What Happens to Your Office Doors When the Internet or Power Goes Out?

An access control power outage sounds like one failure. It is usually several different questions hiding in the same sentence. Did the internet fail? Did the management console stop? Did a switch or cable break the local path? Did the door hub lose power? Or did the lock itself lose power?
Those events can produce different results at the same door. The badge a staff member already carries may still work during one outage while a new mobile credential, remote unlock command, or schedule change does not. A building-wide power failure adds the lock hardware and life-safety design to the answer.
The only honest way to know is to map each door, document its dependencies, and validate the approved design in a controlled maintenance window.
An access control power outage is not an internet outage
Cloud access and local door decisions are separate paths on many modern systems. In UniFi Access, for example, Ubiquiti says credentials already synchronized to the Access Control Hub are stored locally. Those synced credentials can continue to unlock while the console malfunctions or loses internet, as long as the reader, hub, lock, and required local connections remain operational.
There is an important limit. Ubiquiti also says a new credential cannot take effect until it reaches the Access backend and synchronizes to the hub. So an employee's existing card may work while an access change made during the outage waits. That is much more precise than saying "the doors work offline."
Mobile workflows need their own test. Ubiquiti documents local mobile unlock and remote unlock as different paths: local mobile unlock uses Bluetooth to reach the reader and hub, while remote unlock sends a command through the Access application. A card, PIN, phone tap, and remote button should never be treated as interchangeable just because they all open the door on a normal day.
Our published UniFi Access and Kisi comparison covers the broader platform decision. For continuity planning, stay at the individual door and credential level.
Trace the local path from credential to lock
Put the system on paper. A typical path includes a credential, reader, access hub or controller, local network, management console, lock relay, lock power supply, and the physical lock. Some parts may share a switch. Others may have separate power and cabling.
Now ask what happens when each link is unavailable. If the internet fails but the local path stays up, a documented local credential may continue. If the reader loses its link to the hub, that same credential may have nowhere to be evaluated. If the hub loses power, the lock moves to whatever state its hardware and approved egress design produce. If only the remote administrator is offline, a person standing at the door may see no problem at all.
This dependency map is also where hidden single points appear. A battery on the recorder does nothing for a door hub powered by an unprotected switch. A backed-up hub does not help a separate lock supply on a normal wall circuit. And a working lock does not help an employee whose only credential depends on a phone service that is unavailable.
Power loss reaches farther than the reader
Power over Ethernet can simplify the system, but the power still starts somewhere. Ubiquiti's current Door Hub specifications for UA-Hub-Door show a PoE++ input feeding the hub, lock relays, and connected devices. If that model is part of the design, the PoE source and every required upstream device belong in the continuity calculation.
Some access hubs support direct battery input. Others rely on a battery-backed power supply or upstream PoE. Ubiquiti's hub-selection guidance says its Enterprise Access Hub supports an external battery, but does not include a charging circuit. That detail is a good reminder that "battery capable" is not the same as a complete, maintained standby-power system.
A proper runtime plan lists the complete load carried by the backup source, any minimum required by the adopted code, listing, approved design, or authority having jurisdiction, and any longer continuity target the business chooses. Then it gets tested and maintained. The general UPS questions are covered in our guide to power protection for a Colorado Springs business. The door plan still has to identify every access component on that backup.
A battery label beside the network rack does not prove the reader, hub, lock, and safe-exit path survive the same outage.
Fail-safe and fail-secure only describe lock-power behavior
In access-control language, the labels are narrow. Ubiquiti's lock-wiring documentation describes fail-safe locks as using power to stay locked and releasing when that power is interrupted. It describes fail-secure strikes as remaining locked without power and requiring power to unlock.
That does not tell you which one belongs on the front entrance, stockroom, server room, clinic suite, or gate. Door use, occupancy, fire protection, panic hardware, accessibility, local amendments, and the direction of egress all matter. Security from the outside and free exit from the inside can be provided by different parts of the same door assembly.
For workplaces, OSHA's exit-route rule says employees must be able to open an exit-route door from inside at all times without keys, tools, or special knowledge. It also says an exit-route door cannot rely on a device whose failure could restrict emergency use.
Local code review still controls the project. Colorado Springs adopted the 2021 International Fire Code with local amendments, according to the city's fire-code adoption page. Pikes Peak Regional Building Department publishes a local interpretation for access-controlled egress doors. Pueblo businesses need the corresponding Pueblo building and fire authorities. The authority having jurisdiction and the project's qualified designers decide the permitted arrangement.
Test the outage plan without defeating a safety system
Do not prove continuity by opening a live enclosure, pulling conductors, unplugging an unknown lock supply, or interfering with a fire-alarm connection. Schedule the test with the access-control installer and facilities lead. Bring in the fire-alarm contractor or code official when an approved releasing interface is part of the door.
Use vendor-supported controls and approved test points in a maintenance window, keep an alternate safe route available, and make sure no occupant can be trapped. The team should agree on the expected result before each simulation and stop if the observed state differs.
A useful failure matrix looks like this:
- Internet unavailable: test each physical credential type, local administration where configured, remote administration, and queued changes.
- Console unavailable: verify only the specific previously synchronized credentials the manufacturer documents for that condition.
- Local network path unavailable: verify the effect of the planned reader-to-hub and hub-to-console loss without assuming they are the same.
- Building power unavailable: record what remains powered, measured standby runtime, exterior lock state, mechanical override, and interior egress operation.
- Approved fire or emergency release input: have the responsible fire-alarm and access-control professionals verify the code-approved release response and uninterrupted egress through the approved test procedure.
- Separate security lockdown input, if present: have the security and access-control professionals verify its approved ingress behavior while confirming that required egress remains available.
- Recovery: confirm pending access changes and event records synchronize, clocks remain correct, and normal schedules resume.
Run the test for the actual front door, back door, controlled interior rooms, and gates. One passing reader does not certify another door with different hardware or power.
Keep a one-page continuity record for each door
Record the door name and purpose, whether it is part of an exit route, lock and reader models, credential types, controller, network path, primary and standby power, approved emergency interface, request-to-exit hardware, mechanical override, last test date, measured result, and support contacts. Store the approved drawings and inspection records with it.
This is part of a complete commercial access-control design, not an afterthought after the first outage. GTZ can map the technology, configure the platform, and coordinate the test with the licensed and life-safety trades responsible for the door assembly.
The answer should fit on one page, door by door. Internet loss, console loss, network loss, and power loss each get their own line. Anything the team cannot state and demonstrate belongs on the open-items list before the system is accepted.
Free Consultation
Questions About Your IT?
Book a free assessment with Efrain. No sales pitch, no obligation.
Get Your Free Assessment