Why this page exists
Access-control installation for new construction is shaped by how the space is used, not just by the service itself. New construction bring their own operating constraints, and this page pairs what access-control installation actually involves with what that environment changes about it.
An access-control system manages who may open which door and when, and records each attempt. The immediate operational benefit over keys is revocation: a lost credential is disabled in seconds instead of prompting a rekey. The secondary benefit is the audit record, which turns 'who was here on Saturday' into a query rather than a guess.
One window, and it does not reopen
Low-voltage rough-in happens in a specific slot: after framing and electrical, before insulation and drywall. Inside that window, running a cable anywhere is straightforward. Once drywall goes up, the same cable costs many times more and sometimes cannot be run at all.
The asymmetry is the whole story of new-construction low voltage. Decisions made cheaply during rough-in become expensive or impossible afterwards, which is why the pre-rough-in planning conversation is worth more than any equipment choice made later.
- Rough-in window sits between electrical and drywall
- Upstream delays compress the window without extending the deadline
- Post-drywall changes cost many times more, if they are possible at all
- Finish work happens months later, after paint and ceilings
What access-control installation usually involves
Most operational access-control problems come from doors, not from software. A door that does not close fully leaves a held-open alarm that people learn to ignore. A misaligned strike causes intermittent failures that get blamed on credentials. A magnetic lock installed without correct release arrangements is a genuine safety issue rather than an inconvenience.
The second cluster is administrative. Credentials issued to people who left, shared credentials that make the audit log meaningless, and no defined process for issuing or revoking access all erode the value the system was installed to provide.
- Door closers and alignment causing intermittent latch failures
- Held-open alarms so frequent they get ignored
- Credentials never revoked when someone leaves
- Shared credentials making the audit trail unusable
- Request-to-exit devices missing, misaligned, or not covering the approach
- Controllers installed on the unsecured side of the door they control
What to rough in even without a final design
Full system design is often not finished when the rough-in window arrives. That is normal, and it is not a reason to skip the pathway. Running conduit or sleeves to likely positions preserves the option cheaply even when the eventual equipment is undecided.
For a commercial building, the reliable rough-in set is: cable to every likely device outlet, ceiling positions for access points spaced for the intended coverage, camera positions at entries and approaches, door positions with cable to the controller location, and pathway to any likely display or AV position. Plus, in every case, a properly located equipment room.
The equipment room deserves particular emphasis because it is the most commonly under-provisioned item. It has to hold the network rack, camera recorder, access-control panel, and any AV equipment, with dedicated power, ventilation, and clearance to work. Sizing it from the network alone is a decision that gets discovered eighteen months later.
- Sleeves and conduit to likely positions even before final design
- Ceiling access-point positions spaced for the intended coverage
- Camera positions at entries, approaches, and service areas
- Cable from every controlled door to the controller position
- Equipment room with dedicated power, ventilation, and working clearance
Locks, egress, and where the controller belongs
Electric strikes and magnetic locks behave oppositely on power loss. A magnetic lock is fail-safe — it releases when power is removed, so the door is passable during an outage or alarm. A standard electric strike is typically fail-secure — it stays locked without power, though the door can still be opened from the inside by its mechanical hardware. Which is appropriate depends on the door's role and on the applicable life-safety requirements, and it is not an interchangeable preference.
- Magnetic locks fail safe on power loss; standard electric strikes fail secure
- Free egress must be preserved by mechanical hardware and request-to-exit devices
- Fire-alarm interface required where controlled doors must release on alarm
- Controller and wiring on the secured side of the door
- Prefer modern encrypted or mobile credentials over legacy proximity formats
- Door position sensors to detect held-open and forced conditions
Frequently asked questions
What changes about access-control installation in new construction?
The operating environment does. New construction bring specific constraints — how the space is used, when work can happen, and what has to keep running — and those shape the access-control installation plan as much as the service's own technical requirements.
What is the difference between fail-safe and fail-secure?
It describes what happens when power is lost. Fail-safe hardware — typically a magnetic lock — releases and the door becomes passable. Fail-secure hardware — typically a standard electric strike — stays locked, though the door can still be opened from the inside by its mechanical hardware. Which is correct for a given opening depends on its role and on applicable life-safety requirements, so it is a design decision rather than a preference.
What has to be decided before rough-in?
Device locations, the equipment room position, and the pathway plan. Equipment selection can wait — you can run cable to a position without knowing which camera or access point will go there. What cannot wait is the decision about where things go, because that is what determines where cable is pulled while the walls are open.




