A strong managed access control onboarding process starts before the customer goes live. Confirm the service scope, identify authorized contacts, define customer and dealer responsibilities, train users according to their roles, establish the support process and use structured 30, 60 and 90-day reviews to correct issues before they become long-term service problems.

For security integrators, this is the point where a successful installation becomes a successful managed customer relationship.

Key Takeaways

  • Technical commissioning and customer onboarding are not the same thing.
  • Define who manages users, schedules, support requests and system changes before the account goes live.
  • Train administrators according to what they actually need to do rather than putting everyone through the same session.
  • Establish authorized requestors and support channels before the first urgent change request arrives.
  • Use the first 90 days as a structured adoption period rather than assuming the customer is fully onboarded after training.
  • Track early support requests because they often reveal training gaps, unclear scope or future service opportunities.
  • A Managed Services Dealer model can allow the integrator to concentrate on the customer relationship while partnering for the hosted hattrix infrastructure behind the service.

Why Is Managed Access Control Onboarding Different From System Handover?

A traditional access control project usually has a clear technical finish line.

The system has been installed.

The controllers are communicating.

Credentials work.

Doors operate as intended.

The customer has received basic training.

The job can be considered commissioned.

Managed access control introduces a second question:

Does the customer know how the ongoing service relationship is supposed to work?

That is the purpose of onboarding.

Commissioning establishes that the technology works.

Onboarding establishes how the customer, dealer and managed-service environment will work together after the project team leaves.

Those are different outcomes.

A technically successful system can still create a poor managed-service relationship if:

  • nobody knows who is allowed to request changes
  • employees contact individual technicians instead of the support channel
  • the customer expects services that were not included
  • administrators received the wrong training
  • customer IT does not understand network dependencies
  • too many people have administrator access
  • the dealer never establishes a review process
  • routine support requests consume more time than the monthly fee anticipated

These problems rarely appear during commissioning.

They appear over the following weeks and months.

That is why onboarding should be treated as a process rather than a single handover meeting.

A practical 30-60-90 day framework gives the dealer several opportunities to identify and correct these issues while the account is still new.

It does not mean every managed customer literally requires 90 days of technical onboarding. The technical transition may happen much faster.

The 90-day period is a useful framework for helping the customer establish good habits and giving the dealer enough real-world information to determine whether the managed-service model is working as intended.

What Should Happen Before a Managed Access Control Customer Goes Live?

The best onboarding meeting is one where the basic operating questions have already been answered.

Before go-live, confirm the following.

Customer Information

  • customer name
  • sites included
  • primary business contact
  • security or facilities contact
  • customer IT contact
  • primary system administrator
  • backup administrator
  • billing contact where relevant

Service Scope

Confirm:

  • locations covered
  • doors covered
  • managed services purchased
  • remote support included
  • administrative services included
  • reporting included
  • field-service arrangement
  • business-hours support
  • after-hours process
  • exclusions or separately billable work

This should trace directly back to the managed access control service agreement.

If the contract and onboarding process describe different services, confusion is almost guaranteed.

Authorized Requestors

Identify who can request:

  • new users
  • credential removal
  • replacement credentials
  • access-level changes
  • schedule changes
  • holiday changes
  • door changes
  • administrator access

For larger customers, different people may have authority over different requests.

HR may be authorized to initiate employee additions and removals.

Facilities may manage door schedules.

IT may be the contact for communications issues.

A regional security manager may approve access to sensitive locations.

The dealer should not have to determine that hierarchy during an urgent support request.

Support Process

Before go-live, the customer should know:

  • where support requests go
  • what information should be included
  • who can submit them
  • normal support hours
  • emergency process
  • what qualifies as urgent
  • what may require field service

Training Plan

Determine who needs training and what each person will actually use.

Avoid the common approach of inviting everyone to one long software demonstration.

Different users need different information.

We’ll come back to that.

Day 1: Establish the Operating Model

The kickoff should begin with the service relationship, not a tour through every menu in EntraPass.

A useful opening question is:

Who is responsible for what once this account is live?

That should be answered clearly before detailed training begins.

What Should Be Covered in the Customer Kickoff Meeting?

A practical kickoff agenda can include seven areas.

1. What Is Being Managed?

Confirm the exact:

  • sites
  • doors
  • systems
  • integrations
  • services

If the customer has equipment outside the managed scope, make that clear.

For example, the customer might have:

  • 24 managed access-controlled doors
  • a separate intercom
  • an intrusion system from another provider
  • two mechanical-only doors
  • customer-managed video surveillance

The phrase “we manage your security system” is too broad if the dealer actually manages only the access control environment.

2. Who Is the Primary Administrator?

Every account should have a clear customer-side owner.

That person does not necessarily need to perform every administrative task.

They should understand:

  • the service model
  • who can authorize changes
  • how support works
  • what the customer’s responsibilities are
  • when to escalate an issue

A backup administrator should also be identified so the service relationship does not depend entirely on one person.

3. What Does the Customer Manage?

Depending on the service package, the customer may manage routine tasks such as:

  • adding employees
  • removing employees
  • assigning existing access levels
  • reviewing events
  • running basic reports

Kantech’s current EntraPass Web App supports browser-based management of doors, users and events, while EntraPass Go supports mobile functions such as door control, card management and access-level assignment.

The existence of those capabilities does not mean every customer should receive permission to use all of them.

Permissions should follow the operating model.

4. What Does the Dealer Manage?

Depending on the agreement, this may include:

  • more complex access-level configuration
  • schedule changes
  • holiday programming
  • administrative support
  • reporting support
  • remote troubleshooting
  • system modifications
  • escalation
  • field service

The dealer’s role should reflect the package the customer actually purchased.

5. What Belongs to Customer IT?

Identify IT dependencies early.

Examples may include:

  • customer networking
  • internet service
  • firewall changes
  • customer workstations
  • customer identity systems
  • other customer-controlled infrastructure

The security dealer should know who to contact if a controller stops communicating and the issue appears to be network-related.

6. What Belongs to the Hosted Service Layer?

If the account is deployed through hattrix and My Managed Security, explain the hosted component in plain language.

Do not make the customer learn the dealer’s entire backend architecture.

They should simply understand that the dealer is providing the customer relationship and managed access control service while the hosted environment is supported through the dealer’s managed-services infrastructure.

MMS currently positions its service around Kantech hattrix cloud services for security integrators, remote management and dealer support while enabling integrators to operate as hattrix Managed Services Dealers.

7. How Are Problems Escalated?

The customer should know where the first call goes.

In most managed-service relationships, that should be the dealer.

The customer should not need to determine whether the cause is:

  • credential-related
  • software-related
  • network-related
  • controller-related
  • hosting-related
  • physical hardware

That is part of the value the dealer provides.

The dealer receives the issue, performs first-line triage and escalates appropriately when required.

Who Should Manage What in a Managed Access Control Account?

Responsibility varies by service agreement, but a simple matrix can make the onboarding conversation much easier.

TaskCustomerSecurity DealerHosted / MSP Layer
Decide who should have accessPrimaryAdviseNo
Notify when employee leavesPrimaryProcess if includedNo
Add routine cardholdersCustomer or dealerCustomer or dealerNo
Create access-level structureApprovePrimaryPlatform support
Change door schedulesRequest or self-manageManage if includedNo
Troubleshoot field hardwareReportPrimaryNo
Troubleshoot hosted environmentReportFirst-line / escalatePlatform responsibility
Maintain customer networkCustomer ITCoordinateNo
Train customer administratorsParticipatePrimarySupport dealer
Review account performanceParticipatePrimarySupport as needed

This is an example operating model. The actual division should match the dealer’s service agreement and the specific hosted service being provided.

The important point is not which company appears in every cell.

The important point is that the answer has been discussed.

Days 1-30: Train the Right People on the Right Tasks

One of the easiest ways to create unnecessary support work is to train every customer employee the same way.

Consider three people:

Sarah works in HR.
She needs to add and remove employees.

David manages facilities.
He needs to understand doors, schedules and operational issues.

Priya works in IT.
She needs to understand network dependencies and escalation.

Putting all three in a two-hour session covering every function will probably leave everyone with more information and less confidence.

Role-based training is more effective.

What Should an HR or Office Administrator Learn?

If the customer will manage its own employees, focus on routine administration.

Training may include:

  • signing in securely
  • finding an existing cardholder
  • creating an approved user
  • assigning an existing access level
  • disabling or removing credentials
  • replacing a credential
  • recognizing when a request requires dealer assistance
  • submitting a support request

Do not turn this person into a Kantech technician.

Their goal is to perform routine tasks correctly.

What Should Facilities or Operations Learn?

Facilities may need more operational understanding.

Training may include:

  • door names and locations
  • schedules
  • holidays
  • basic door status
  • event review
  • reporting
  • recognizing physical door problems
  • understanding the difference between network, software and hardware symptoms
  • support escalation

Kantech’s current EntraPass Corporate positioning emphasizes centralized user management and multi-site monitoring, which is especially relevant for facilities teams managing more than one location.

What Should Customer IT Learn?

Customer IT often does not need full access-control administration training.

They need to understand dependencies.

Cover:

  • which devices rely on their network
  • relevant connectivity requirements
  • who owns firewall or network changes
  • what to communicate before network work occurs
  • dealer contact information
  • escalation process
  • any customer identity integrations
  • administrator security responsibilities

Treating IT as a stakeholder instead of an obstacle can significantly improve support on larger accounts.

What Should a Security Manager Learn?

Security leaders may need:

  • event review
  • access reports
  • access-level structure
  • investigation workflow
  • exception handling
  • sensitive access policies
  • administrative oversight
  • account-review process

Their focus is typically governance and outcome rather than daily cardholder administration.

What Should Executives Learn?

Usually much less.

An executive sponsor may only need to understand:

  • what is being managed
  • who owns the service internally
  • support expectations
  • reporting
  • major risks or recommendations
  • how the service can expand as the organization grows

Do not make executives sit through cardholder creation unless they will actually use it.

What Documentation Should the Customer Receive?

Training should not rely on memory.

Provide a concise customer handover package.

That could include:

Account Overview

  • sites
  • managed doors
  • services included
  • key contacts

Administrator Quick Reference

Simple instructions for the few tasks the customer is expected to perform.

Support Guide

  • support email or portal
  • phone number
  • business hours
  • emergency process
  • information to include in a ticket

Responsibility Summary

Customer versus dealer versus hosting-provider responsibilities.

Authorized Requestor List

Who can ask for what.

Door and Site Naming Reference

Especially useful for multi-site customers.

Instead of:

“The side door isn’t working.”

the customer can report:

“Guelph Distribution Centre, Door 14, North Shipping Entrance.”

That alone can save time during support.

What Support Expectations Should Be Established Before the First Problem?

The worst time to explain the support process is during an urgent issue.

Before go-live, the customer should understand the difference between:

Routine Administration

Examples:

  • employee starting next week
  • future schedule change
  • report request
  • replacement credential

Standard Support

Examples:

  • one card not working
  • question about access permissions
  • unexpected schedule behaviour

High-Priority Operational Issue

Examples:

  • multiple users affected
  • important door unavailable
  • site-wide communications issue

Emergency

Defined according to the dealer’s actual service agreement.

Avoid vague language such as:

“Call us anytime if you need anything.”

That sounds friendly.

It also creates an undefined managed-service scope.

A better customer experience is:

“Here is exactly how to reach us, what happens next and what information will help us resolve your issue quickly.”

What Information Should Customers Include in a Support Request?

Give customers a simple format.

For access-related problems, request:

  1. Site
  2. Door
  3. Affected user or users
  4. Credential, where appropriate
  5. Approximate time the issue occurred
  6. What they expected to happen
  7. What actually happened
  8. Whether other users are affected
  9. Any recent changes
  10. Business impact or urgency

For example:

Site: Cambridge Office
Door: D07, Employee Entrance
User: Jane Smith
Time: Approximately 8:05 a.m.
Issue: Credential produces denied access. Other employees can enter normally. Jane was moved to the accounting department yesterday.

That is significantly more useful than:

“Jane’s card doesn’t work.”

Teaching customers how to report issues is part of onboarding.

What Should Happen at the 30-Day Review?

Thirty days gives the dealer enough real-world behaviour to see where the onboarding process is working and where it is breaking down.

The 30-day conversation should be practical.

Ask:

What Has the Customer Actually Used?

Not what they were trained on.

What have they actually done?

For example:

  • added cardholders
  • removed employees
  • changed schedules
  • viewed events
  • run reports
  • contacted support

Where Are They Getting Stuck?

If the customer repeatedly calls for something it should be self-managing, the issue may be training.

If the customer is self-managing something the dealer expected to control, the administrative boundary may be unclear.

Are Support Requests Going to the Right Place?

Look for:

  • texts to technicians
  • emails to salespeople
  • calls to the installer
  • messages from unauthorized staff

Correct those habits early.

Are Permissions Appropriate?

The customer’s actual usage may reveal that:

  • someone needs more access
  • someone has too much access
  • a backup administrator was never established
  • shared accounts are being used
  • an administrator no longer needs certain functionality

Are There Recurring Technical Problems?

One recurring door issue should not become ten separate support tickets without somebody asking why it keeps happening.

Look for patterns.

A Useful 30-Day Dealer Question

Ask internally:

What is this customer calling us about that they should either know how to handle themselves or have explicitly included in their managed service?

That question can uncover two very different problems.

Problem 1: Training Gap

The service includes customer self-administration, but the customer does not feel confident using it.

Solution:

Provide focused retraining.

Problem 2: Scope Gap

The customer regularly needs the dealer to perform work that was not accounted for in the managed-service package.

Solution:

Clarify the service or consider adjusting the package at the appropriate time.

Neither problem should be ignored for a year and discovered at renewal.

What Should Happen at the 60-Day Review?

The 60-day point is less about training and more about normalization.

By now, the dealer should begin to see what an ordinary month looks like for the account.

Review:

  • volume of administrative requests
  • type of support requests
  • recurring issues
  • field-service requirements
  • customer confidence
  • response expectations
  • account documentation
  • open technical recommendations

Ask whether the service process is sustainable.

For example:

A customer may have been expected to submit five or ten employee changes each month.

After two months, it is submitting 60.

That does not mean the customer is doing anything wrong.

It means your original assumptions about the account were wrong.

The earlier that becomes visible, the easier it is to manage.

What Should Happen at the 90-Day Managed Access Control Review?

The 90-day review should bring the onboarding period to a close and transition the customer into normal account management.

This is where the dealer moves from:

“Is everyone comfortable with the new system?”

to:

“Is this managed access control service delivering what the customer needs?”

Review four areas.

1. Service Performance

Discuss:

  • support volume
  • recurring issues
  • unresolved concerns
  • customer feedback
  • field-service requirements
  • process improvements

2. Administration

Review:

  • current administrators
  • access-change process
  • employee offboarding
  • customer self-service
  • dealer-managed administration

3. System Opportunities

Look for legitimate next steps.

Potential examples:

  • additional doors
  • additional locations
  • standardized access levels across sites
  • reporting improvements
  • updated credentials
  • mobile functionality
  • intrusion or video integrations
  • better identity workflows

These should arise from actual customer needs rather than an arbitrary upsell target.

4. Next Review Date

Managed service should have an ongoing rhythm.

For a larger account, that may mean quarterly business reviews.

For a smaller account, an annual review may be enough.

The important thing is that the dealer does not disappear until renewal.

Why Is the 90-Day Review Also a Sales Conversation?

Because good managed-service sales should come from understanding how the customer operates.

Suppose the customer says:

“The only thing we still struggle with is our second warehouse. It isn’t connected to the same system, so our facilities manager has to maintain two separate employee lists.”

That is not a cold upsell.

The customer has identified an operational problem.

A dealer that understands the environment can discuss whether consolidating that location makes sense.

Likewise, a support history may reveal that the customer regularly asks for:

  • remote door management
  • additional reporting
  • changes across multiple locations
  • administration help
  • mobile access
  • integrated video verification

The managed relationship gives the dealer visibility into those needs.

That is one reason recurring service can be more commercially valuable than a simple installation-and-break-fix relationship.

The dealer stays involved.

Five Managed Access Control Onboarding Mistakes That Create Unnecessary Support Work

Several onboarding mistakes are especially expensive because they repeat across every customer.

Mistake 1: Training Everyone Together

One generic session usually gives everyone information they do not need and skips the detail they do need.

Better: Train by role.

Mistake 2: Failing to Define Authorized Requestors

If anyone at the customer can request access changes, your service desk eventually has to make judgment calls it should not be making.

Better: Establish authority before go-live.

Mistake 3: Letting Customers Contact Individual Technicians

The technician who installed the system may be the customer’s favourite person to call.

That technician may also be:

  • on a ladder
  • on vacation
  • at another customer
  • no longer with your company

Better: Create one documented support path.

Mistake 4: Giving Too Many People Administrative Access

More access is not necessarily better customer service.

It can create:

  • inconsistent configuration
  • unintended changes
  • difficulty tracing problems
  • unnecessary security exposure

Better: Give each role the access it actually needs.

Mistake 5: Treating Go-Live as the End of Onboarding

The customer has not developed real habits yet.

You will not know whether training worked until people start using the system.

Better: Review the account after real usage begins.

How Can Integrators Make Onboarding Easier Across Multiple Customers?

The answer is standardization.

Every managed customer will have unique doors, people and policies.

The onboarding process should still follow a consistent structure.

Build reusable templates for:

Kickoff Agenda

Use the same core agenda for every account.

Responsibility Matrix

Customer, dealer and hosting responsibilities.

Authorized Requestor Form

Document approval authority.

Training Matrix

Who needs which training module.

Support Guide

Same request process across all customers where possible.

30-Day Review

Use consistent questions.

60-Day Review

Review service volume and recurring issues.

90-Day Review

Evaluate performance, administration and expansion opportunities.

Account Record

Maintain a consistent account summary internally.

This is how onboarding becomes an operating process instead of an activity that depends on whichever technician happens to complete the project.

How Does My Managed Security Fit Into Customer Onboarding?

A security dealer entering managed access control has two different things to build.

The first is the customer service model.

That includes:

  • customer onboarding
  • sales
  • access-control design
  • administration
  • support
  • field service
  • customer reviews
  • recurring revenue strategy

The second is the hosted infrastructure behind the service.

A dealer can choose to build and operate both.

Or it can focus on the first and work with a managed-services provider for the second.

My Managed Security currently provides Kantech hattrix cloud services to security integrators and positions its offering around helping dealers manage customer systems remotely, reduce operational demands and build recurring revenue as hattrix Managed Services Dealers. MMS also advertises 24/7 dealer support for its dealer network.

That distinction matters during onboarding.

The dealer should be spending customer-facing time answering questions such as:

  • Who should have access?
  • Who is the customer’s administrator?
  • What does this customer need help managing?
  • What should our service team own?
  • How should support work?
  • What additional locations may need to be standardized?

The dealer should not necessarily have to spend that same time building a private-cloud operation from scratch before it can offer managed services.

For integrators looking to scale their managed offering, that can make the Managed Services Dealer model an attractive middle ground.

You maintain the customer relationship.

You build the recurring service.

You continue installing and servicing the physical security environment.

And you partner for the hosted infrastructure supporting the hattrix service.

A Repeatable 30-60-90 Day Managed Access Control Onboarding Framework

For quick reference, the entire process can be summarized like this.

Before Go-Live

  • confirm service scope
  • identify authorized requestors
  • identify administrators
  • confirm customer IT contact
  • define responsibilities
  • establish support channels
  • schedule role-based training

Day 1

  • review the managed-service model
  • confirm sites and doors
  • review responsibilities
  • confirm support and escalation
  • begin role-specific training
  • provide onboarding documentation

Days 1-30

  • complete training
  • observe customer behaviour
  • track early support requests
  • correct improper support channels
  • resolve permission issues
  • identify training gaps

Day 30 Review

  • review actual usage
  • review support requests
  • clarify responsibilities
  • adjust permissions
  • address early recurring issues

Days 31-60

  • monitor normal administration volume
  • identify service patterns
  • refine documentation
  • provide targeted retraining where needed
  • resolve recurring technical issues

Day 60 Review

  • confirm the account is operating normally
  • review workload against service scope
  • address process gaps
  • confirm open recommendations

Days 61-90

  • transition from onboarding to regular account management
  • prepare service observations
  • identify legitimate system opportunities

Day 90 Review

  • evaluate service performance
  • review administrative processes
  • discuss customer feedback
  • identify appropriate improvements
  • establish future review cadence

The framework does not need to be rigid.

A ten-door office and a 60-site organization should not receive identical onboarding.

The value is having a consistent process that can scale up or down according to the customer.

Frequently Asked Questions

How long should managed access control onboarding take?

Technical deployment may be completed much sooner than 90 days. A 30-60-90 day framework is useful because it gives the dealer time to observe how the customer actually uses the system, identify training or scope gaps and transition the account into a stable long-term support process.

Who should attend a managed access control onboarding meeting?

At minimum, include the customer’s primary administrator, an appropriate backup and the dealer’s account or service contact. Facilities, HR, security and IT contacts may also participate depending on their responsibilities. Not everyone needs to attend every training session.

Who should manage employee credentials?

It depends on the service agreement. Some customers manage routine cardholder additions and removals themselves, while others purchase dealer-managed administration. The responsibility should be established before go-live, along with who is authorized to request or approve access changes.

What training does an access control customer need?

Training should match the person’s role. HR may need cardholder administration, facilities may need doors and schedules, IT needs network and escalation information, and security managers may need events and reporting. Avoid teaching every user every system function.

What should happen at a 30-day managed access control review?

Review what the customer has actually used, recurring support requests, training gaps, administrator permissions, support-channel behaviour and any unresolved technical issues. The objective is to correct problems early rather than allowing them to become permanent service habits.

Should customers contact the technician who installed their system?

Routine support should generally go through the dealer’s established support channel rather than directly to an individual technician. A centralized process makes requests visible, trackable and easier to prioritize even when the original installer is unavailable.

How many access control administrators should a customer have?

There is no universal number, but relying on a single administrator creates unnecessary risk while giving administrative access to too many people creates its own problems. Identify a primary administrator and appropriate backup coverage, then grant privileges according to each person’s actual responsibilities.

What documentation should a customer receive after onboarding?

Useful documentation includes the managed sites and systems, administrator contacts, authorized requestors, support process, responsibility summary, basic user instructions and consistent site or door naming. Keep customer-facing documentation concise enough that people will actually use it.

Good Onboarding Makes Managed Access Control Easier to Scale

The goal of managed access control onboarding is not to teach the customer everything about the technology.

It is to establish a relationship that works without constant improvisation.

The customer knows:

  • what is being managed
  • what it is responsible for
  • who can request changes
  • how to use the functions relevant to its role
  • where to go for support
  • what happens when a problem occurs

The dealer knows:

  • what it has promised
  • what the customer is expected to manage
  • who can authorize changes
  • how much support the account actually consumes
  • which issues are recurring
  • where future opportunities exist

That clarity becomes more valuable with every additional managed customer.

A dealer with five managed accounts may be able to work around inconsistent processes.

A dealer building a significant recurring-revenue portfolio needs a repeatable operating model.

And that is where the technology and business model come together.

My Managed Security helps security integrators offer Kantech hattrix managed access control while partnering for the cloud infrastructure behind the service. The dealer can continue focusing on customer onboarding, installation, administration, service and long-term account growth without having to build the entire hosted environment itself.

If your company is looking to turn more Kantech customers into ongoing managed-service relationships, the next step is not simply putting another account in the cloud.

It is building a service model you can onboard and support repeatedly.

Interested in building a scalable managed access control offering? Talk to My Managed Security about becoming a hattrix Managed Services Dealer.


Recommended Internal Links

Add contextual internal links to: