The short answer
In a cloud-managed access control system the door controller stays on site while the credential database and administration console are hosted by the vendor and billed as a per door subscription. In an on-premise system both run on a server the owner controls, under a perpetual license plus an annual support agreement. Controllers on both architectures keep unlocking doors from a cached credential database when the network or the server is unavailable, so the practical difference is who patches the software, who backs up the database, and how the recurring cost appears.
| Architectures | Cloud-managed, on-premise server, hybrid |
|---|---|
| Cloud platforms | Brivo, Verkada, Avigilon Alta |
| Hybrid platform | UniFi Access, local console with cloud access |
| Enterprise on-premise | Genetec Synergis, LenelS2 OnGuard and NetBox |
| Multifamily | ButterflyMX video intercom and smart access |
| Equipment listing | UL 294 access control system units |
| Reader protocol | OSDP v2 with Secure Channel preferred over Wiegand |
Three architectures: where the controller, database and admin live#
Every access control system has four parts: a reader at the door, a controller that decides whether to unlock, a database of credentials and schedules, and an administration interface. The architecture question is where the last two live.
In a cloud-managed system the controller is on premises, in a telecom room or above the door, and reports to a vendor-hosted service over an outbound internet connection. The database of record and the admin console are in the vendor’s cloud. Nothing on site needs a static IP or an inbound firewall rule.
In a fully on-premise system the database and admin console run on a server the owner controls: a physical server in the MDF, a virtual machine, or an embedded appliance. Controllers talk to that server over the building LAN. Nothing leaves the building unless the owner sets up remote access.
A hybrid system keeps the server and controllers on site and adds a cloud layer for remote administration, mobile credentials or multi-site reporting. Decisions and records stay local; the vendor cloud is a relay for remote login.
The distinction matters less at the door than in the IT department. The reader, door position switch, request-to-exit device, lock power and cabling are the same in all three cases. What changes is who patches the software, who backs up the database, and what the invoice looks like in year six.
Platforms commonly specified for each architecture#
The table lists platforms that appear most often on California Division 28 specifications. Telelink installs and configures ButterflyMX and DoorKing systems and installs the others to the project specification. We claim no certification, authorization or partnership with any manufacturer.
| Platform | Architecture | Typical fit | Notes on naming |
|---|---|---|---|
| Brivo Access | Cloud-managed, controller on premises | Multi-site commercial, property portfolios | Reader-agnostic controllers, Wiegand and OSDP |
| Verkada Access | Cloud-managed, controller on premises | Offices, schools, sites with Verkada cameras | Own readers and controllers, per-door license terms |
| Avigilon Alta Access | Cloud-managed, controller on premises | Offices, mobile-first credential programs | Formerly Openpath; acquired by Motorola Solutions and rebranded. Older specs still say Openpath |
| UniFi Access | Hybrid: local console, cloud remote access | Small and mid-size commercial on UniFi networking | Runs on a local UniFi console; no recurring per-door license as of 2026 |
| ButterflyMX | Cloud-managed intercom and access | Multifamily and senior housing entries, elevators, package rooms | Property-wide subscription; resident app and video intercom |
| DoorKing (DKS) | On-premise controllers, optional cloud management | Vehicle gates, telephone entry, parking | Long-standing gate and telephone entry line |
| Genetec Security Center Synergis | On-premise server, cloud options available | Enterprise, campus, public agency with IT operations | Unified with Genetec Omnicast video |
| LenelS2 OnGuard and NetBox | On-premise server or embedded appliance | Enterprise, healthcare, government | OnGuard for large enterprise; NetBox for mid-size |
Names change. Openpath became Avigilon Alta, Avigilon’s on-premise line became Avigilon Unity, and several manufacturers sell the same controllers under both a subscription and a perpetual license. Verify the current name and licensing model before pricing.
Licensing: subscription, perpetual, and what each one buys#
Cloud platforms are sold as a subscription, usually per door per year, sometimes per user or per site. It covers hosting, updates, the admin console, mobile credentials on most platforms, and support. Some vendors sell one to ten year terms up front; others bill annually. Stop paying and, after a grace period, the doors keep working on the last downloaded database but administration stops.
On-premise platforms are sold as a perpetual license plus an annual support agreement priced as a percentage of the license. The license does not expire. The support agreement buys upgrades, patches and vendor support, and most owners keep it current because an unsupported server on a corporate network is a liability. Add server hardware, an operating system license, database licensing on larger platforms, and a refresh cycle.
The comparison is a visible annual fee against a set of less visible annual costs. On a ten year view for a 20 door building the two often land in a similar range. The subscription is easier to budget; the perpetual license is easier to defend where a server room and a patching schedule already exist.
What happens when the internet or the server goes down#
Cloud-managed controllers on the platforms above hold a local copy of the credential database and schedules. When the internet fails, the controller keeps reading cards and unlocking doors on the last synced rules, and buffers events until the link returns. Two things do not work during the outage: console changes (a new hire, a revoked badge) do not reach the door until the controller reconnects, and mobile credential modes that route through the cloud may fall back to Bluetooth or stop.
On-premise systems behave the same way when the server goes down: controllers continue on cached rules. The difference is who recovers. On a cloud platform the vendor’s availability is in the contract. On an on-premise platform, server recovery is the owner’s job: backups, a spare, and someone who knows the system.
Two habits cover both cases. Put controllers on a UPS so a power blip does not reboot them mid-day. Set the fail-safe or fail-secure behavior of each lock deliberately; doors in the path of egress must allow free exit at all times regardless of what the software is doing.
Credentials and readers: prox, smart cards, mobile, and OSDP#
The 125 kHz proximity card that most buildings installed in the 1990s and 2000s transmits its number in the clear and can be copied with a handheld cloner. Replacing 125 kHz prox cards removes the easiest attack on the system.
13.56 MHz smart cards (MIFARE DESFire, HID Seos and iCLASS SE are the names you will see) store the credential in an encrypted application and authenticate with the reader before releasing it. Mobile credentials use Bluetooth Low Energy or NFC from a phone and are issued and revoked from the console without printing anything.
Between the reader and the controller there is a second choice. Wiegand is a one-way, unencrypted interface that has been the default for decades. OSDP version 2 with Secure Channel is bidirectional and encrypted, supports reader supervision, and allows firmware updates over the same wires. Specify OSDP for new construction. For a retrofit, an OSDP reader on existing wiring is usually possible.
Regardless of platform, specify UL 294 listed access control equipment, which is what an inspector and an insurer will ask about.
Integrating access control with video and intercom#
The reason to pick a platform is often not the controller but what it connects to. Video association ties a door event to a camera clip so an operator reviewing a forced door sees the person, not just the log entry. Platforms that make both cameras and controllers do this natively; cross-vendor integrations exist through APIs and are worth testing before the specification names them. On any project touching federal funds the camera line must meet Section 889 and 2 CFR 200.216; see our NDAA compliant cameras guide.
Intercom integration lets a visitor call a resident or a front desk and lets that person unlock the door from a phone or a station. In multifamily this is the core of the system: a ButterflyMX lobby panel calls the resident’s phone, the resident sees video and unlocks, and the same platform runs amenity keypads and elevator access. In commercial buildings the intercom is more often a SIP device at a secured entry tied to the phone system. Our intercom and entry systems page covers both.
Elevator control, visitor management and identity provider sync (Microsoft Entra, Okta, Google Workspace) are the next tier. Identity sync is worth pricing on any office project because it deactivates the badge when HR closes the account.
IT security considerations the spec should state#
An access controller is a network device with a web interface and a firmware version. Treat it that way. Require a dedicated VLAN for physical security devices (controllers, IP readers, cameras, intercom panels) segmented from the corporate network, with firewall rules that allow only what the platform needs: outbound HTTPS to the vendor for cloud platforms and nothing inbound; server-to-controller LAN traffic for on-premise.
Require multi-factor authentication on every administrator account, single sign-on where supported, and role-based permissions so a leasing agent who issues fobs cannot change door schedules. Require a firmware update policy: cloud platforms push updates, which the owner should be able to schedule; on-premise platforms leave the owner to apply them, so name who does it. Require audit logging of admin actions, default credentials changed at commissioning, and a closeout package with the IP addressing, VLAN assignments and firewall rules as installed.
These items are routinely missing from Division 28 specifications and get argued at commissioning. Writing it down moves the argument to bid time.
Ten year cost view and a decision table by building type#
The figures below are California commercial planning ranges as of 2026, not quotes. Door hardware, door count and existing pathways move them more than the platform choice. Our access control installation cost guide covers installed cost per opening in detail.
| Cost element | Cloud-managed | On-premise | Notes |
|---|---|---|---|
| Installed cost per door (reader, controller share, cabling, labor) | Similar | Similar | Roughly $2,000 to $6,000 per door before electrified hardware |
| Electrified door hardware | Same | Same | Division 08 or C-28 scope, coordinated, not in the low voltage number |
| Software, year 1 | Per-door subscription | Perpetual license plus first-year support | Roughly $150 to $600 per door per year, about $12 to $50 per door per month, by platform and term |
| Software, years 2 to 10 | Same subscription | Annual support, often 15 to 20 percent of license | Plus at least one server refresh in ten years |
| Server, OS, backups, staff time | None on site | Owner’s cost | Owner cost, not invoiced by the vendor |
| Building type | Usual recommendation | Why |
|---|---|---|
| Multifamily and affordable housing | Cloud (ButterflyMX at entries, cloud or hybrid at staff doors) | Resident turnover, remote management, no on-site IT |
| Senior and assisted living | Cloud or hybrid | Staff doors and nurse call coordination; local decisioning is essential |
| Office, tenant improvement, multi-site business | Cloud | Identity sync, mobile credentials, one console across sites |
| K-12 and higher education | Follows district or campus standard | Lockdown functions and existing standards outweigh preference |
| Government and public agency | Often on-premise or hybrid | IT security policy, data residency, procurement rules |
| Healthcare and clinics | Small clinics cloud; hospitals on-premise enterprise | Integration with existing enterprise systems |
| Industrial and warehouse | Cloud with DoorKing gate control | Vehicle gates, shift schedules, remote sites |
The smaller the on-site IT operation and the more sites in the portfolio, the stronger the case for cloud. The larger the existing security operation and the stricter the data policy, the more on-premise or hybrid fits. If you are still deciding who should install it, our guide on how to choose a low voltage contractor in California covers what to ask.
Next step#
Send us the door schedule, the building type and the platform you are leaning toward, or ask for a recommendation, and request a bid. We will return a per-door scope with the electrified hardware handoff, the network requirements and the licensing model stated plainly. General contractors can find our standard exclusions on the for general contractors page, and the full service description is on our access control systems page.
This article is general information for planning and specification, not a bid, engineering advice or legal advice. Codes and standards change; confirm the current edition with the authority having jurisdiction. Scope and price for a specific building come only in a written proposal.