Access Control — codes that open the door even when the internet is down

Access Control is your org's door-code surface, at Access Control (/access). It does one job and does it reliably: someone enters a code, and the door grants or denies them — instantly, on the device, even during an internet outage. Every entry is logged. Turn it on from the module directory; then you get two tabs, Keypad and Codes.

Verifying a code at the keypad:
1. Open the Keypad tab.
2. Enter the access code and tap Verify (or press Enter).
3. You get a clear verdict: Access granted or Access denied. If a code has a label, it shows whose code it was; a denial shows the reason.
4. Under the verdict, a small line tells you how it was decided: Verified online, Verified on-device, or No match.

It fails safe, not soft:
Unlike a ticket check-in, a lock denies anything it does not recognize. An unknown, expired, or revoked code is denied — offline included — full stop. Security beats convenience at a door, so there is no provisional "let them in and sort it out later" at the keypad.

The status line at the top:
Above the tabs, a colored dot and a short line tell you the current state. Green means you are online. Amber means you are offline and verifying on this device against the codes cached on it (it shows how many). When you reconnect, it shows any queued entries syncing, and a small "to review" badge appears if any offline decision needs a second look (see the offline article).

Where codes come from:
You add and revoke codes on the Codes tab — see "Adding and revoking access codes". Every verification, grant or deny, is recorded and reconciled with the server so you have a complete, defensible access log.