Scope and methodology. This guide is for organizations evaluating physical access control in Israel. It uses a requirements-first review of doors, users, permission workflows, offline operation, integrations, privacy and total cost. It is not a paid ranking and does not assume one architecture fits every site.
Security and privacy principles were checked against primary guidance from NIST, ISO and the Israel Privacy Protection Authority. This guide is not legal advice or a certification of any vendor.
Buyer Decision Summary
| Primary requirement | Direction to evaluate | Evidence to request |
|---|---|---|
| Central management across sites | Cloud-managed or hybrid | Site-level roles, central audit export and documented offline behavior |
| Operation during internet loss | Local controller or hybrid | Locally retained permissions, event buffering and resynchronization process |
| Employee biometrics | Necessity and proportionality review before reader selection | Purpose, lawful basis/consent, non-biometric alternative, security, retention and deletion |
| Reuse of installed hardware | Compatibility-led upgrade | Supported model list, site survey and a pilot on a representative door |
| Sensitive or changing permissions | Role-based, least-privilege administration | Approval flow, periodic review, prompt offboarding and exportable logs |
1. Types of Access Control Systems
- Legacy on-premise — server in the building, manual updates, hard to manage across sites
- Modern cloud platforms — managed remotely, no on-site server, automatic updates
- Hybrid — local controllers with cloud management
TimeClock 365 is a cloud-native platform that also unifies attendance management — one system, one identity per employee, one audit log.
2. Cost Drivers
- Number of doors and zones
- Credential type — card, NFC, biometric, Apple/Google Wallet
- Licensing model — per-door, per-employee, or flat
- One-time hardware: readers, locks, controllers, intercom
- Integration: payroll, HR, SSO, alerts
Compare combined and separate platforms using the same 3-year TCO worksheet, including hardware, licensing, installation, integrations, support and replacement costs.
3. Credential Type — How to Choose
- Card — familiar, easy to issue, easy to lose
- NFC & Apple/Google Wallet — phone-based, no plastic, fast onboarding
- Fingerprint — eliminates buddy punching and shared cards
- Face recognition — hands-free, ideal for high-traffic doors
4. Vendor Selection Checklist
- Cloud-native (not just cloud-managed legacy)
- Local Israeli support, Hebrew + English interface
- ISO 27001 certification
- Integration with Hilan, Priority and your SSO provider
- Audit trail you can export for compliance
- Automatic deprovisioning when an employee leaves
- Scales to multiple sites without hardware refresh
5. Questions to Ask Every Vendor
- What's the 3-year total cost of ownership for our footprint?
- How does deprovisioning work when an employee leaves?
- Where is our data stored and who can access it?
- What happens if internet goes down?
- Which payroll and HR systems do you integrate with?
- Can we manage multiple sites from one dashboard?
Primary Sources and Further Review
- NIST — least privilege, a primary basis for evaluating roles, authorization and periodic access review.
- ISO/IEC 27001:2022, the official requirements for an information security management system. A vendor's mention of the standard is not a substitute for checking the certificate's scope and validity.
- Israel Privacy Protection Authority — employee biometrics guidance, relevant to proportionality, notice, consent, security and purpose limitation.
Want a personalized recommendation?
Free 20-minute call — we'll map your building and help you compare options factually.
Book a Free Demo ←