RBH access control reader kit with dual black readers, interface board and coloured wiring, shown against a commercial sliding gate entrance.

Anti-Passback Explained: When Access Control Should Stop Credential Sharing

Essential Security Supplies

Anti-passback checks whether a credential's movement follows a defined entry and exit sequence. It can discourage certain forms of credential reuse, but it does not physically stop someone following another person through a door. NZ access control designs need suitable reader topology, exception handling and safe operating rules before enabling it.

Define the zone and direction

Choose the boundary whose occupancy state the system should track. Mark every reader that changes a credential's state on entry or exit. A single entry reader with unrestricted mechanical exit cannot always supply the movement information needed for strict sequence enforcement. Confirm the platform's supported arrangement and define how unrecorded movement is handled. Keep logical occupancy separate from proof that a person remains physically inside.

Distinguish soft and hard behaviour

Soft anti-passback commonly logs or reports an invalid sequence while allowing the configured action; hard anti-passback can deny a credential request. Exact terminology and behaviour vary by platform. Verify the chosen software and firmware rather than assuming a menu label has the same meaning everywhere. Write expected outcomes for repeated entry, repeated exit and an unknown initial state, then use them as commissioning tests.

RBH-IRC-2000 - RBH Integra32 2-Door Controller (UL Listed) includes Enclosure with 13.8VDC, 2A power supply
RBH-IRC-2000 - RBH Integra32 2-Door Controller (UL Listed) includes Enclosure with 13.8VDC, 2A power supply. Genuine supplier catalogue photograph.

Soft vs hard anti-passback: comparison

The right mode depends on site security, reader configuration and supported platform features. Confirm the exact behaviour in manufacturer documentation before commissioning.

Mode Typical behaviour Application
Soft anti-passback Flags or logs an invalid credential sequence without necessarily denying entry. Office sites, initial rollout and systems prioritising continuity.
Hard anti-passback May refuse an invalid entry or exit sequence until the state is corrected. Controlled areas with entry and exit readers and defined exception procedures.
Timed restriction or reset Applies a supported time window or state reset, according to the platform. Selected sites where a time-based rule is suitable and documented.

Timed restrictions are not automatically equivalent to zone-based anti-passback. Confirm the selected RBH controller, software release and topology support the rule being specified.

Worked example: staff entry and exit

Consider an office with entry and exit readers connected to a controller that supports zone-state anti-passback. The following is an example workflow, not a guarantee of behaviour for every product.

  1. First entry: An authorised employee presents a credential at the entry reader. The system records the credential as inside the zone.
  2. Repeated entry: Before an exit has been recorded, a second entry presentation is made. Soft mode may flag it; hard mode may deny it.
  3. Recorded exit: The employee uses the exit reader, allowing the zone state to return to outside.
  4. Unrecorded exit: An alternative permitted exit leaves the logical credential state unchanged, potentially causing a later entry refusal.
  5. Authorised recovery: The operator checks events and follows a documented state-reset procedure, recording the reason where supported.

During commissioning, test each sequence using the installed firmware and record expected and actual results. Credential events are not proof of physical occupancy, and anti-passback must not obstruct the site's approved emergency escape arrangements.

Plan resets and exceptions

Decide who can reset a credential or area state and what record is kept. Include a lost exit event, a reader outage, emergency movement and a staff member returning with a forgotten item. Automatic timed resets can restore usability while also weakening enforcement, so use them deliberately. Avoid a policy that leaves an authorised person locked out without an assistance route and a responsible operator.

Check global and offline behaviour

A multi-controller zone may depend on communication or server features to share state. Determine how the selected platform handles a failed link, buffer replay and conflicting events after reconnection. Do not assume global anti-passback remains identical when controllers are offline. Test the actual topology and confirm supported limits. An anti-passback requirement must specify the operating conditions, not just the presence of a feature.

RBH-BFR350 - Blueline Fingerprint Reader, PIN Keypad and Card Reader
RBH-BFR350 - Blueline Fingerprint Reader, PIN Keypad and Card Reader. Genuine supplier catalogue photograph.

Keep safe egress independent

Anti-passback should not be improvised as a restriction on required escape. Coordinate the release and emergency movement arrangements with the approved building design. Logical state after an evacuation may require reconciliation or reset, but that is an operational process. The security installer should not promise accurate emergency headcounts solely from credential events, particularly where tailgating or unrecorded exits can occur.

Verify support before deployment

For an RBH project, obtain the current Integra32 or Axiom documentation for the exact feature and topology proposed. Do not infer capability from a generic controller listing. Run a small trial covering normal movement and all required exceptions before applying the rule to every user. Train operators in resets, logs and assistance so an enforcement feature does not become a source of unexplained access refusals.

RBH-EXITRDR - RBH Exit Reader Module-URC, IRC (Ver4+) & UNC (INT)
RBH-EXITRDR - RBH Exit Reader Module-URC, IRC (Ver4+) & UNC (INT). Genuine supplier catalogue photograph.

Apply the design to the actual project

Create an anti-passback state table with initial state, reader event, permitted outcome and resulting state. Include unknown state and authorised reset, not just entry and exit. Present the same sequences during the platform demonstration so the client's policy is compared with actual behaviour. Confirm whether a denial, warning or logged event occurs and who can resolve it. Keep a trace of the operator's reset where the platform supports one.

Test exceptional movement with the site team. A reader outage, emergency exit or door held open can leave the logical state inconsistent with physical movement. Decide how the system recovers and what users are told. Check global rules during communication loss if the design depends on more than one controller. Do not infer a complete occupancy picture from a clean anti-passback log. Train operators to distinguish a credential-state problem from a door or reader fault, and keep the assistance route available without weakening the required escape arrangement.

Separate security permissions from safe escape

Build permissions around roles and areas, then apply schedules and expiry dates. Give contractors time-limited access and allocate an owner to remove it. Use named operator accounts, restrict configuration rights and keep an audit trail of administrative changes. Test a valid credential, an expired credential and a credential without the required area permission. Include a revoked credential after synchronisation. Those tests reveal errors that a single successful presentation cannot show.

Entry control must be coordinated with the building's approved escape and accessibility arrangements. Do not treat a software unlock command as proof of acceptable emergency egress, and do not add an interlock that delays escape without the required design approval. Document the mechanical exit path, release devices and interfaces, with responsibility assigned to the relevant building professionals. New Zealand Building Code guidance on access routes and movement to a place of safety provides the starting point for the project's design review.

Commissioning acceptance checklist

Agree the expected result before testing. Use the installed configuration and retain evidence of each outcome, including a failure that must be corrected. The following checks supplement the exact manufacturer procedures and the approved project design.

Required check Record to retain
Test valid sequences, repeated entry and an unknown initial state. Expected behaviour, actual result, configuration tested and responsible person. Resolve an unexpected outcome before accepting this requirement.
Check communication-loss behaviour and reconciliation after recovery. Expected behaviour, actual result, configuration tested and responsible person. Resolve an unexpected outcome before accepting this requirement.
Verify authorised reset, assistance and the independent emergency egress path. Expected behaviour, actual result, configuration tested and responsible person. Resolve an unexpected outcome before accepting this requirement.

Repeat affected checks after a material equipment, software or site change. Keep the test record with the as-built schedule so the next maintainer can understand which configuration passed and which assumptions still need review.

Equipment candidates and specification checks

These are relevant active catalogue candidates for a project review, rather than a universal recommendation or a promise of immediate stock. Use the full product page and current manufacturer information to confirm the supplied variant and its role in your design.

Review the Essential Security Supplies access control equipment range alongside the intended workflow. For further context, read our multi-site access control planning guide.

Frequently asked questions

Does anti-passback prevent tailgating?

No. It evaluates credential sequences, not every person's physical movement through the opening.

Can it work with only an entry reader?

That depends on the platform and required rule. Verify how exit state is established and what limitations remain.

Are access events an accurate emergency headcount?

Not automatically. Unrecorded movement, tailgating and outages can make the logical count differ from occupancy.

When should hard anti-passback be used?

Use it where repeated credential use must be controlled, entry and exit events can be reliably captured, and authorised staff can resolve exceptional states. Confirm platform support and test emergency egress independently before enabling enforcement.

What happens to anti-passback during an evacuation?

Emergency escape must remain available under the approved building design. An evacuation can leave logical credential states inconsistent with actual movement. Document and test the post-evacuation reconciliation or reset procedure; do not use access events alone as an emergency headcount.

Primary references and technical scope

Use the primary manufacturer or technical reference for the claims it covers. General design guidance does not replace the selected product's installation manual. Confirm current firmware, model variants and the approved project requirements before ordering or commissioning.

Get specification help from Essential Security Supplies

Send your site layout, equipment schedule, intended workflow and any existing model details to Essential Security Supplies for specification help and a project quotation. Identify the functions that must be demonstrated and the interfaces owned by other contractors. Our enquiry route supports a documented equipment review without publishing prices or assuming unverified compatibility.