The integration of facial recognition technology with Access It! via ASSA Control iD significantly enhances security without requiring users to overhaul their existing systems. This integration allows current users, who have made substantial investments in Mercury panels and established workflows, to incorporate advanced biometric and multi-factor authentication without additional installations or software learning curves.
ASSA's integration introduces facial recognition and multi-factor authentication through existing Mercury controllers. This upgrade eliminates the need for new panels or expensive rewiring. It ensures that access points, where speed and accurate authentication are critical, are enhanced beyond the traditional card-only authentication systems.
Multi-Factor Authentication Options
The concern of whether this advancement requires replacing old systems is addressed by the integration's core design, which maintains the current infrastructure. The architecture remains straightforward, with Control iD face readers performing facial recognition while maintaining credential conformity. Access rules remain administered by Access It!, ensuring that logs and event data persist as they are, without redesign.
The integration supports four authentication modes, tailored to different security levels: Face only, for quick access; Face + Card, for high-security areas using cards or mobile credentials; Face + PIN, providing additional security without new credentials; and QR Code, intended for temporary or visitor access. These modes all report through Access It!, preserving the existing user-friendly system.
Enhancing Security, Maintaining Familiarity
Facial recognition processing is executed at the reader, ensuring swift access decisions
Facial recognition processing is executed at the reader, ensuring swift access decisions. Control iD Vision AI performs identity verification with liveness detection, differentiating real faces from images or videos. Access It!'s administrative protocols remain unchanged, with synchronization ensured in access provisioning and deprovisioning. Application and biometric data security is prioritized with encryption, reinforcing the system's 24/7 operation.
Facial recognition technology is particularly beneficial in environments where identity verification is crucial, such as corporate offices, data centers, healthcare facilities, and educational campuses. In these areas, the efficiency and security provided by the new system far surpass the capabilities of card-only systems.
To utilize this integration, users need Access It! version 12.4 or higher, along with existing Mercury-based panels such as the MP, LP, and EP series. Control iD iDFace biometric readers, specifically the IDFACE MAX and IDFACE PRO models, are validated for use. Communication between the reader and controller can occur via Wiegand or OSDP, with version 2.2 necessary for door status indication. Importantly, there is no limit to the number of Control iD readers a system can support, though licensing is required per reader.
If users are running Access It! today, they have already made a real investment — in Mercury panels, in wiring, in workflows the operators know cold. The question isn't whether biometric authentication is worth adding. It's whether adding it means starting over.
The ASSA Control iD integration brings facial recognition and multi-factor authentication into Access It! through the Mercury controllers that users are already running. No new panels. No rewiring. No new system for the team to learn.
Multi-factor authentication
Cards get shared. PINs get guessed. Badges get left in cars. Facial recognition closes that gap — it verifies the person, not just the credential they're carrying. For access points where speed and certainty both matter, that's a meaningful upgrade over card-only authentication.
The objection most security teams raise next is predictable: does this mean replacing what they have? It doesn't. That's the design principle behind this integration, not a footnote to it.
Card-only authentication
The architecture is deliberately simple, and that's the point.
- A Control iD face reader performs the facial recognition and captures the presented credential.
- The credential number is sent to the Mercury controller, over Wiegand or OSDP, whichever users are already using.
- Access It! remains the system of record. It applies access rules, schedules, and anti-passback, and logs every event exactly as it would for a card swipe.
- The net result: biometric authentication at the edge, with no system redesign. The Mercury controllers, wiring, and Access It! workflows — unchanged. The reader does new work; nothing else has to.
Four authentication modes
Four ways to authenticate, one system managing all of them. Different doors carry different risk. The integration supports four authentication modes, and users choose which applies where:
- Face only: the fastest path through the door, built for speed at access points where a quick, frictionless walk-through is the priority.
- Face + Card adds a second factor for higher-security doors. Works with physical cards and mobile credentials over NFC or BLE.
- Face + PIN: a third option for areas where users want elevated assurance without issuing a new credential type.
- QR Code: built for temporary or visitor access, where supported by the reader.
Every mode reports back through Access It! the same way a card read would. The operators don't learn a second system, they keep using the one they already know. What changes for the security team and what doesn't. This is where the integration earns its place, not in the feature list but in what it leaves alone.
What changes:
- Facial recognition processing happens at the reader itself, so the time between presentation and decision stays fast.
- Identity verification is backed by Control iD Vision AI with liveness detection, built to tell a real face from a photo or a video.
- A double-tap on the reader can trigger configured actions, mirroring the double-card behavior the team already uses.
Provisioning and deprovisioning follow Access It! automatically: assign someone a Control iD-mapped access level and they're in; remove that access, or remove them from the host system, and they're out. Records stay synchronized automatically, with face photo sync available as an optional, separately controlled setting.
What doesn't change:
- Access decisions, schedules, and event logging all stay in Access It!.
- Administration stays in the Access It! desktop client — no separate database, no second login.
- The operators' monitoring workflow is exactly what it was yesterday.
Application data and biometric data are encrypted in transit, and the system is designed for always-on, 24/7 operation, which matters because access control doesn't get a maintenance window.
Identity certainty matters
Facial recognition earns its place fastest in environments where identity certainty matters and foot traffic is constant: corporate offices, data centers, healthcare facilities, and education campuses. Anywhere a card alone isn't quite enough and anywhere “replace the whole system” was never going to be the answer the budget or the operations team wanted to hear.
What users need to get started
- Access It! version: 12.4 or higher
- Controllers: Existing Mercury-based panels: MP, LP, and EP series are supported. No controller, panel, or wiring changes required.
- Readers: Control iD iDFace biometric readers. Validated models are the IDFACE MAX and IDFACE PRO.
- Communication: Wiegand or OSDP between reader and controller. OSDP (version 2.2) is required if users want door-status indication at the reader.
- Capacity: No limit on the number of Control iD readers a system can support.
- Licensing: Control iD is licensed per reader.