DeskOS agents now work every lead from first message to signed agreement
DeskOS
Access control

The door knows who is still a member

Door level grants tied to the membership, on whatever readers your building already has. Access issues itself when you sell, ends itself when somebody leaves, and every unlock is on the record.

Granularity
Per door, per member
Credentials
Face, card, PIN, QR
Network
No inbound ports
Truth
Device confirms, then applied
Nova Coworking, Bengaluru14 doors online
Access matrixMeridian Labs, 8 members
Main entranceGranted
Level 3 lobbyGranted
Cabin 3BGranted
Level 1 lobbyBlocked
Server roomBlocked
FaceCardPINEnds 31 Aug
Door activityLast hour
Main entranceRavi Menon · face · 09:41Allowed
Level 3 lobbyAnita Shah · card · 09:38Allowed
Server roomRavi Menon · face · 09:36Denied
Main entranceVisitor pass 4471 · QR · 09:30Allowed
Level 1 lobbyFront desk remote · 09:22Unlocked
The daily problem

The access list and the member list stopped matching months ago

Credentials get issued in a vendor app that knows nothing about who is paying you. People leave and keep their card. Somebody has access to a floor they moved off in March. The list is only ever cleaned up after an incident.

What DeskOS does about it6 capabilities
01Model

Access is granted per door, not per building

A member gets the main entrance, their floor and their cabin. A staff member gets the server room. Each grant is its own record against a specific door, so access is described exactly rather than approximately.No blanket credentials nobody can audit

02Lifecycle

Access starts and ends with the membership

Sell the membership and credentials issue themselves. Log a notice and access ends on the last day of the term. Nobody has to remember, and nobody keeps working access three months after they churned.Ex members stop walking in

03Credentials

Face, finger, card, PIN and QR on one set of rules

Enrol whichever credential the site uses. The grant is the same object regardless, so changing a member from card to face does not mean rebuilding their access.Mixed hardware, one access model

04Revocation

Revoke means blocked, not deleted

Removing access blocks the credential rather than quietly dropping the record, so a revocation survives a device reboot, a resync or a controller replacement. The grant list is the truth and devices are reconciled against it.Revocations that cannot un-revoke themselves

05Network

A gateway built for real buildings

Devices behind NAT with no public address still work: they report in and receive their commands, with confirmation from the device treated as the source of truth rather than an assumption. Nothing is considered applied until a device says so.Works without opening ports to the street

06Audit

Every unlock, on the record

A searchable log of who opened which door, when, with which credential, and which grant allowed it. Answer a landlord, an insurer or an incident question from the console rather than from a device.One log across every door and centre

Remote unlock, with a leash

The front desk can open a door remotely, but the unlock is time limited, permission gated and logged like everything else.

Schedules

Access windows follow what the member bought. Weekday plans, shift plans and 24/7 plans each open the door at the right hours.

Manual linking

Existing enrolments on a device can be matched to a member rather than re-enrolled, so a live site can move over without queuing everyone at the reader.

Because it is one system

The safest access list is the one nobody has to maintain

Access goes stale when it is maintained by hand. Here it is a consequence of the membership, so it is correct by construction.

Memberships

Sell, upgrade, move or end a membership and the door grants follow the same day.

Visitors

A visitor pass is a time limited grant on the doors that visit needs, and nothing else.

Attendance

Door events feed check-in and attendance, so presence is measured rather than self reported.

Collections

If you choose to, non payment can restrict access. It stays a deliberate policy, never a surprise.

FAQ

Questions operators actually ask

Which access hardware do you work with?

ZKTeco biometric and card readers are the ones we deploy most, connected through the DeskOS access gateway. Because grants are stored as our own records rather than inside a device, adding another controller family is an integration job rather than a migration.

Our devices sit on a private network behind NAT. Is that a problem?

No. Devices reach out to the gateway rather than the gateway reaching in, so no inbound ports and no public IP are needed. Commands are queued and only marked applied once the device confirms them.

What happens to door access when a member gives notice?

Access ends on the last day of the term automatically, because the grant hangs off the membership. If they extend, it extends with them.

Can we give one member access to some doors but not others?

Yes, that is the default. Access is a matrix of members and doors, so a member can hold their floor and their cabin without holding the whole building.

Does this work across multiple centres?

Yes. Doors belong to centres, and members can hold grants at one centre or several depending on what they bought.

Bring one door and one reader

We will enrol a member, grant a door, end the membership and show you the credential stop working. It takes about ten minutes.