Somewhere in every access control quote there is a column nobody reads carefully. Beside each door is a word: fail-safe or fail-secure. It looks like a technical detail for the installer. It is not. It is the single decision on that page most likely to be wrong, and it is wrong in the same way almost every time — because one of those words sounds better than the other.
Read them cold and you will hear a recommendation. Safe. Secure. An owner asked to choose picks the one matching their temperament: the cautious owner picks fail-safe, the owner who has been broken into picks fail-secure. Both have just made a building-wide preference out of a decision that has to be made one door at a time.
Neither word is a grade. They describe a mechanical behaviour, and that behaviour only appears under one condition.
What the words actually describe
Both terms answer exactly one question: what does this lock do when it loses power?
A fail-safe device unlocks when power is removed. It needs electricity to stay locked. Cut the supply and the door releases.
A fail-secure device stays locked when power is removed. It needs electricity to release. Cut the supply and the door remains locked.
That is the entire definition. "Safe" means safe for people — the door lets go. "Secure" means secure for property — the door holds. Neither word tells you anything about quality, strength or reliability. A fail-safe device on the wrong door is a defect; a fail-secure device on the wrong door is a worse one. The whole job is knowing which door you are standing at.
Note what these terms do not cover. They describe behaviour during a power loss — a blackout, a tripped breaker, a cut cable, a controller failure. In normal operation both types are locked when they should be and release on a valid credential. The distinction only becomes visible on the worst day.
The fixed point: people must be able to get out
Before any of this becomes a preference, there is a requirement it has to survive.
The BC Building Code states the free-egress principle in two parallel places, and which one governs your door depends on where the door is. Division B, Sentence 3.4.6.16.(1) covers a principal entrance door to a building and every exit door. It requires that locking, latching and other fastening devices on those doors include release hardware "to permit the door to be readily opened from the inside with not more than one releasing operation and without requiring keys, special devices or specialized knowledge of the door-opening mechanism."
Each phrase is doing work:
- From the inside — the requirement is about leaving, not entering. Locking people out is a business decision. Locking people in is not.
- One releasing operation — one motion. Not turn the thumbturn and then push the bar. Not release the deadbolt and then the latch.
- Without keys — a person leaving cannot be required to have or find a key.
- Without special devices or specialized knowledge — no code to remember, no hidden button, no sequence somebody has to have been shown. A visitor who has never been in the building before must be able to do it.
The related Sentence 3.4.6.16.(4) adds that every exit door must open under a force of not more than 90 N applied at the knob or other latch releasing device once the latch is released, subject to the exception it names. Getting out cannot require strength either.
Doors inside a floor area — a suite door opening into a corridor, a door along the path to the stairwell — are governed instead by Article 3.3.1.13. Sentence (2) requires that a door in an access to exit be readily openable in travelling to an exit, again without keys, special devices or specialized knowledge; Sentence (3) requires release hardware and that the door be openable with not more than one releasing operation. The tests are near identical, which is why the distinction is easy to miss and worth getting right: an exit is the part of the route leading out of the floor area, while an access to exit is the part within it.
So here is a rule of thumb — not the Code test, which depends on which provision reaches your door. Stand at a door and ask: if the power died right now with someone inside, could they get out with one motion and no special knowledge? If the honest answer is no, look hard at that door. It errs toward more egress freedom than the Code strictly demands in some places, which is the safe direction for a rule of thumb to err.
Where owners get it backwards
Here is the part that surprises people. A fail-secure door can be entirely compliant, and frequently should be. The trick is separating two questions that get collapsed into one:
- The mechanical question — what does the lock do without power?
- The code question — what must this door do for a person leaving?
They are not the same question, and a door only needs the lock to release on power loss if egress depends on the lock releasing.
Consider a typical office suite door with an electric strike on the exterior side and a mechanical lever handle inside. This is an access-to-exit door — it opens into a corridor inside the floor area — so 3.3.1.13.(2) and 3.3.1.13.(3) are the provisions that govern it. The strike controls entry. The inside lever mechanically retracts the latch regardless of what the electronics are doing. Kill the power and the strike stays locked — nobody gets in — but the person inside turns the lever and walks out in one motion, with no key and no special knowledge. That door is fail-secure and it satisfies the free-egress requirement, because egress was never routed through the electronics in the first place.
Now fit the same suite so the electronics hold the door shut against the person inside as well. Egress now depends on the system releasing, and fail-secure on that door means a power loss traps people. That is precisely the situation the code language above exists to prevent.
The rule underneath both cases: if the electrified device is what stands between a person and the way out, it must release when power is lost. If the way out is mechanical and independent, it does not. Fail-secure is not a compromise on life safety when egress is mechanically free — it is the correct answer, and the more resilient one, because a blackout does not unlock your building.
Where fail-safe becomes the defect
Run the same logic the other way and you find the failure owners never anticipate. Some doors have a job that has nothing to do with keeping people out. A door in a fire separation is there to hold the separation, and Article 3.1.8.15 of the Code deals with door latches and positive latching in a fire separation. A door required to latch has to actually latch — and stay latched when it matters most, which is when the building is on fire and may well have lost power.
Fit that door with a device that releases every time power drops, chosen because "fail-safe sounds safer," and you have built something worse than an inconvenience: a fire-separation door that unlatches at exactly the moment the separation is doing its only job. The stairwell meant to stay a protected route now has a door standing off its latch. Occupants can still get out — that was never in question — but the compartment fails.
Article 3.3.1.13 — titled "Doors and Door Hardware" — reaches more than the free-egress rule quoted above. It also covers clear widths, thresholds, hardware height and other requirements that a door has to satisfy at the same time. Power-loss behaviour has to be chosen against all of the obligations a given door carries, not against a general feeling about safety.
Electromagnetic locks are their own conversation
Electromagnetic locks — devices that hold a door shut with a magnet and release when power is removed — are addressed in the BC Building Code at Division B, Sentences 3.4.6.16.(5) and 3.4.6.16.(6). They are permitted, subject to conditions.
We are not going to tell you what those conditions are, and you should be wary of anyone who recites them from memory. They are specific, and they are the difference between a permitted installation and one that has to come out. If your building has these locks, or a proposal puts them on your drawings, have the current conditions confirmed against the Code for your door, your occupancy and your building by someone accountable for that opinion — in writing.
The output is a schedule, not a preference
Doing this properly produces a document: a door schedule — every controlled opening in the building listed in a row, with its power-loss behaviour, the reason for it, and how a person leaving gets out when the electronics are dead. It is the only form in which this decision can be checked, handed to a new manager, or shown to an inspector. A verbal preference relayed to an installer is not reviewable by anyone.
Two more things belong in the picture.
First, responsibility. Division A, Article 1.2.1.2 of the Code addresses the responsibility of the owner. Whatever your installer, integrator or consultant proposes, the obligation attaches to the building and its owner. Strata councils in particular should notice that this survives every change of council and every change of contractor. The drawing is how it survives.
Second, the Building Code governs the design; the Fire Code governs the rest of the building's life. Egress has to stay usable and the hardware has to be inspected and tested on an ongoing basis — a door compliant on the day it was commissioned is not compliant if a chain appears on it in year four, or if nobody has confirmed the release hardware still works. We are deliberately not quoting a Fire Code article number here; the exact provision and edition should be confirmed for your building. The obligation is real and continuous.
What to do this week
Walk your building with a notebook and, at every door with electronics on it, write down three things: what the door is for, what it does when power is lost, and how a person inside gets out with one motion and no key.
There is one test worth doing rather than reasoning about, and it takes a minute per door. Kill the power to the door and try the inside handle.
This matters more than it sounds. From the inside, a plain mechanical lever and a fail-secure electrified lever or mortise lock look identical — same lever, same escutcheon, same feel while the power is on. The entire distinction the example above rests on, that the inside lever retracts the latch regardless of the electronics, is invisible standing at the door. The only way to know which one you own is to remove the power and pull the handle. Do it with someone who can restore the power, do it outside business hours, and write down what happened.
The doors where you cannot answer the third question are your list. There is no correct answer to "should our building be fail-safe or fail-secure?" There is only a correct answer for each door, and a drawing that records it.