One RFID Card For Access Control And Attendance: ID/IC Mapping And Rollout Checklist

Oct 10, 2026

Leave a message

Ruby Chen
Ruby Chen
A product expert specializing in RFID solutions. Ruby focuses on customer service, matching suitable hardware to clients across various industries seeking RFID solutions, and has over 10 years of sales experience.

A company can issue one RFID badge to every employee and still end up with two conflicting identities: one number enrolled at the door and another number expected by the time clock. The badge may work at the entrance but fail to record attendance, or the clock may accept it while the access-control system shows an unknown credential.

Solving this requires more than choosing between an "ID card" and an "IC card." Define a stable person record, identify what each reader outputs, map every authorized credential to that person, and test access and attendance as separate business events.

This guide is for facilities managers, HR and IT teams, integrators, and organizations issuing RFID cards for both doors and time-and-attendance. It covers identity mapping, common failure conditions, acceptance tests and purchase specifications rather than another general card comparison.

 

 

One Badge Does Not Automatically Mean One Credential Number

In some markets, "ID card" means a basic 125 kHz proximity credential, such as certain fixed-identifier EM-series cards, and "IC card" means a 13.56 MHz contactless smart card. These are informal market labels, not universal technical classifications. Both products contain an integrated circuit. In other contexts, an IC card may also be a contact smart card.

The relevant question for employee badging is which credentials the actual door and time-clock readers support. A 125 kHz-only reader cannot read a 13.56 MHz-only credential merely because both use a PVC card body. A compatible-frequency HF reader might detect a smart card but still be unable to use its required application or credential format.

For the broader technology and purchasing comparison, Syntek's IC card vs ID card guide handles that decision. This page focuses on making a badge work consistently across two operating systems.

 

 

Separate the Person, the Physical Card and the System Credentials

A workable dual-use system contains several different records. Treating them as interchangeable causes problems when someone changes departments or loses a badge.

Record Meaning Administrative control
Workforce person ID The employee or approved contractor HR or authoritative identity service
Physical badge inventory ID The actual card issued from stock Credential administrator
Door credential The value or authenticated application accepted by the access system Access-control administrator
Attendance credential The value recognized by the time clock Attendance administrator

Door and attendance identifiers can sometimes be the same technical value. They can also differ in byte representation, length, application or even RF technology. Neither outcome should be assumed from an image or printed number on the card.

A stable design follows one person → one or more authorized credential references → independent door and attendance permissions. Replacing the card should not create a second employee record.

Diagram mapping a single physical RFID employee badge to separate door access and attendance credentials under one person record.

 

 

Inventory Both Reader Populations Before Ordering Cards

Many buildings have newer main-door readers and older attendance terminals. Get the manufacturer, model and relevant configuration of each materially different reader type.

Check Access reader Attendance terminal
RF support Which exact LF/HF card families and protocols? Which credential technologies are accepted?
Credential source UID, formatted number or authenticated application? Card ID, employee number or application data?
Representation Bit layout, site code, card number, number base? Which value appears during enrollment?
Connection Reader-to-controller interface and policy? Local storage, server sync or separate integration?
Offline rule How does the door operate without connectivity? Are punches buffered or handled manually?
Administration Who revokes access rights? Who updates mapping and corrects punches?

Use a known-good authorized card on a representative unit of each device family. Capture the value as shown in the authorized application, preserve leading zeros and document decimal or hexadecimal representation. Do not assume the printed card number is what the controller stores.

 

 

Why the Same Badge Can Show Two Different Numbers

Reader firmware may extract part of a chip identifier, apply a card format, reverse byte order, or display a converted number. A modern smart-card implementation may instead authenticate and retrieve a credential value from a protected application.

For example, a door system may store DOOR_TOKEN_A and an attendance system may register CLOCK_TOKEN_B. Both symbolic references can belong to PERSON_RECORD_1. They need a controlled association, not an invented rule that forces them to equal the employee's HR number.

Where a facility code and card-number range are used, document that layout and validate the resulting output. Two systems listing "26-bit" support are not necessarily configured to interpret identical credential fields.

 

 

Pick a Technology Architecture That Fits the Installed Systems

 

Approach Potential fit What must be checked
Existing LF credential Both devices already accept the same legacy low-frequency type Continues existing functionality; does not create a cryptographic upgrade
One HF credential Both systems support the chosen contactless smart-card technology Chip family, reader support, application, key management and data field
Dual-technology card Door and clock populations must coexist during a controlled transition Each chip and identifier must be tested and mapped separately

NXP MIFARE DESFire EV3 has cryptographic and multi-application capabilities, but those features are available only when the supporting reader, keys and application are correctly configured. Reading a public UID on a capable chip is not equivalent to authenticating protected credential data.

For card sourcing and construction options, Syntek's RFID card category is the commercial destination. This guide does not replace the product page's buying task.

 

 

Create an Approved Mapping Registry Before Mass Enrollment

The relationship between staff and badges needs one accountable owner and an audit history. A controlled credential registry can live in a credential-management platform or an approved integration. Avoid relying on an unversioned spreadsheet emailed between facilities and HR.

Registry field Use
Workforce person reference The stable business identity
Card inventory reference The particular piece of plastic issued
Card technology and chip profile Clarifies which device population can use it
Door credential reference Supports access enrollment and diagnostics
Attendance credential reference Maps time-clock events to the correct person
Encoding and data-format rule Explains identifier transformations and source
Issue / revocation state Shows whether the card may still be used
Effective and expiry dates Supports onboarding and contractor limits
Reader verification Documents which devices accepted the test card
Change approval Records who authorized reissue or correction

Keep employee personal information and payroll details in protected business systems rather than putting them on the credential simply because a writable chip offers memory. Limit mapping-file sharing to authorized administrators.

 

 

Access Events Are Not Attendance Events

An authorized door opening is not necessarily a valid work-time punch. Someone may enter a building to collect equipment, move between sites or escort a visitor. A time-clock punch may be valid without corresponding door activity.

  • Access application: determines whether the enrolled credential has permission at a door and time.
  • Attendance application: receives clock-in, clock-out and exception events under the organization's policies.
  • HR / payroll process: validates schedules, corrections and hours-worked records independently.

If the business wants one tap to generate both events, the integration must explicitly create and validate both. A door reader's log entry alone should never be assumed to prove hours worked.

 

 

Use Dual-Technology Cards Only With a Planned End State

A phased deployment can have old 125 kHz readers at attendance stations and new 13.56 MHz readers at doors, or the reverse. A physical badge containing two technologies can bridge the gap if both credential systems support the actual chip combination.

That card may expose two different electronic identifiers. Each must be linked to the same authorized person and verified on the correct device. HID offers multiCLASS technology-migration information; practical compatibility still depends on the installed reader configuration and access platform.

Set a date or explicit condition for retiring legacy acceptance. A modern cryptographic card is of limited security value if its older fixed-ID side remains an accepted credential indefinitely without an approved business need.

 

 

Test the Reader-to-Controller Connection as a Separate Layer

Diagnose failures in sequence. If the reader does not detect the badge, investigate frequency, protocol and supported credential family. If the reader reacts but the access software denies entry, inspect its output format, mapping, user permissions and controller policy.

The reader-to-controller link is separate from the card interface. The Security Industry Association's OSDP checklist addresses deployment and security verification of OSDP-based connections. OSDP and legacy Wiegand describe component communications; neither by itself guarantees that a given ID or IC card works with the reader.

Card procurement should not be used as shorthand for a reader/controller security upgrade. Document such infrastructure changes as their own approved project work.

 

 

Acceptance Tests Should Follow the Whole Employee Lifecycle

One successful door swipe and one successful clock-in cannot prove a complete implementation. Test how each system behaves after normal and exceptional workforce events.

Scenario Door-access check Attendance check
New hire Access starts at the authorized time and doors Badge maps to the correct workforce person
Contractor expires Permissions end as required Clocking eligibility follows the contractor policy
Lost badge Old credential is revoked Old attendance identifier is disabled as appropriate
Badge replaced New credential works, original no longer grants access New identifier belongs to original person; history remains
Department transfer Door rights change Identity and work records stay attached to the same person
Employee leaves Every issued credential reference is reviewed for revocation Clocking stops while retained records follow policy
Network interruption Offline access follows controller policy Buffered/manual clocking follows attendance policy

Some platforms synchronize identity and credential status. Others require separate administrative actions. Confirm the behavior in documentation and a controlled pilot rather than promising automatic updates.

 

 

Prevent Replacement Cards From Creating Parallel Active Identities

Replacement creates a specific risk: the door administrator enrolls a new badge while the time-clock administrator leaves the old one active. Both cards may then appear valid in one or both databases.

  1. Look up the authoritative workforce person record.
  2. List active door and attendance credential references for that person.
  3. Record why the physical badge was replaced and whether it was returned.
  4. Enroll and test the new card references using approved procedures.
  5. Revoke the old references in every relevant system.
  6. Confirm the retired credential is denied where required.
  7. Keep the mapping and change history; preserve the person's prior attendance records.

Physical recovery and electronic revocation are different states. A missing badge can be disabled; a returned badge may still be technically authorized until access permissions are actually removed.

RFID badge replacement desk showing old and new cards and separate access and attendance status reconciliation.

 

 

Pilot a Complete Shift, Not Just Two Reader Demonstrations

Run the pilot on the exact reader models and backend applications expected in production. Use approved non-sensitive test data, and include security, HR and the integrator in the acceptance process.

  1. Baseline: capture how a known-good badge behaves at representative doors and time clocks.
  2. Enrollment: issue a sample card and record its technical identities and workforce mapping.
  3. Access: verify allowed and intentionally denied door transactions, including different reader models.
  4. Attendance: verify clock-in and clock-out events appear under the right person record.
  5. Exceptions: test unknown numbers, conflicting mappings, expiry and an intentionally revoked credential.
  6. Replacement: issue a new sample and ensure both systems retire the previous identity.
  7. Reconciliation: compare audit logs and exception queues before approving batch production.

The business must decide its own acceptance thresholds, such as which failed events block rollout and who can approve an exception. A supplier's statement that a card "reads successfully" is not proof that attendance records and door permissions are correct.

Facilities administrator testing the same RFID employee card at a door reader and a separate attendance terminal before rollout.

 

 

What to Specify in an ID/IC Card Purchase Request

Request field What the buyer should supply
Applications Door access, time attendance, or both
Reader families Manufacturer/model and supported technologies for each system
Card technology Required chip and credential families rather than just "ID" or "IC"
Credential source Chip ID, supported application credential or site-defined format
Enrollment fields Expected bit layout, site code, number base and application mapping
Dual-tech need Exact technologies and which application reads each
Printing Approved visible ID, photo or barcode and its relationship to the registry
Data handoff Mapping-file fields, secure transfer and approval owner
Sample approval Actual door and clock acceptance tests
Reorder control Unique identifiers, reference samples, reissue/revocation rules

A quote rarely needs raw employee rosters, confidential application keys or live production access credentials. Start with reader specifications and authorized test samples, then establish a controlled data-sharing process if personalization is required.

 

 

When Keeping Existing ID Cards Makes Sense

If the job is a maintenance reorder and both applications depend on a known-working 125 kHz format, continuity may be the immediate priority. That should not be misrepresented as a security improvement. A separate plan may still be needed to address the risks of fixed-identifier credentials.

If the organization needs authenticated applications or consolidated management across more systems, define compatible readers, credential keys and identity governance before selecting a smart-card chip. For the broader cost and technology decision, Syntek's 125 kHz vs 13.56 MHz access credential cost guide is the appropriate adjacent resource.

 

 

The Handoff That Makes One Card Work

Before full rollout, there should be one approved workforce-to-credential mapping rule, one reader-compatibility matrix, one issuance and revocation process, and test records showing that door access and attendance resolve to the same authorized person.

The useful sequence is person record → reader inventory → credential architecture → identifier mapping → sample issue → door test → attendance test → replacement and revocation test → approved batch specification → rollout.

One card is a convenient physical format. Consistent identities and disciplined administration are what make it a dependable shared credential.

Send Inquiry