ZKTeco Access Control in Egypt: Biometrics, Doors & Time Attendance

ZKTeco · Egypt

A door either opens for the right person, or it does not.

ZKTeco access control, biometric readers and time attendance — specified against the doors you actually have, wired to fail the right way, and enrolled properly so the system is trusted instead of propped open.

What we deliver

Door survey and design

Every controlled door walked and recorded: what it is made of, which way it swings, whether it is on the fire escape route, and what has to happen to it when the alarm sounds.

Installation and integration

Controllers, readers, locks, exit devices and power installed by the same engineers who build the network, and integrated with surveillance rather than sitting beside it.

Enrolment, policy and support

Users enrolled properly, door groups and time zones built to your actual shift pattern, and the system maintained under a written agreement.

The three things that go wrong

The door was never surveyedAccess control is a door problem before it is an electronics problem. A reader on a door with a weak frame, a failing closer or a handle that can be pulled from outside is a log entry, not security.
Fail-safe and fail-secure confusedWhether a lock releases or holds when power is lost is a life-safety decision, and it is different for a fire escape than for a server room. Getting it wrong is either a trapped person or an open building.
Enrolment done badly, onceFingerprints captured in thirty seconds on a bad reader produce a system that rejects real staff every morning. Within a month somebody props the door open and the whole investment is gone.

What we actually specify, and why

Most disappointing access control systems were specified by counting doors and readers. The decisions that determine whether people trust the system are the credential type, the door hardware, the failure mode and the quality of enrolment. All four are settled before anything is ordered.

Choosing the credential

CredentialWhere it belongsWhat it will not do
FingerprintOffice and administrative doors, and time attendance where the credential must not be lendable.Work reliably for staff with worn, wet, dusty or damaged fingers — which describes a lot of industrial and kitchen workforces.
Face recognitionMain entrances and turnstiles, hands-free flow, and environments where hands are gloved or dirty.Cope with a badly lit or backlit position. The camera needs controlled light like any other camera.
Card or fobContractors, visitors, high-turnover sites, and anywhere a credential must be issued and revoked in seconds.Prove who used it. A card proves a card was present, which is why it is often paired with a PIN.
PINA second factor on a sensitive door, or a low-cost fallback.Stay private. PINs get shared, watched and written down. Rarely acceptable on its own.
Mobile credentialManagers and mobile staff who already carry a phone and lose cards.Help when the phone is flat, and it depends on the phone estate you actually have.
Two factors togetherServer rooms, cash areas, pharmacy and record stores — card plus biometric, or biometric plus PIN.Move a crowd quickly. Reserve it for the doors that justify the delay.

The practical consequence: one credential type across a whole site is nearly always wrong. A factory gate, an accounts office and a server room have different populations, different risks and different acceptable failure rates.

Biometrics, honestly

False rejection is the real costThe number that damages a deployment is not the impostor who gets in, it is the genuine employee refused three times in front of a queue. Threshold, reader placement and enrolment quality are tuned against that.
Enrol more than one fingerTwo fingers on each hand, captured carefully, at enrolment. A cut on the index finger should not stop someone working.
Hands the workforce actually hasManual, chemical and kitchen work degrades fingerprints. On those sites we specify face or card as the primary credential and keep fingerprint as an option, not the rule.
Reader position and lightFace readers mounted against a bright window or under direct sun fail exactly when the shift starts. Position is decided on the site walk.
Templates, not imagesZKTeco devices store a mathematical template rather than a picture of the finger. It still counts as biometric personal data, and it is still treated as such.

Door hardware, power and failure mode

Fail-safe versus fail-secure, decided per doorFail-safe releases on power loss, which is what a fire escape route requires. Fail-secure stays locked, which is what a records room usually requires. It is recorded per door, in writing, and signed off.
Fire alarm interlockControlled doors on escape routes are wired to release on a fire alarm signal, independently of the software. This is not a configuration setting, it is a hardwired requirement.
The right lock for the doorMagnetic locks, electric strikes and motorised locks each suit different frames and different traffic. A magnet on a warped timber door will be pulled off; a strike in a weak frame will be kicked through.
Request-to-exit and free egressPeople must be able to get out without presenting anything. Exit buttons, break-glass and mechanical override specified so nobody is ever locked in.
Door position and forced-open monitoringA contact on every controlled door so held-open and forced-open events are alarmed. Without it the system records who was granted access and misses everyone who walked in behind them.
Power and battery backupLocks draw real current. Power supplies sized per door with battery backup so a short outage does not unlock or strand the building.

Policy: the part that gets skipped

Door groups and time zonesBuilt from your actual shift pattern and cleaning schedule, not one profile called “All Doors” that everybody ends up on within six months.
Anti-passbackA credential that has entered cannot enter again until it has exited. It is what stops one card admitting a queue, and it only works if every entry and exit point is read.
Interlock and airlock doorsWhere two doors must never be open at once — server rooms, clean areas, cash handling — configured at the controller so it holds regardless of the software.
Visitors and contractorsTemporary credentials with an expiry, so the badge that stops working is the system doing its job rather than a fault.
Leavers removed the same dayAccess revoked as part of the leaver process, tied to the same checklist as the mailbox and the laptop. An access list full of former staff is a standard audit finding.

Time and attendance

One reader, two purposesWhere it suits you, the same devices that control the door produce attendance data, so staff do not clock twice and the two records cannot disagree.
Shift rules that match realityGrace periods, overtime, night shifts crossing midnight, Ramadan hours and public holidays configured before go-live rather than argued about at the first payroll run.
Export to payrollReports in the format your payroll or HR system actually accepts, scheduled, so nobody is retyping figures at month end.
Exceptions surfacedMissed punches, unusual patterns and manual amendments reported and traceable to the person who made them.

Network, resilience and integration

Controllers keep working offlineDoors continue to grant and deny against locally held rules if the server or network drops. A system that stops working when a switch reboots is not acceptable on a door.
Its own network segmentControllers and readers segmented from the business network, reaching the management server and nothing else.
Never exposed to the internetNo port forwarding to a controller or a management server. Remote administration over a VPN, with named accounts.
Integrated with surveillanceAccess events tied to camera footage, so an alarm at a door comes with the picture of who was standing at it. This is why access control and CCTV should be one project.
Backed up and documentedDatabase backed up, controller configuration exported, door schedule maintained as a document. Most inherited systems have none of these.

Privacy and the law

Biometric data is sensitive personal dataUnder Egypt’s Personal Data Protection Law it attracts a higher standard of care than a card number. Storage, retention, access and consent are decided deliberately, not by default.
Retention statedHow long attendance and access logs are kept, and who can see them, written down before go-live.
An alternative where it is neededWhere an employee cannot or will not give a biometric, a card credential achieves the same control. We design that in rather than leaving it as an argument.

Access control and time attendance touch employment terms and personal data. We will tell you where a configuration is likely to create a dispute or a compliance problem, rather than install it and leave that to you.

Send us a door schedule

Or just a floor plan with the doors marked. We will tell you which ones justify control, what each one needs, and how it should fail.

Book the free assessment02 35375791