--mermaid-font-family:Roboto,sans-serif;}<\/style><g><marker id=\"a3a-diagram-1_flowchart-v2-pointEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 0 L 10 5 L 0 10 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-pointStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"4.5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 5 L 10 10 L 10 0 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"11\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"-1\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossEnd\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"12\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossStart\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"-1\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><g class=\"root\"><g class=\"clusters\"><\/g><g class=\"edgePaths\"><path d=\"M193.141,34.25L197.307,34.25C201.474,34.25,209.807,34.25,217.474,34.25C225.141,34.25,232.141,34.25,235.641,34.25L239.141,34.25\" id=\"L_A_B_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_A_B_0\" data-points=\"W3sieCI6MTkzLjE0MDYyNSwieSI6MzQuMjV9LHsieCI6MjE4LjE0MDYyNSwieSI6MzQuMjV9LHsieCI6MjQzLjE0MDYyNSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M418.609,34.25L422.776,34.25C426.943,34.25,435.276,34.25,442.943,34.25C450.609,34.25,457.609,34.25,461.109,34.25L464.609,34.25\" id=\"L_B_C_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_B_C_0\" data-points=\"W3sieCI6NDE4LjYwOTM3NSwieSI6MzQuMjV9LHsieCI6NDQzLjYwOTM3NSwieSI6MzQuMjV9LHsieCI6NDY4LjYwOTM3NSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M662.734,34.25L666.901,34.25C671.068,34.25,679.401,34.25,687.068,34.25C694.734,34.25,701.734,34.25,705.234,34.25L708.734,34.25\" id=\"L_C_D_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_D_0\" data-points=\"W3sieCI6NjYyLjczNDM3NSwieSI6MzQuMjV9LHsieCI6Njg3LjczNDM3NSwieSI6MzQuMjV9LHsieCI6NzEyLjczNDM3NSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M907.406,34.25L911.573,34.25C915.74,34.25,924.073,34.25,931.74,34.25C939.406,34.25,946.406,34.25,949.906,34.25L953.406,34.25\" id=\"L_D_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_D_E_0\" data-points=\"W3sieCI6OTA3LjQwNjI1LCJ5IjozNC4yNX0seyJ4Ijo5MzIuNDA2MjUsInkiOjM0LjI1fSx7IngiOjk1Ny40MDYyNSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M1126.188,34.25L1130.354,34.25C1134.521,34.25,1142.854,34.25,1150.521,34.25C1158.188,34.25,1165.188,34.25,1168.688,34.25L1172.188,34.25\" id=\"L_E_F_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_E_F_0\" data-points=\"W3sieCI6MTEyNi4xODc1LCJ5IjozNC4yNX0seyJ4IjoxMTUxLjE4NzUsInkiOjM0LjI1fSx7IngiOjExNzYuMTg3NSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M1313.313,34.25L1317.479,34.25C1321.646,34.25,1329.979,34.25,1337.646,34.25C1345.313,34.25,1352.313,34.25,1355.813,34.25L1359.313,34.25\" id=\"L_F_G_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_F_G_0\" data-points=\"W3sieCI6MTMxMy4zMTI1LCJ5IjozNC4yNX0seyJ4IjoxMzM4LjMxMjUsInkiOjM0LjI1fSx7IngiOjEzNjMuMzEyNSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M1533.016,34.25L1537.182,34.25C1541.349,34.25,1549.682,34.25,1557.349,34.25C1565.016,34.25,1572.016,34.25,1575.516,34.25L1579.016,34.25\" id=\"L_G_H_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_G_H_0\" data-points=\"W3sieCI6MTUzMy4wMTU2MjUsInkiOjM0LjI1fSx7IngiOjE1NTguMDE1NjI1LCJ5IjozNC4yNX0seyJ4IjoxNTgzLjAxNTYyNSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><\/g><g class=\"edgeLabels\"><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_A_B_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_B_C_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_C_D_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_D_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_E_F_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_F_G_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_G_H_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><\/g><g class=\"nodes\"><g class=\"node default\" id=\"flowchart-A-0\" transform=\"translate(100.5703125, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-92.5703125\" y=\"-26.25\" width=\"185.140625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-62.5703125, -11.25)\"><rect><\/rect><foreignObject width=\"125.140625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Assets and processes<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-B-1\" transform=\"translate(330.875, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-87.734375\" y=\"-26.25\" width=\"175.46875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-57.734375, -11.25)\"><rect><\/rect><foreignObject width=\"115.46875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Threats and risks<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-C-3\" transform=\"translate(565.671875, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-97.0625\" y=\"-26.25\" width=\"194.125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-67.0625, -11.25)\"><rect><\/rect><foreignObject width=\"134.125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Security zones<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-D-5\" transform=\"translate(810.0703125, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-97.3359375\" y=\"-26.25\" width=\"194.671875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-67.3359375, -11.25)\"><rect><\/rect><foreignObject width=\"134.671875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Transition points<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-E-7\" transform=\"translate(1041.796875, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-84.390625\" y=\"-26.25\" width=\"168.78125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-54.390625, -11.25)\"><rect><\/rect><foreignObject width=\"108.78125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Access profiles<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-F-9\" transform=\"translate(1244.75, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-68.5625\" y=\"-26.25\" width=\"137.125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-38.5625, -11.25)\"><rect><\/rect><foreignObject width=\"77.125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Permissions<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-G-11\" transform=\"translate(1448.1640625, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-84.8515625\" y=\"-26.25\" width=\"169.703125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-54.8515625, -11.25)\"><rect><\/rect><foreignObject width=\"109.703125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Functional matrix<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-H-13\" transform=\"translate(1678.359375, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-95.34375\" y=\"-26.25\" width=\"190.6875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-65.34375, -11.25)\"><rect><\/rect><foreignObject width=\"130.6875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Tests and evidence<\/p><\/span><\/div><\/foreignObject><\/g><\/g><\/g><\/g><\/g><\/svg><figcaption>From physical risk to verifiable access permissions<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">First, assets, critical processes, regulatory requirements and the consequences of unauthorized access are identified. Then the zones and their boundaries are defined. Only then does it make sense to decide which roles may cross each boundary and under which conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This sequence avoids two opposite problems: <strong>excessive access<\/strong>, when a profile grants more access than necessary, and <strong>excessive fragmentation<\/strong>, when each person receives an almost unique collection of doors that becomes impossible to govern.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to structure security zones and restricted areas<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Security zones are physical groupings with similar protection requirements. They may coincide with floors, departments, buildings or perimeters, but they do not need to follow the civil architecture literally. A single building may contain several zones, and one zone may cover physically separate rooms if the protection policy is equivalent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A practical taxonomy may use terms such as <strong>public<\/strong>, <strong>controlled<\/strong>, <strong>restricted<\/strong> and <strong>critical<\/strong>, provided the design makes clear that these names are a facility convention rather than a universal normative scale. What matters is the association among risk, requirements and controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A public area may allow circulation without credentials up to a defined point. A controlled area may require simple identification. A restricted area may require an individual credential and an authorization rule. A critical area may require multifactor authentication, anti-passback, dual custody, escorting, enhanced event supervision or other measures proportional to risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zoning must also consider transitions. Many failures occur not inside the critical area, but at the boundary between areas with different requirements. At this boundary, the design defines the reader, barrier, controlled direction, door sensor, authentication, emergency behavior and expected event.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Avoid zones that exist only in software<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A logical zone is useful only when it corresponds to a verifiable operational reality. If the software contains \u201cZone 4\u201d but no one knows which doors define it, which assets it protects or which entry rule applies, the classification has lost its engineering purpose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each zone should have, at minimum, a definition, a justification, its boundary points and the list of authorized profiles. In critical environments, it is also advisable to record authorization owners and periodic review criteria.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Restricted areas are not all the same<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The term <strong>restricted areas<\/strong> appears frequently in security policies, but it is broad. A telecommunications room, hospital pharmacy, records archive, laboratory and substation can all be \u201crestricted\u201d and still require different controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design must translate the restriction into requirements: who authorizes, who may enter, whether unescorted access is allowed, which authentication factors are required, whether there is a time limit, whether events require associated video, whether anti-passback applies, or whether entry depends on another operational state.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to create access profiles without losing governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An access profile is a package of permissions that can be assigned to people with similar needs. This abstraction reduces errors because it allows rules to be administered at the level of role, relationship or activity instead of configuring doors individually for each user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The model should follow the principle of <strong>physical least privilege<\/strong>: grant only the access required for the role and only for the necessary period. The objective is not restriction for its own sake, but to reduce the exposure surface and make every authorization justifiable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Useful profiles are often derived from combinations such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>operational role;<\/li><li>work location;<\/li><li>criticality of the required areas;<\/li><li>relationship \u2014 employee, contractor, visitor, supplier, auditor;<\/li><li>need for access outside standard hours;<\/li><li>need for unescorted access;<\/li><li>authorization for vehicles, loading docks, elevators or technical areas;<\/li><li>additional authentication requirements.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A generic \u201cmaintenance\u201d profile may be too broad. In a complex facility, there may be electrical, HVAC, telecommunications, civil and security maintenance, each with different needs. Granularity should be sufficient to represent risk without creating hundreds of nearly identical profiles.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Base profile and controlled exceptions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A sound operational practice is to separate the base profile from exceptions. A person receives what the role normally requires; extraordinary permissions are temporary, justified and, whenever possible, have automatic expiration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This reduces privilege accumulation: someone changes roles, receives new permissions and retains the old ones because they were never reviewed. In integrations with HR and IAM, job or organizational-unit changes should trigger profile reassessment, not simply add access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Role-based profiles do not eliminate approval<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Automating assignment based on job title or corporate group improves scale, but does not mean every mapping should be automatic. Critical areas may require a second approval, proof of training or authorization from the asset owner.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Engineering must define which permissions may be derived automatically from an identity source and which depend on a specific workflow.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Access permissions must be expressed in a verifiable way<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A permission should not be described merely as \u201caccess to the building.\u201d To be testable, it must specify <strong>where, in which direction, when and under which conditions<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At one door, the rule may define controlled entry and free egress. At another, both entry and exit may require a read to maintain occupancy state. At a turnstile, the profile may authorize a specific direction. In parking areas, authorization may depend on the relationship between vehicle and driver. In elevators, it may limit the available floors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A permission structure may combine:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Dimension<\/td><td>Examples<\/td><\/tr><tr><td>Identity<\/td><td>employee, contractor, visitor, emergency team<\/td><\/tr><tr><td>Location<\/td><td>building, zone, area, door, turnstile, floor<\/td><\/tr><tr><td>Direction<\/td><td>entry, exit, both<\/td><\/tr><tr><td>Time<\/td><td>days, shifts, windows, holidays, validity<\/td><\/tr><tr><td>Authentication<\/td><td>card, PIN, biometrics, two factors<\/td><\/tr><tr><td>State<\/td><td>valid anti-passback, current training, escort<\/td><\/tr><tr><td>Exception<\/td><td>scheduled maintenance, contingency, emergency<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This decomposition converts the security policy into rules that can be implemented and tested. It also simplifies investigation of a denied access event: the cause can be traced to area, schedule, factor, state or validity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Access levels should not be a simple scale from 1 to 5<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It is common to find facilities that classify users as \u201clevel 1,\u201d \u201clevel 2,\u201d \u201clevel 3,\u201d and so on. This strategy seems simple, but it can create dangerous interpretations if a higher number automatically means \u201caccess to everything below.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Physical reality is rarely perfectly hierarchical. Someone authorized to enter a highly critical laboratory does not necessarily need access to the treasury. An infrastructure technician may enter the data center and have no reason to access HR records.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Levels can therefore help communicate criticality, but permissions should be defined by need. The more robust model combines <strong>zone + role + condition<\/strong>, rather than using a universal privilege ladder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where a hierarchy exists, it must be explicitly documented. The software should not infer that a critical profile grants unrestricted access to every area of the facility unless this was an explicit design decision.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Zones, areas and anti-passback must share the same spatial model<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anti-passback and occupancy rules depend on knowing where the system considers a person to be located. If the zones used by the permission policy do not match the zones configured for occupancy, operational inconsistencies arise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A transition door between Zone A and Zone B may record the state change. If an exit is not read, if there is an alternative route, or if an emergency door bypasses the normal flow, the system can lose occupancy-state consistency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design must decide which areas truly require state tracking and which are only administrative groupings. Not every security zone needs to be an anti-passback zone, and not every occupancy rule requires hard anti-passback.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This decision should appear in the functional matrix and test plan. A spatial diagram or floor plan showing zone boundaries is also far more useful than trying to reconstruct the logic solely from software configuration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Schedules, calendars and validity are part of the permission<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Physical permission is not necessarily permanent. A profile may be valid only on business days, during a shift, within a maintenance window or for the duration of a contract.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Time must therefore be treated as a dimension of authorization. The same person may be authorized to enter a given area during business hours and require additional approval outside them. A contractor may have permission only until the service order ends. A visitor may have a window of only a few hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The system must manage these rules without turning temporary exceptions into permanent rights. Automatic expiration is an important control because it reduces dependence on later manual removal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Programming schedules, shifts, calendars and holidays deserves specific requirements, especially in 24&#215;7 facilities, because date changes, shift transitions, local holidays and offline operation can alter the authorization result.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Visitors, contractors and service providers require their own profiles<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Copying an employee profile to a contractor is a dangerous operational shortcut. External relationships have their own characteristics: sponsor, contract, validity, escort requirements, training, permitted areas and offboarding process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Visitors also should not inherit an excessively broad \u201cvisitor profile\u201d merely for convenience. The profile may depend on the host, meeting location, period and type of visit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The permission policy should anticipate these groups during design. Otherwise, operations will create improvised profiles after implementation, outside the original traceability.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Integration with HR, Active Directory and IAM changes the scale of governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In enterprise systems, identity may originate in HR, directories or IAM platforms. This allows part of the Joiner-Mover-Leaver life cycle \u2014 hiring, change and termination \u2014 to be automated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The integration, however, must clearly define the source of truth. HR may be responsible for the employment relationship; IAM may organize digital roles; the physical system remains responsible for applying permissions to zones and access points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The mapping between a corporate group and a physical-access profile must be versioned and auditable. A change in a directory group should not create access to a critical area unless that rule has been previously designed and approved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conflicts must also be addressed. If a person belongs to two groups, will the result be the union of permissions? Will there be an explicit deny rule? Can a temporary authorization expand the profile? Who reviews these combinations? These decisions are part of the architecture, not merely product configuration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to represent zones and profiles in the functional matrix<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">When the policy must relate profiles, zones, directions, schedules, APB, integrations and emergency behavior, the functional matrix is the link among requirement, configuration and testing. This documentation reduces ambiguity in procurement and acceptance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">See how A3A structures Access Control System Designs<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The functional matrix converts conceptual logic into a design requirement. Each access point should relate origin, destination, direction, readers, sensors, events and integrations. To govern access levels and profiles, the matrix can be complemented by an authorization matrix.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A simplified example:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Profile<\/td><td>Public zone<\/td><td>Controlled zone<\/td><td>Restricted zone<\/td><td>Critical zone<\/td><\/tr><tr><td>Visitor<\/td><td>allowed<\/td><td>escorted<\/td><td>no<\/td><td>no<\/td><\/tr><tr><td>Administrative<\/td><td>allowed<\/td><td>allowed<\/td><td>according to role<\/td><td>no<\/td><\/tr><tr><td>Technical maintenance<\/td><td>allowed<\/td><td>allowed<\/td><td>according to discipline<\/td><td>with authorization<\/td><\/tr><tr><td>Critical operations<\/td><td>allowed<\/td><td>allowed<\/td><td>allowed<\/td><td>according to role<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This table should not be interpreted as a universal model. It demonstrates the need to explicitly record the relationship between profiles and zones.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a real design, granularity may increase to buildings, floors, doors, schedules, factors and exceptions. What matters is that the rule remains traceable from requirement to acceptance testing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Emergency and life safety take precedence over normal policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A physical-security authorization must not be applied in a way that compromises egress, evacuation, firefighting or other life-safety requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The system must define how doors, turnstiles, interlocks and other controlled means behave in an emergency. The rule may involve release, local unlocking, interfaces with fire systems, emergency controls and specific operating modes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These conditions are not \u201cuser profiles.\u201d They are system states that may temporarily change the normal policy. They should therefore be addressed in the cause-and-effect matrix and verified during commissioning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Likewise, emergency teams may have specific authorizations, but this does not replace the safe behavior required from the facility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Periodic permission reviews prevent privilege accumulation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A well-designed architecture can lose quality over the years if no one reviews who still needs access to each area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Periodic reviews should examine profiles, exceptions, inactive users, terminated contractors, unused credentials and critical access. In higher-risk environments, the area owner may periodically recertify the list of authorized people.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST SP 800-53 control PE-2 is a useful reference for the logic of maintaining the list of authorized individuals, reviewing authorizations and removing access that is no longer required. The same publication also addresses authorization by position or role, a concept directly related to physical-access profiles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review frequency should be proportional to risk. An administrative area and a critical-asset room do not necessarily require the same recertification cycle.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Logs and audit records should explain why access was granted or denied<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Recording only \u201caccess denied\u201d is insufficient for mature operations. Whenever the platform allows it, it is useful to distinguish causes such as invalid credential, profile without permission, access outside the time window, anti-passback, missing factor, expired validity or an access point out of service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This level of evidence helps maintenance, security, audit and incident investigation. It also makes it possible to test whether the designed policy was implemented correctly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Record retention should consider purpose, internal requirements, investigation needs and data protection. There is no single universal retention period suitable for every facility; the design and governance model should justify the period and control who can access this information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to specify access levels and profiles without tying the design to a manufacturer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The requirement should describe <strong>behavior<\/strong>, not proprietary screen names or features. Instead of requiring a specific menu, the specification may require the system to support user groups, access profiles, zones, calendars, exceptions, expiration and audit trails under defined criteria.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It should also require capacity compatible with the scale: number of profiles, users, areas, points, time-based rules and events. Licensing limits must be understood because an architecture that works technically may become impractical if every essential capability requires modules that were not anticipated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For multi-site environments, the specification should define whether profiles are global, local or hybrid. A corporate role may have common permissions across several sites and specific exceptions at each location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Performance-based specification preserves competition and keeps the focus on what engineering must demonstrate during acceptance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAT, SAT and commissioning must test the policy \u2014 not only the reader<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Testing whether a reader recognizes a card does not prove that access control is correct. Commissioning must verify the permission logic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Test cases should include, for example:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>authorized profile in the correct zone and schedule;<\/li><li>the same profile attempting to access an unauthorized zone;<\/li><li>valid credential outside the permitted schedule;<\/li><li>user with temporary authorization before and after expiration;<\/li><li>profile change after a role change;<\/li><li>termination and revocation;<\/li><li>offline controller operation;<\/li><li>authorized exception and subsequent removal;<\/li><li>emergency event;<\/li><li>log records and correlation with the functional matrix.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The test must produce evidence. This keeps requirement, configuration and acceptance linked, and the access policy no longer depends on the interpretation of whoever operated the software at that moment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Common errors when defining access levels and permissions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The first error is to create a \u201cmaster\u201d profile for operational convenience and distribute it widely. The second is to use the organizational chart as the sole reference. The third is to add exceptions without expiration. The fourth is to fail to review permissions after role changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also common are zones without clear boundaries, profile names that do not explain the rule, duplication of nearly identical profiles, permissions granted directly to users without justification, and configurations that appear in no design documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another problem is confusing complexity with security. Creating dozens of levels and hundreds of profiles does not improve the system if no one can administer them. Quality lies in representing risk with the lowest complexity compatible with operations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to procure an access control design with a traceable permission policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Procurement should require engineering to convert surveys, risks, flows, areas and roles into verifiable deliverables. Point layouts, diagrams, design criteria, the functional matrix, authorization matrix, software requirements, interfaces and the test plan should tell the same story.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before implementation, the owner should be able to answer: which zones exist, which areas are restricted, which profiles were defined, who approves each profile, which permissions each one receives, how exceptions work, and how everything will be tested.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When these answers emerge only during integrator configuration, the design has transferred engineering decisions to the wrong phase. This increases rework, manufacturer dependence and difficulty in technical oversight.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Access levels, access profiles, security zones, access permissions and restricted areas are parts of the same physical-authorization model. The central point is to convert risk and operational need into clear, minimal, auditable and testable rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most robust architecture is not the one with the greatest number of levels, but the one that can explain why each person may enter each area, for how long and under which conditions. When this logic originates in the design and reaches the matrix, configuration and commissioning, the system stops being a collection of doors and begins to operate as an engineering discipline.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Acceptance must prove the complete authorization logic. Engineering defines positive, negative and contingency cases to confirm that implemented access levels, profiles and permissions correspond to the design.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Request an Access Control System Design<\/a><\/p>\n<\/div>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Technical references<\/summary>\n<p class=\"wp-block-paragraph\">[1] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60839-11-1:2013 \u2014 Alarm and electronic security systems \u2014 Part 11-1: Electronic access control systems \u2014 System and components requirements. 2013. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/3662\">https:\/\/webstore.iec.ch\/en\/publication\/3662<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60839-11-2:2014 \u2014 Alarm and electronic security systems \u2014 Part 11-2: Electronic access control systems \u2014 Application guidelines. 2014. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/3663\">https:\/\/webstore.iec.ch\/en\/publication\/3663<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. NIST SP 800-53 Rev. 5 \u2014 Security and Privacy Controls for Information Systems and Organizations. 2020. Available at: <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/final\">https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/final<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. Electronic Physical Access Control Systems \u2014 Security Control Overlay of SP 800-53 Revision 5. 2021. Available at: <a href=\"https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/risk-management\/documents\/overlayRepo\/Electronic%20Physical%20Access%20Control%20Systems\/ePACS%20Overlay_v1_SP800-53rev5-April2021.pdf\">https:\/\/csrc.nist.gov\/CSRC\/media\/Projects\/risk-management\/documents\/overlayRepo\/Electronic%20Physical%20Access%20Control%20Systems\/ePACS%20Overlay_v1_SP800-53rev5-April2021.pdf<\/a>.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Frequently asked questions<\/summary>\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-qual-a-diferen-a-entre-n-vel-de-acesso-e-perfil--50ca5cc8\"><strong class=\"schema-faq-question\">What is the difference between an access level and an access profile?<\/strong> <p class=\"schema-faq-answer\">An access level is a way to organize criticality or progression among areas; an access profile is the concrete set of permissions assigned to a role, relationship or need. In mature designs, the profile should be derived from actual zones and needs, not merely from a numerical scale.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-s-o-zonas-de-seguran-a-no-controle-de-aces-5d49a472\"><strong class=\"schema-faq-question\">What are security zones in access control?<\/strong> <p class=\"schema-faq-answer\">They are groupings of physical areas with similar protection requirements. The design defines their boundaries, protected assets, transition points and which profiles may access them. Terms such as public, controlled, restricted and critical may be used as a convention, provided they are clearly defined.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-definir-permiss-es-de-acesso-559c7d0a\"><strong class=\"schema-faq-question\">How should access permissions be defined?<\/strong> <p class=\"schema-faq-answer\">A permission should specify who may access which point or area, in which direction, during which period, with which authentication factors and under which conditions. The more verifiable the rule, the easier it is to implement, audit and test.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-uma-rea-restrita-b58b9c59\"><strong class=\"schema-faq-question\">What is a restricted area?<\/strong> <p class=\"schema-faq-answer\">It is an area whose entry depends on specific authorization. The restriction should be translated into authentication, profile, validity, supervision, escort and record requirements compatible with the area&#8217;s risk.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-correto-criar-perfis-de-acesso-apenas-por-depart-9ec1bd3d\"><strong class=\"schema-faq-question\">Is it correct to create access profiles only by department?<\/strong> <p class=\"schema-faq-answer\">Not as a general rule. Department can be an attribute, but people in the same organizational area may require different physical access. The profile should represent role, location, risk, relationship and operational need.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-perfis-de-acesso-podem-vir-automaticamente-do-rh-d02830d4\"><strong class=\"schema-faq-question\">Can access profiles come automatically from HR or Active Directory?<\/strong> <p class=\"schema-faq-answer\">Yes, provided the mapping between corporate identity and physical permission is designed, approved and auditable. Critical areas may require additional approvals even when identity and job data are received automatically.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-testar-n-veis-e-perfis-de-acesso-no-comissi-9b4df5cd\"><strong class=\"schema-faq-question\">How should access levels and profiles be tested during commissioning?<\/strong> <p class=\"schema-faq-answer\">SAT should include authorized and denied cases, schedules, expiration, profile changes, revocation, offline operation, exceptions and emergency behavior. The objective is to prove the complete policy, not merely reader operation.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-qual-servi-o-deve-definir-zonas-perfis-e-permiss-3672d450\"><strong class=\"schema-faq-question\">Which engineering service should define zones, profiles and permissions for a system?<\/strong> <p class=\"schema-faq-answer\">These decisions should be part of the Access Control System Design because they depend on risks, flows, architecture, integration, documentation and acceptance criteria. Software configuration should implement previously defined requirements rather than replace the design.<\/p><\/div><\/div>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Complementary technical materials<\/summary>\n<h4 class=\"wp-block-heading\">Related services<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Access Control System Design<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-sistema-integrado-de-seguranca-eletronica\/\">Integrated Electronic Security Design: CCTV, access control, intrusion and integration<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning: planning, testing, readiness and handover<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Key content on this topic<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-controle-de-acesso\/\">Access Control Systems: types, technologies, standards and design<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/matriz-funcional-controle-de-acesso-como-especificar-cada-ponto\/\">Access control functional matrix: how to specify each point<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Related technical content<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/integracao-rh-active-directory-iam-identidade-fisica\/\">Integration among access control, HR, Active Directory and IAM<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/ciclo-vida-credenciais-controle-acesso-emissao-revogacao-expiracao\/\">Credential life cycle in access control<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/anti-passback-controle-de-acesso-soft-hard-global-temporizado\/\">Anti-passback in access control<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/terceiros-prestadores-contratados-acesso-fisico\/\">Physical access control for contractors and service providers<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/comissionamento-controle-de-acesso-iec-60839\/\">Commissioning access control systems according to IEC 60839<\/a><\/li><\/ul>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>How to define access levels, access profiles, security zones, restricted areas and permissions in physical access control systems.<\/p>\n","protected":false},"author":1,"featured_media":80109,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"65c68b73-91e7-4774-ab5e-032a63a15f2e","_a3a_i18n_canonical_slug":"access-levels-profiles-security-zones-areas-permissions","_a3a_prod_post_id":"","_a3a_lang_url_en-us":"","_a3a_lang_url_es-es":""},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-79270","articles","type-articles","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/79270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/79270\/revisions"}],"predecessor-version":[{"id":79271,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/79270\/revisions\/79271"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media\/80109"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=79270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=79270"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=79270"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=79270"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=79270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}