Open the reporting menu of almost any access control system and you will find a list long enough to be useless. Cardholder activity. Door activity. Alarm history. Audit trail. Credential inventory. Access level detail. Operator actions. Time schedule exceptions. Some systems offer thirty or more, several of which are the same query wearing a different hat.
The practical consequence of a menu that long is that nobody picks anything from it. In building after building across BC, the reporting module has never been opened by the person who owns the building. It was demonstrated once during handover, everyone nodded, and the system went back to doing the only job anyone asks of it: opening doors for people who tap.
That is a shame, because four of those reports are genuinely worth running, and they are worth running on a schedule rather than in a panic. Each one finds a different species of the same underlying problem, which is drift — the slow divergence between what your system is configured to do and what your organization actually looks like today.
Before the four, one thing has to be said plainly, because it governs all of them.
These reports are personal information
Every one of these reports is a list of named people and their movements. That makes running them a collection and use of personal information under BC's Personal Information Protection Act, not an IT housekeeping task. We have written separately about why your door logs are personal information, and that article carries the detail. The short version for this one:
The Act's employee-information provisions — sections 13, 16 and 19, covering collection, use and disclosure — let an employer handle employee personal information without consent where it is reasonable for establishing, managing or terminating the employment relationship, and ask in return that the individual be notified about what is being done and why. Section 34 requires reasonable security arrangements around the information you hold. Section 35 requires you to have thought about how long you keep it.
None of that stops you running a report. What it does is give the report a job description. Before you run one, you should be able to say in one sentence why you are running it — "to find credentials that are still active for people who have left" is a purpose; "to see what Dave has been up to" is not. The first is administration of the employment relationship. The second is a person using a corporate system to satisfy curiosity about a colleague, and it is the single easiest way to turn a compliance-neutral tool into a complaint.
The practical control is boring and effective: write down which reports get run, on what cycle, by whom, and for what purpose. That document takes fifteen minutes and it is the difference between a defensible practice and an improvised one. Also note that these sections govern employee personal information — if your cardholders include tenants, strata residents or contractors, a different part of the Act applies to them and the question is worth asking specifically.
1. Credentials not used in N days
What to look at. Ask the system for every active credential with no read event in the last sixty or ninety days. Pick the number to suit your building — a site with rotating contractors needs a shorter window than a nine-to-five office. What matters is that the report lists credentials that are enabled and idle, not credentials that are disabled.
What normal looks like. A short list. Long-term leave, a seasonal worker, the spare fob in the manager's drawer, the elevator technician who visits quarterly. You should be able to name every entry within a minute or two.
What the finding usually means. This is the report that finds departed staff still holding live access, and in our experience it is the most common real finding in the whole set. Someone resigned, their manager collected the laptop and the parking pass, and nobody told the person with the access control login. The credential was never disabled. It has simply been sitting there, valid, for eleven months.
Say the uncomfortable part clearly: this is almost never wrongdoing. It is administrative drift. The offboarding checklist has HR steps and IT steps, and access control belongs to neither department, so it falls into the gap between them. The former employee has probably thrown the fob in a drawer and forgotten about it. The risk is not that they are coming back at night; the risk is that your system's answer to "who can enter this building" is wrong, and you did not know it was wrong.
The fix is two-part. Disable what the report found, and then put access control on the offboarding checklist so the next one is caught on the day rather than the quarter.
2. After-hours and weekend access
What to look at. All granted access events outside normal operating hours, and all weekend access, grouped by person and by door. Most systems will do this from a time-range filter; some have a dedicated report.
What normal looks like. Cleaners on their scheduled evenings. The person who genuinely comes in at six. Whoever opens on Saturday. A handful of one-off late nights around a deadline or a month-end.
What the finding usually means. Two categories, and separating them is the entire value of the report.
The first is a genuine problem, and it is rarer than owners expect: access at an hour that nobody can explain, at a door that person has no reason to use.
The second is far more common and much more interesting: a legitimate pattern that nobody ever documented. The maintenance contractor who has been coming in at five in the morning for three years because that is when the mechanical room is quiet. The bookkeeper who does month-end on Sundays. The tenant's staff using a shared corridor door on a schedule nobody at the property management company knew about. None of this is misconduct. All of it is your building operating in a way that exists nowhere in writing.
That matters more than it sounds. If your understanding of who is in the building after dark is wrong, then your alarm response is calibrated to the wrong picture, your guard's post orders describe a building that does not exist, and the first time anyone reconciles the two is during an incident. Running this report once a quarter converts undocumented reality into documented reality, which is most of what "knowing your site" actually means.
3. Doors held open and forced open
What to look at. Two alarm types, reported together and grouped by door: door held open (the door was opened with a valid credential, or from the inside, and then stayed open past the timer) and door forced open (the door opened with no corresponding grant at all).
What normal looks like. A trickle. Deliveries at a loading bay generate held-open events legitimately. A busy main entrance in the morning will produce a few. What you are looking for is not the presence of events but their concentration — one door producing far more than its neighbours.
What the finding usually means. This report finds two very different things, and the grouping tells you which is which.
A door with many held open events at consistent times of day is propped. Someone has wedged it with a bin or a fire extinguisher, and they have done it for a reason: the door is on the smokers' route, or the delivery path, or the shortcut to the parkade, and badging through it forty times a shift is intolerable. The person propping it is solving a real workflow problem in the only way available to them. Treating that as a discipline matter usually just relocates the prop to a door you are not watching. The better response is to ask what the door is being used for and whether the access design matches it.
A door producing forced open events, or held-open events scattered without pattern, is more often failing hardware. A door closer that no longer pulls the door fully shut, a strike out of alignment, a warped exterior door in cold weather, a position switch drifting out of range. The system is not reporting a person; it is reporting a door that no longer latches reliably. That is a maintenance finding, and an important one, because a door that does not latch is not securing anything regardless of what the software believes. Our article on access control maintenance covers what has to be inspected and how often.
The distinction is worth internalizing: repeated held-open at regular times is a people and workflow finding. Forced-open and irregular held-open is a hardware finding. Same report, two entirely different work orders.
4. Access level membership — who can go where
What to look at. For each access level or group, the full list of cardholders in it. Then read it against what the level is called. If your system can produce the inverse — for each person, every door they can currently open — that view is even more revealing, and it is the one to put in front of a manager.
What normal looks like. Membership that matches the name. The people in "Server Room" are the people who should be in the server room. Most staff sit in one or two levels.
What the finding usually means. This is the report that finds privilege creep, and it is the one that surprises owners most, because nothing on it looks wrong until you total it up.
The mechanism is simple and entirely innocent. Someone covers a role temporarily and is added to a level. The coverage ends; the membership does not. Someone moves from one department to another and is added to the new department's access without being removed from the old. A manager asks for a staff member to be given access to a storage area for a project that finished two years ago. Every single one of those additions was correct on the day it was made. Nobody ever removes anything, because removal requires someone to notice, and noticing is exactly what nobody is assigned to do.
The result is a workforce where a meaningful share of people can open doors they have no current reason to open, and the organization's own view of its access control is optimistic in a way it cannot detect from the inside.
Again — and this is the point of the whole article — the finding is drift, not misconduct. The people on that list did not do anything. The system simply has no mechanism for forgetting, and the organization never supplied one. The remedy is an annual review where each level's membership is read by whoever owns that space, and anything unexplained is removed. It takes an afternoon and it is the single most effective access control exercise available to a building that already has the system installed.
What to actually do
Run the credential-idle report first, because it finds something in almost every building and it is the easiest to act on. Add the after-hours report next quarter, and expect it to teach you things about your own site. Put held and forced open on the same cycle as your door maintenance, since the findings are mostly maintenance findings. Do the access level review once a year, with the managers in the room.
Write down that you are doing all four, why, and who receives the output. That document is your purpose statement under the Act, your handover note for whoever replaces you, and — not least — the reason the reports keep getting run after the person who started running them has moved on.
Your system has been collecting this information the whole time. Four reports is what it takes to make it worth having.
