One RFID Card For Access Control And Attendance: ID/IC Mapping And Rollout Checklist
Oct 10, 2026
Leave a message

A company can issue one RFID badge to every employee and still end up with two conflicting identities: one number enrolled at the door and another number expected by the time clock. The badge may work at the entrance but fail to record attendance, or the clock may accept it while the access-control system shows an unknown credential.
Solving this requires more than choosing between an "ID card" and an "IC card." Define a stable person record, identify what each reader outputs, map every authorized credential to that person, and test access and attendance as separate business events.
This guide is for facilities managers, HR and IT teams, integrators, and organizations issuing RFID cards for both doors and time-and-attendance. It covers identity mapping, common failure conditions, acceptance tests and purchase specifications rather than another general card comparison.
One Badge Does Not Automatically Mean One Credential Number
In some markets, "ID card" means a basic 125 kHz proximity credential, such as certain fixed-identifier EM-series cards, and "IC card" means a 13.56 MHz contactless smart card. These are informal market labels, not universal technical classifications. Both products contain an integrated circuit. In other contexts, an IC card may also be a contact smart card.
The relevant question for employee badging is which credentials the actual door and time-clock readers support. A 125 kHz-only reader cannot read a 13.56 MHz-only credential merely because both use a PVC card body. A compatible-frequency HF reader might detect a smart card but still be unable to use its required application or credential format.
For the broader technology and purchasing comparison, Syntek's IC card vs ID card guide handles that decision. This page focuses on making a badge work consistently across two operating systems.
Separate the Person, the Physical Card and the System Credentials
A workable dual-use system contains several different records. Treating them as interchangeable causes problems when someone changes departments or loses a badge.
| Record | Meaning | Administrative control |
|---|---|---|
| Workforce person ID | The employee or approved contractor | HR or authoritative identity service |
| Physical badge inventory ID | The actual card issued from stock | Credential administrator |
| Door credential | The value or authenticated application accepted by the access system | Access-control administrator |
| Attendance credential | The value recognized by the time clock | Attendance administrator |
Door and attendance identifiers can sometimes be the same technical value. They can also differ in byte representation, length, application or even RF technology. Neither outcome should be assumed from an image or printed number on the card.
A stable design follows one person → one or more authorized credential references → independent door and attendance permissions. Replacing the card should not create a second employee record.

Inventory Both Reader Populations Before Ordering Cards
Many buildings have newer main-door readers and older attendance terminals. Get the manufacturer, model and relevant configuration of each materially different reader type.
| Check | Access reader | Attendance terminal |
|---|---|---|
| RF support | Which exact LF/HF card families and protocols? | Which credential technologies are accepted? |
| Credential source | UID, formatted number or authenticated application? | Card ID, employee number or application data? |
| Representation | Bit layout, site code, card number, number base? | Which value appears during enrollment? |
| Connection | Reader-to-controller interface and policy? | Local storage, server sync or separate integration? |
| Offline rule | How does the door operate without connectivity? | Are punches buffered or handled manually? |
| Administration | Who revokes access rights? | Who updates mapping and corrects punches? |
Use a known-good authorized card on a representative unit of each device family. Capture the value as shown in the authorized application, preserve leading zeros and document decimal or hexadecimal representation. Do not assume the printed card number is what the controller stores.
Why the Same Badge Can Show Two Different Numbers
Reader firmware may extract part of a chip identifier, apply a card format, reverse byte order, or display a converted number. A modern smart-card implementation may instead authenticate and retrieve a credential value from a protected application.
For example, a door system may store DOOR_TOKEN_A and an attendance system may register CLOCK_TOKEN_B. Both symbolic references can belong to PERSON_RECORD_1. They need a controlled association, not an invented rule that forces them to equal the employee's HR number.
Where a facility code and card-number range are used, document that layout and validate the resulting output. Two systems listing "26-bit" support are not necessarily configured to interpret identical credential fields.
Pick a Technology Architecture That Fits the Installed Systems
| Approach | Potential fit | What must be checked |
|---|---|---|
| Existing LF credential | Both devices already accept the same legacy low-frequency type | Continues existing functionality; does not create a cryptographic upgrade |
| One HF credential | Both systems support the chosen contactless smart-card technology | Chip family, reader support, application, key management and data field |
| Dual-technology card | Door and clock populations must coexist during a controlled transition | Each chip and identifier must be tested and mapped separately |
NXP MIFARE DESFire EV3 has cryptographic and multi-application capabilities, but those features are available only when the supporting reader, keys and application are correctly configured. Reading a public UID on a capable chip is not equivalent to authenticating protected credential data.
For card sourcing and construction options, Syntek's RFID card category is the commercial destination. This guide does not replace the product page's buying task.
Create an Approved Mapping Registry Before Mass Enrollment
The relationship between staff and badges needs one accountable owner and an audit history. A controlled credential registry can live in a credential-management platform or an approved integration. Avoid relying on an unversioned spreadsheet emailed between facilities and HR.
| Registry field | Use |
|---|---|
| Workforce person reference | The stable business identity |
| Card inventory reference | The particular piece of plastic issued |
| Card technology and chip profile | Clarifies which device population can use it |
| Door credential reference | Supports access enrollment and diagnostics |
| Attendance credential reference | Maps time-clock events to the correct person |
| Encoding and data-format rule | Explains identifier transformations and source |
| Issue / revocation state | Shows whether the card may still be used |
| Effective and expiry dates | Supports onboarding and contractor limits |
| Reader verification | Documents which devices accepted the test card |
| Change approval | Records who authorized reissue or correction |
Keep employee personal information and payroll details in protected business systems rather than putting them on the credential simply because a writable chip offers memory. Limit mapping-file sharing to authorized administrators.
Access Events Are Not Attendance Events
An authorized door opening is not necessarily a valid work-time punch. Someone may enter a building to collect equipment, move between sites or escort a visitor. A time-clock punch may be valid without corresponding door activity.
- Access application: determines whether the enrolled credential has permission at a door and time.
- Attendance application: receives clock-in, clock-out and exception events under the organization's policies.
- HR / payroll process: validates schedules, corrections and hours-worked records independently.
If the business wants one tap to generate both events, the integration must explicitly create and validate both. A door reader's log entry alone should never be assumed to prove hours worked.
Use Dual-Technology Cards Only With a Planned End State
A phased deployment can have old 125 kHz readers at attendance stations and new 13.56 MHz readers at doors, or the reverse. A physical badge containing two technologies can bridge the gap if both credential systems support the actual chip combination.
That card may expose two different electronic identifiers. Each must be linked to the same authorized person and verified on the correct device. HID offers multiCLASS technology-migration information; practical compatibility still depends on the installed reader configuration and access platform.
Set a date or explicit condition for retiring legacy acceptance. A modern cryptographic card is of limited security value if its older fixed-ID side remains an accepted credential indefinitely without an approved business need.
Test the Reader-to-Controller Connection as a Separate Layer
Diagnose failures in sequence. If the reader does not detect the badge, investigate frequency, protocol and supported credential family. If the reader reacts but the access software denies entry, inspect its output format, mapping, user permissions and controller policy.
The reader-to-controller link is separate from the card interface. The Security Industry Association's OSDP checklist addresses deployment and security verification of OSDP-based connections. OSDP and legacy Wiegand describe component communications; neither by itself guarantees that a given ID or IC card works with the reader.
Card procurement should not be used as shorthand for a reader/controller security upgrade. Document such infrastructure changes as their own approved project work.
Acceptance Tests Should Follow the Whole Employee Lifecycle
One successful door swipe and one successful clock-in cannot prove a complete implementation. Test how each system behaves after normal and exceptional workforce events.
| Scenario | Door-access check | Attendance check |
|---|---|---|
| New hire | Access starts at the authorized time and doors | Badge maps to the correct workforce person |
| Contractor expires | Permissions end as required | Clocking eligibility follows the contractor policy |
| Lost badge | Old credential is revoked | Old attendance identifier is disabled as appropriate |
| Badge replaced | New credential works, original no longer grants access | New identifier belongs to original person; history remains |
| Department transfer | Door rights change | Identity and work records stay attached to the same person |
| Employee leaves | Every issued credential reference is reviewed for revocation | Clocking stops while retained records follow policy |
| Network interruption | Offline access follows controller policy | Buffered/manual clocking follows attendance policy |
Some platforms synchronize identity and credential status. Others require separate administrative actions. Confirm the behavior in documentation and a controlled pilot rather than promising automatic updates.
Prevent Replacement Cards From Creating Parallel Active Identities
Replacement creates a specific risk: the door administrator enrolls a new badge while the time-clock administrator leaves the old one active. Both cards may then appear valid in one or both databases.
- Look up the authoritative workforce person record.
- List active door and attendance credential references for that person.
- Record why the physical badge was replaced and whether it was returned.
- Enroll and test the new card references using approved procedures.
- Revoke the old references in every relevant system.
- Confirm the retired credential is denied where required.
- Keep the mapping and change history; preserve the person's prior attendance records.
Physical recovery and electronic revocation are different states. A missing badge can be disabled; a returned badge may still be technically authorized until access permissions are actually removed.

Pilot a Complete Shift, Not Just Two Reader Demonstrations
Run the pilot on the exact reader models and backend applications expected in production. Use approved non-sensitive test data, and include security, HR and the integrator in the acceptance process.
- Baseline: capture how a known-good badge behaves at representative doors and time clocks.
- Enrollment: issue a sample card and record its technical identities and workforce mapping.
- Access: verify allowed and intentionally denied door transactions, including different reader models.
- Attendance: verify clock-in and clock-out events appear under the right person record.
- Exceptions: test unknown numbers, conflicting mappings, expiry and an intentionally revoked credential.
- Replacement: issue a new sample and ensure both systems retire the previous identity.
- Reconciliation: compare audit logs and exception queues before approving batch production.
The business must decide its own acceptance thresholds, such as which failed events block rollout and who can approve an exception. A supplier's statement that a card "reads successfully" is not proof that attendance records and door permissions are correct.

What to Specify in an ID/IC Card Purchase Request
| Request field | What the buyer should supply |
|---|---|
| Applications | Door access, time attendance, or both |
| Reader families | Manufacturer/model and supported technologies for each system |
| Card technology | Required chip and credential families rather than just "ID" or "IC" |
| Credential source | Chip ID, supported application credential or site-defined format |
| Enrollment fields | Expected bit layout, site code, number base and application mapping |
| Dual-tech need | Exact technologies and which application reads each |
| Printing | Approved visible ID, photo or barcode and its relationship to the registry |
| Data handoff | Mapping-file fields, secure transfer and approval owner |
| Sample approval | Actual door and clock acceptance tests |
| Reorder control | Unique identifiers, reference samples, reissue/revocation rules |
A quote rarely needs raw employee rosters, confidential application keys or live production access credentials. Start with reader specifications and authorized test samples, then establish a controlled data-sharing process if personalization is required.
When Keeping Existing ID Cards Makes Sense
If the job is a maintenance reorder and both applications depend on a known-working 125 kHz format, continuity may be the immediate priority. That should not be misrepresented as a security improvement. A separate plan may still be needed to address the risks of fixed-identifier credentials.
If the organization needs authenticated applications or consolidated management across more systems, define compatible readers, credential keys and identity governance before selecting a smart-card chip. For the broader cost and technology decision, Syntek's 125 kHz vs 13.56 MHz access credential cost guide is the appropriate adjacent resource.
The Handoff That Makes One Card Work
Before full rollout, there should be one approved workforce-to-credential mapping rule, one reader-compatibility matrix, one issuance and revocation process, and test records showing that door access and attendance resolve to the same authorized person.
The useful sequence is person record → reader inventory → credential architecture → identifier mapping → sample issue → door test → attendance test → replacement and revocation test → approved batch specification → rollout.
One card is a convenient physical format. Consistent identities and disciplined administration are what make it a dependable shared credential.
Send Inquiry

