What a mobile credential actually is
A mobile credential replaces the card or fob in your pocket with a digital credential on your phone, presented to the door reader over NFC or Bluetooth — either from a dedicated app or from the phone's wallet. To the access control system it is just another credential: the doors, schedules and permissions work the same way. What changes is the logistics of issuing, carrying and revoking it.
The major access platforms — HID on the credential side, and systems such as Gallagher and Inner Range — all offer mobile credential options. The concept is mainstream; the details of licensing and reader compatibility are where the decisions live.
Where mobile is genuinely better
- New starters. A credential can be issued to a phone before someone's first day — no card printing, no waiting for the one person who knows how to run the badge machine.
- Leavers and lost credentials. Revocation is immediate and remote. No chasing plastic out of a departed employee, no window where a lost card still opens the door unnoticed.
- Visitors and contractors. Temporary credentials can be issued and expired without a drawer of loan cards that never come back.
- No card logistics. No printer, no ribbon, no stock, no reorder cycle, no drawer of unreturned cards of unknown status — a small ongoing overhead that quietly disappears.
- People actually carry their phones. Cards get left at home and shared at the door. Phones rarely do either, and a phone credential usually sits behind the phone's own lock.
The honest limitations
- Platform lock-in. Mobile credentials tie you to a vendor's ecosystem and, usually, to ongoing per-credential licensing. Moving platforms later means re-issuing every credential. This is the biggest long-term cost of the decision, and the least discussed at sale time.
- BYOD questions. Putting a work credential on personal phones raises questions someone has to answer: what happens when a phone is replaced, whether staff can be required to use their own device, and who supports it when the app misbehaves. None are hard; all need deciding before rollout, not after.
- Flat batteries and dead phones. Less of a problem than folklore suggests — some wallet-based credentials can work with the phone nearly flat — but the failure mode exists, and reception needs a plan for it.
- Not everyone, not everything. Some staff won't or can't use a personal phone; shared devices, cleaners' access and lift readers in some buildings still favour cards. Assume a mixed fleet.
- Reader compatibility. Older readers may not support mobile at all. If the rollout quietly requires replacing every reader in the tenancy, that is the real project — the credentials are the easy part.
The realistic end state: both
Framing this as cards versus phones is mostly a sales framing. In practice, offices that adopt mobile credentials run both: phones as the everyday default, cards for visitors, contractors, exceptions and anyone the mobile scheme doesn't fit. Modern readers handle both at once, so the decision is not either/or — it is what the default is, and how the exceptions are handled.
The useful question is therefore not "should we go mobile?" but "what does mobile-first change about how we issue, revoke and support credentials — and are we set up for that?"
What to ask before committing
- How are credentials licensed? Per credential, per user, one-off or recurring — and what happens to licences when someone leaves. Get the model in writing and project it over the life of the lease.
- Which of our existing readers support it? Reader by reader, not "generally compatible". The answer determines whether this is a software change or a hardware project.
- Wallet or app? Credentials in the phone's wallet behave differently from app-based ones — in convenience, in what staff must install, and in what happens with a flat battery. Know which you are buying.
- What is the leaver and lost-phone process? Walk through both scenarios with the vendor before signing, and make sure whoever administers your system can do them without a support ticket.
- What is our BYOD position? Decide — and tell staff — whether work credentials go on personal phones, what the alternative is for those who decline, and who supports the app.
- What happens if we change platforms in five years? The answer tells you how locked in you really are. A vendor who answers it plainly is telling you something good about themselves, too.
The short version
Mobile credentials genuinely fix the annoying parts of card management — issuing, revoking, and the endless logistics of plastic. They are worth it for most offices with staff turnover and visitors. But go in with eyes open on licensing, reader compatibility and BYOD, plan for a mixed fleet rather than a card-free utopia, and make the vendor answer the exit question before you sign.