PHYSICAL ACCESS SECURITY

Security starts with the right permission — and continues with evidence

TimeClock 365 brings permission management, entry events and remote control together. This page explains what the product supports and what your team should validate before procurement.

Controls across the access lifecycle

Protection does not end at the door reader. Identity management, permission changes and evidence after an event matter just as much.

01

Provision and revoke

Managers can assign access by employee, area and schedule, then revoke permission remotely as requirements change.

Remote management →
02

Event log

Entry events are recorded with time, employee and door details for search and operational review.

Entry log →
03

Organizational identity

The site documents SSO options including SAML and common identity providers. Fit is confirmed before deployment.

SSO options →
04

Door continuity

Supported controllers can use locally cached permissions during a temporary outage and synchronize events when connectivity returns.

How it works →

ISO 27001: look beyond the badge

TimeClock 365 is presented on this site as ISO 27001 certified. A professional supplier review should request the current document and verify that the certified entity, scope, version and validity cover the service you intend to buy.

Transparency note: this page does not publish a certificate number, certification body or expiry date, so it is not a substitute for reviewing the certificate during procurement.

What to request in due diligence

  • Current certificate and certification scope
  • Relevant data processing and storage locations
  • Retention and deletion rules by data type
  • Security incident response process
  • Responsibility split between platform, installer and customer

Decisions your organization must make

Least privilege

Define who needs each area and schedule — not only whether someone works for the organization.

Administrative roles

Decide who may add employees, open doors, review logs and export information.

Leaver or lost device

Document rapid revocation for cards, phones, PINs and permissions across every site.

Fallback credential

Choose an alternative for power loss, hardware trouble, empty batteries or network outages.

Biometric data

If biometrics are selected, complete legal and organizational review of necessity, consent, retention and deletion.

Periodic review

Schedule permission and log reviews, active-user checks and edge-case exercises.

Want to review your security scenario?

In a demo, we can map doors, user types, credentials and revocation workflows.

Book a demo