← Physical Security Engineering Studio
Concept Explainer · Physical Security

Access Control vs. Intrusion Detection

The same door, the same door contact sensor, and two systems that watch it for two completely different reasons — one running every second of every day, the other switched on and off like a light.

Clients and even some junior technicians routinely lump these together as "the alarm system." They aren't the same system, and they don't even ask the same question. Access control is a continuous, always-active system: at every door, every second, it evaluates whether the person trying to pass is permitted to pass, and grants or denies in real time — occupied or empty, 9am or 3am, it never stops running that evaluation. Intrusion detection is an armed/disarmed-statesystem: it only cares whether the space is currently supposed to be occupied at all. When armed, any motion, any broken window, any door that opens is treated as evidence that someone is present where no one should be. Same building, sometimes the exact same physical devices — but one system is asking "are you allowed through this door," and the other is asking "should anyone be in here right now."

The Setup

A permission engine, and an occupancy alarm

Access control exists to manage passage. A reader captures a credential, the panel checks it against a permission list and a time schedule, and the door unlocks or stays locked — a decision made fresh every single time, whether it is the first badge-in of the morning or the last one before the lights go out at midnight. It has no concept of "armed" or "disarmed"; it is simply always evaluating. Intrusion detection exists to answer a completely different question: is anyone in this space right now who shouldn't be? It does that by watching motion sensors, glass-break detectors, and door/window contacts — but only while armed. The same door contact that access control's panel ignores all day (because doors opening and closing during business hours is expected and normal) becomes, the instant the intrusion system is armed after closing, the trigger for a full alarm. It is the identical piece of hardware reporting the identical "door opened" event to two different logic engines that interpret it in opposite ways.

Same door, same contact — two states, opposite outcomes

State comparison
OCCUPIED HOURS — ACCESS CONTROL ACTIVEbadge holderREADERdoorcontactDOORACCESS CONTROLPANELcontinuous evaluationcredential presentedverify →unlockDPS reports "open" — ignoredGRANT / DENY — every badge, all dayRuns continuously whether the building isbusy or empty. No armed/disarmed state.Intrusion system: DISARMED — occupancy expectedAFTER HOURS — INTRUSION DETECTION ARMEDdoorcontactSAME DOORdoor opens(any cause)INTRUSIONPANEL — ARMEDstate-based watchcontact breaks →reported as intrusionALARMSame contact, same door —now treated as a breach.Access control: still running, but nobody expected here nowOne physical device. Two logic engines. Opposite verdicts on the identical event.
Access control
continuous — evaluates every passage event
No armed/disarmed concept. Runs the identical permission check at 9am and at 3am.
Intrusion detection
state-based — only watches while armed
The same sensor event means nothing while disarmed and everything the moment it's armed.

Four scenarios, one door — why the two systems can disagree

Because the two systems run on entirely different logic, the same door event can produce four genuinely different outcomes depending on the time of day and whether a valid credential is involved. Notice that a valid credential and an armed intrusion system are not mutually exclusive — a badge that access control still considers valid can open a door while intrusion detection, unaware of anything except the time-of-day state, treats the opening as a breach.

Decision logic: two independent systems, one door

4 scenarios
Scenario
Access control
Intrusion detection
Result
Valid badge, business hours
Grants passage
Disarmed
Enter, no alarm
Still-valid badge, 3am, armed
Grants passage
Armed — contact breaks
Enters AND alarms
Forced door, business hours
Denies / forced-door flag
Disarmed
Access control alarm only
Forced door, 3am, armed
Denies / forced-door flag
Armed — contact breaks
Both systems alarm
Why this works

Access control asks "who," intrusion detection asks "when"

Access control's question is entirely about identity and permission: does this credential belong to someone allowed through this door, right now, per their schedule? It answers that question continuously, with no separate on/off mode — it is running the exact same evaluation whether the lobby is full of employees or it's 3am and the building is empty. Intrusion detection's question has nothing to do with identity at all: is the space currently in a state where nobody should be moving through it? That question only gets asked while the system is armed. This is why row two of the table above is not a contradiction — a still-active credential and an armed intrusion system are two entirely independent judgments running on two independent clocks, and a person can pass one check while tripping the other, because neither system was ever designed to answer the other's question.

Common misconception
"Access control and intrusion detection are basically the same alarm system, so installing one makes the other redundant."

False, and the gap it leaves is a real one. A building can have excellent access control — every door reader-controlled, every credential logged, every schedule enforced — and zero intrusion detection. In that building, an ex-employee whose badge was never deactivated can walk in at 3am, and nothing alarms at all: access control grants the passage exactly as it's designed to, and with no intrusion system installed, there is no second layer asking whether anyone should be there in the first place. The reverse gap is just as real: a building can have an excellent intrusion detection system — motion sensors, glass-break detectors, contacts on every opening — and no access control whatsoever, meaning during business hours literally anyone can walk through an unlocked door, because intrusion detection is disarmed all day and was never built to evaluate who is entering. They are not the same system wearing two names. They are two independent systems that happen to often share physical devices like a door contact, built to answer two different questions, and neither one's presence substitutes for the other's absence.

Related Concept Explainers
REX vs. Door Position Switch
Read it →
Detection, Verification & Assessment
Read it →

Access Control vs. Intrusion Detection — Concept Explainer

Explains why access control and intrusion detection are not the same alarm system, but two independent systems built to answer two different questions at the same door: access control is a continuous, always-active permission engine that grants or denies passage in real time regardless of occupancy, while intrusion detection is an armed/disarmed-state system that only interprets sensor events — including the same door contact access control ignores all day — as a potential breach while the space is armed.

What Access Control Actually Evaluates

Access control is a continuous permission system. At every controlled opening, a reader captures a credential and the panel checks it against a permission list and a time schedule, then grants or denies passage — a fresh decision made every single time, all day, every day. It has no armed or disarmed mode; there is no state where access control simply stops running its evaluation. A valid badge presented at 9am and the identical valid badge presented at 3am are evaluated by the exact same logic, because access control was never designed around a notion of "the building should be empty right now" — it was designed around "is this specific credential permitted through this specific door at this specific time."

What Intrusion Detection Actually Evaluates

Intrusion detection is a state-based occupancy system. It watches motion sensors, glass-break detectors, and door/window contacts, but it only interprets what they report through the lens of whether the system is currently armed or disarmed. While disarmed — typically during expected occupied hours — a door opening, a person walking past a motion sensor, or a window being opened are all treated as normal activity and generate no alarm. The instant the system is armed — typically after hours, when the space is supposed to be unoccupied — those same sensor events are reinterpreted as potential evidence of an intrusion, because the underlying assumption has flipped from "people are expected here" to "nobody should be here."

Why the Same Door Contact Behaves Differently Under Each System

A door contact (or door position switch) is a simple physical-state sensor: it reports open or closed, nothing more. Access control's logic largely ignores that report during expected occupied hours — people opening and closing doors all day is exactly what's supposed to happen, so the contact's state isn't treated as an alarm condition. Intrusion detection, once armed, treats the identical contact opening as exactly the kind of evidence its entire purpose is built around: an opening that shouldn't be happening right now. The device hasn't changed at all. What changed is which logic engine is listening to it, and what assumption that engine is currently operating under.

Why a Valid Credential Doesn't Prevent an Intrusion Alarm

Because access control and intrusion detection run on independent clocks, a credential that access control still considers valid can pass its check while simultaneously tripping an armed intrusion system — the two systems are not, by default, cross-checking each other's state. An ex-employee's badge that was never deactivated, or a current employee arriving before an integrated disarm schedule takes effect, can unlock a door through access control's logic and still have that same door opening reported as a breach by intrusion detection, precisely because the intrusion panel has no visibility into who badged in — only that the space is armed and a contact just opened. Properly integrated systems can bridge this gap (an access-granted event can automatically disarm a specific zone), but that bridge is an added integration, not something either system provides on its own by default.

Why Installing One Never Makes the Other Redundant

A building with excellent access control and no intrusion detection has no layer watching for occupancy at all outside of the credential check itself — a still-valid badge, a cloned credential, or someone who simply follows an authorized person through a door (see piggybacking and tailgating) faces no additional resistance once past the reader, at any hour. A building with excellent intrusion detection and no access control has no layer restricting who can walk through an unlocked door during the hours the system is disarmed — anyone can enter during business hours, because intrusion detection was never built to check identity or permission in the first place. Each system closes a gap the other cannot, which is exactly why facilities that take security seriously deploy both, deliberately, rather than treating either as a substitute for the other.

Frequently asked questions

Can access control and intrusion detection be integrated so a badge-in automatically disarms the alarm?

Yes — this is a common integration, sometimes called "access-to-alarm" or zone-level auto-disarm, where a valid access-granted event for an authorized user automatically disarms the intrusion system for that zone or the whole panel. It is a deliberate integration layered on top of two otherwise independent systems, not a default behavior either system provides on its own, and it typically requires both systems to share a common platform or a dedicated integration point.

If a building only has intrusion detection and no access control, is that a security gap?

Yes, specifically during the hours the intrusion system is disarmed. Intrusion detection provides zero restriction on who can walk through an unlocked door while the space is occupied and the system is disarmed — it was built to detect unauthorized presence during unoccupied hours, not to manage who is permitted through a door at any time. A facility relying on intrusion detection alone has no credential-based control over daytime access at all.

Does a door contact sensor "belong" to access control or to intrusion detection?

Often neither exclusively — the same physical door contact is frequently wired to report to both systems, or to a shared panel that feeds both logic engines. It is one sensor answering one question (is this door open or closed) that gets consumed by two different downstream systems, each applying its own interpretation depending on whether it is evaluating permission (access control) or occupancy state (intrusion detection).

Why doesn't intrusion detection just check the access control log before alarming?

Some integrated systems do exactly this, suppressing an alarm when a valid access-granted event immediately precedes a door contact opening. But a large number of intrusion detection deployments are not integrated with access control at all — they are separate panels, sometimes from different vendors, installed at different times, with no shared data path. In that far more common unintegrated case, the intrusion panel has no way to know a credential was even presented; it only knows its own armed state and what its own sensors just reported.

Is an armed intrusion system the same thing as a locked door?

No. A door can be locked by access control (fail-secure hardware, no valid credential presented) while the intrusion system is disarmed, and a door can be unlocked by access control (during occupied hours, or via a REX/free-egress device) while the intrusion system is separately armed or disarmed. Locked/unlocked is access control's state for a specific opening; armed/disarmed is intrusion detection's state for a zone or the whole facility. They are independent variables that happen to interact at the same door.

What happens if the intrusion system is armed but someone with a valid badge is still working late?

Depending on the installation, this typically produces either a false alarm (if the systems aren't integrated) or requires the occupant to manually disarm the intrusion panel — often via a keypad and a separate PIN — before or immediately after entering, precisely because access control granting passage and intrusion detection being armed are two independent facts that the occupant, not the system, has to reconcile unless an integration exists to do it automatically.

🎓

Try our Physical Security Studio

More calculators, simulators, and guides for this discipline.

Related tools & guides

REX vs. Door Position Switch — Concept ExplainerDetection, Verification & Assessment — Concept ExplainerAccess Control System DesignerIntrusion Detection Zone Layout