{"id":8733,"date":"2026-09-02T10:27:31","date_gmt":"2026-09-02T08:27:31","guid":{"rendered":"https:\/\/blog.simons-voss.com\/?p=8733"},"modified":"2026-09-02T10:28:44","modified_gmt":"2026-09-02T08:28:44","slug":"how-do-i-prove-who-accessed-a-building","status":"publish","type":"post","link":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/","title":{"rendered":"How Do I Prove Who Accessed a Building?\u00a0"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><span data-contrast=\"auto\">An <a href=\"https:\/\/www.simons-voss.com\/en\/\">electronic access control system<\/a> with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system\u00a0actually delivers\u00a0this in practice depends on how\u00a0it&#8217;s\u00a0configured and how long the data is kept.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It&#8217;s\u00a0the question that comes up after the fact, not before. A contractor&#8217;s badge goes missing. An item disappears from a stockroom. An insurer asks for evidence following a claim. Someone, somewhere, needs a straight answer to &#8220;who was in that area, and when,&#8221; and reaching for a paper sign-in sheet or a vague memory of who had keys that week\u00a0isn&#8217;t\u00a0going to satisfy anyone asking the question formally. One UK university found out the hard way what happens without an answer: a lost master key to a scientific research\u00a0centre\u00a0meant the entire system had to be rekeyed, at a cost of \u00a350,000. In\u00a0SimonsVoss&#8217;s\u00a0own survey of facilities and security professionals,\u00a039% said they\u00a0couldn&#8217;t\u00a0produce an audit trail showing who accessed specific areas and when.\u00a0That&#8217;s\u00a0not a small gap.\u00a0It&#8217;s\u00a0the difference between answering a question and rekeying a building.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">What a Proper Audit Trail Actually Captures<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">A mechanical key system can tell you almost nothing after\u00a0the\u00a0fact. A key either\u00a0works\u00a0or it\u00a0doesn&#8217;t, and once\u00a0it&#8217;s\u00a0been cut,\u00a0copied\u00a0or handed to a contractor,\u00a0there&#8217;s\u00a0no record of who used it, where, or when. If a key goes missing, the only real fix is rekeying the\u00a0whole system, which is expensive and disruptive.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The speed difference\u00a0shows up\u00a0the moment something goes wrong. On a properly configured online access control system, blocking a lost card and issuing a replacement typically takes about three clicks. On an offline system covering a larger estate, the same job can mean physically visiting every lock, which on an 80-door site can take around two hours. With a mechanical master key, there&#8217;s often no equivalent\u00a0short version\u00a0at all, only a full rekey.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">An electronic access control system replaces that with a structured log. Done properly, it captures:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Who.<\/span><\/b><span data-contrast=\"auto\">\u00a0The specific credential (a card, fob,\u00a0PIN\u00a0or mobile key) tied to a named individual, not a generic master key shared by a dozen people.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Where.<\/span><\/b><span data-contrast=\"auto\">\u00a0The exact door or zone the credential was used at, down to individual rooms if the system is set up that way.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">When.<\/span><\/b><span data-contrast=\"auto\">\u00a0A precise,\u00a0accurate\u00a0timestamp for every access event, not just an approximate window.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Whether it was expected.<\/span><\/b><span data-contrast=\"auto\">\u00a0Access outside normal hours or patterns can be flagged, rather than sitting unnoticed in a log nobody checks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">This is the baseline. Without it, &#8220;prove who accessed the building&#8221;\u00a0isn&#8217;t\u00a0really answerable, no matter how good your locks are.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">Why Data Retention Is the Gap Nobody Plans For<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Capturing the data is only half the job. The other half is keeping it long enough to be useful, and this is where\u00a0SimonsVoss&#8217;s\u00a0survey found a bigger gap:\u00a046% of facilities and security professionals said they cannot search or\u00a0retain\u00a0access data for a meaningful period.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">There&#8217;s\u00a0no single fixed retention period set out in UK law for access control logs. What does apply is UK GDPR&#8217;s storage limitation principle, which requires\u00a0organisations\u00a0to keep personal data only as long as necessary for the purpose it was collected for, and to be able to justify that period if asked. In practice, that means the right retention window depends on what the data is for: a short window might cover routine building management, but investigations, insurance claims and safeguarding reviews often surface weeks or months after the event in question. If the data&#8217;s already been overwritten by then, it\u00a0doesn&#8217;t\u00a0matter how good the system was on day one.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A searchable archive that only goes\u00a0back\u00a0a few days\u00a0isn&#8217;t\u00a0really an audit trail.\u00a0It&#8217;s\u00a0a temporary log that happens to be useful if\u00a0you&#8217;re\u00a0lucky with timing. The storage limitation\u00a0principle\u00a0cuts both ways too: once data has served its purpose and the retention period has passed, it should be securely\u00a0deleted\u00a0rather than left to accumulate indefinitely. A system that\u00a0can&#8217;t\u00a0do either, keep data long enough or dispose of it properly, creates risk at both ends.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">Where This Actually Matters<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">This\u00a0isn&#8217;t\u00a0a hypothetical compliance exercise. It shows up in ordinary situations that most estates and facilities teams deal with at some point:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Security incidents.<\/strong><span data-contrast=\"auto\">\u00a0Theft,\u00a0vandalism\u00a0or\u00a0unauthorised\u00a0entry all raise the same first question: who had access to that area, and when. Without a searchable log, the answer starts with a shrug.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Contractor and visitor access.<\/strong><span data-contrast=\"auto\">\u00a0Contractors,\u00a0cleaners\u00a0and temporary staff often need short-term access to specific areas. When something goes wrong during that window, being able to pull an exact record of who was where matters far more than remembering who was booked in.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Staff turnover.<\/strong><span data-contrast=\"auto\">\u00a0People leave, change roles, or lose credentials. A clear log shows exactly when access was revoked and whether it was used after that point, which protects the\u00a0organisation\u00a0as much as it protects the departing employee.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Insurance claims.<\/strong><span data-contrast=\"auto\">\u00a0Insurers increasingly ask for evidence of access control and monitoring after a claim, not just confirmation that a system exists. A documented, searchable audit trail is what turns &#8220;we had security measures in place&#8221; into something an insurer can\u00a0actually verify.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Martyn&#8217;s Law readiness.<\/strong><span data-contrast=\"auto\">\u00a0For\u00a0organisations\u00a0already reviewing their access control approach ahead of Martyn&#8217;s Law, an audit trail is one of the clearest, most concrete things to get right. Under the Act&#8217;s Enhanced Tier, premises expecting 800 or more people are expected to carry out formal risk assessments and put in place reasonably\u00a0practicable\u00a0physical security measures. A searchable, time-stamped record of who accessed what is direct, demonstrable evidence that those measures\u00a0actually work, not just that they exist on paper.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Board and governance reporting.<\/strong><span data-contrast=\"auto\">\u00a0This is often the version of the question that actually gets budget released.\u00a0Facilities managers are\u00a0frequently\u00a0the influencers rather than the final decision-makers, and getting sign-off from senior leadership depends on being able to answer a different, harder set of questions: can you\u00a0demonstrate\u00a0that permissions align with defined roles? Can you evidence that access is revoked\u00a0immediately\u00a0when it should be? Can you produce a searchable audit trail on demand, in front of a board, a regulator or an auditor? An access control system that only answers &#8220;did the door open&#8221;\u00a0doesn&#8217;t\u00a0help here. One that produces a clear, searchable\u00a0record does.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>IT and infrastructure oversight.<\/strong><span data-contrast=\"auto\">\u00a0For IT managers increasingly involved in access control decisions, the audit trail itself is data that needs to be handled properly: stored securely, access to the logs restricted and recorded, and the system able to sit alongside existing infrastructure rather than as an isolated island. An audit trail that\u00a0isn&#8217;t\u00a0itself secure and well-governed undermines the case\u00a0it&#8217;s\u00a0meant to support.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">How\u00a0SimonsVoss\u00a0Systems Support This<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">This is exactly what\u00a0SimonsVoss&#8217;s\u00a0software platforms are built to provide. Access events are logged centrally against named credentials, giving estates and facilities teams a searchable record rather than a scattered set of assumptions. Permissions can be set,\u00a0changed\u00a0or revoked instantly when someone\u00a0leaves\u00a0or a credential is lost, and that change is itself recorded. Retention settings can be configured to match what the\u00a0organisation\u00a0actually needs, rather than defaulting to whatever the system happens to store by default.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The result is a system that answers &#8220;who accessed this building, and when&#8221; as a straightforward search, not a project.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">FAQ<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><strong>How long should access data be\u00a0retained?\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">There&#8217;s\u00a0no single legal minimum or maximum. UK GDPR requires you to keep data only as long as necessary for a documented, justifiable purpose, which for most\u00a0organisations\u00a0means balancing routine storage costs against the realistic time it takes for an incident,\u00a0claim\u00a0or investigation to surface. Many\u00a0organisations\u00a0retain\u00a0access logs for several months to a year, but the right period depends on your sector, risk profile and any specific compliance requirements that apply to you.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Can this data be used as evidence?\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">Access control logs can support an investigation or claim, but their evidential weight depends on the integrity of the system:\u00a0accurate\u00a0timestamps, credentials tied to named individuals, and a clear record of who can access and edit the logs themselves. A system that&#8217;s well configured and consistently used is far more useful as evidence than one bolted on as an afterthought.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>What&#8217;s\u00a0the difference between logging and monitoring?\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">Logging is the record itself, the who, where and when of every access event, stored for later review. Monitoring is watching that activity in real\u00a0time, or\u00a0setting up alerts for unusual patterns as they happen. A good access control system does both, but logging is the non-negotiable foundation. You\u00a0can&#8217;t\u00a0monitor\u00a0effectively, or\u00a0investigate after\u00a0the fact, without a complete log to work from.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">If\u00a0you&#8217;d\u00a0like a wider view of how this fits into a broader access control strategy, our\u00a0<\/span><a href=\"https:\/\/www.simons-voss.com\/en\/digital-locking-systems.html\"><span data-contrast=\"auto\">digital locking systems for compliance-ready buildings<\/span><\/a><span data-contrast=\"auto\">\u00a0page covers the core capabilities, audit trails included, that estates and facilities teams should expect as standard. And if\u00a0you&#8217;re\u00a0specifically weighing this up against Martyn&#8217;s Law, our piece on\u00a0<\/span><a href=\"https:\/\/blog.simons-voss.com\/en\/technology\/does-wireless-locking-comply-with-martyns-law\/\"><span data-contrast=\"auto\">whether wireless locking complies with Martyn&#8217;s Law<\/span><\/a><span data-contrast=\"auto\">\u00a0covers the tiered requirements and where the common compliance gaps sit.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Not ready to talk to a person yet? Get the\u00a0<\/span><a href=\"https:\/\/go.simons-voss.com\/hubfs\/UK\/SimonsVoss%20Martyn%E2%80%99s%20Law%20Whitepaper%202026.pdf\"><span data-contrast=\"none\">Access Control Readiness Checklist<\/span><\/a><span data-contrast=\"auto\">\u00a0first.\u00a0It&#8217;s\u00a0a practical, non-technical walkthrough covering access control, monitoring, staff training and audit-trail readiness, built to help you see exactly where your current setup stands before you make any changes.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Ready to see where your current setup stands?<\/span><\/b><span data-contrast=\"auto\">\u00a0<a href=\"https:\/\/www.simons-voss.com\/en\/who-we-are\/contact.html\">Speak to our UK team about audit-trail capability and what &#8220;meaningful retention&#8221; should look like for your estate.<\/a><\/span><a href=\"https:\/\/www.simons-voss.com\/en\/who-we-are\/contact.html\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><span data-contrast=\"auto\">An electronic access control system with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system\u00a0actually delivers\u00a0this in practice depends on how\u00a0it&#8217;s\u00a0configured and how long the data is kept.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It&#8217;s\u00a0the question that comes up after the fact, not before. A contractor&#8217;s badge goes missing. An item disappears from a stockroom. An insurer asks for evidence following a claim. Someone, somewhere, needs a straight answer to &#8220;who was in that area, and when,&#8221; and reaching for a paper sign-in sheet or a vague memory of who had keys that week\u00a0isn&#8217;t\u00a0going to satisfy anyone asking the question formally. One UK university found out the hard way what happens without an answer: a lost master key to a scientific research\u00a0centre\u00a0meant the entire system had to be rekeyed, at a cost of \u00a350,000. In\u00a0SimonsVoss&#8217;s\u00a0own survey of facilities and security professionals,\u00a039% said they\u00a0couldn&#8217;t\u00a0produce an audit trail showing who accessed specific areas and when.\u00a0That&#8217;s\u00a0not a small gap.\u00a0It&#8217;s\u00a0the difference between answering a question and rekeying a building.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">What a Proper Audit Trail Actually Captures<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">A mechanical key system can tell you almost nothing after\u00a0the\u00a0fact. A key either\u00a0works\u00a0or it\u00a0doesn&#8217;t, and once\u00a0it&#8217;s\u00a0been cut,\u00a0copied\u00a0or handed to a contractor,\u00a0there&#8217;s\u00a0no record of who used it, where, or when. If a key goes missing, the only real fix is rekeying the\u00a0whole system, which is expensive and disruptive.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The speed difference\u00a0shows up\u00a0the moment something goes wrong. On a properly configured online access control system, blocking a lost card and issuing a replacement typically takes about three clicks. On an offline system covering a larger estate, the same job can mean physically visiting every lock, which on an 80-door site can take around two hours. With a mechanical master key, there&#8217;s often no equivalent\u00a0short version\u00a0at all, only a full rekey.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">An electronic access control system replaces that with a structured log. Done properly, it captures:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Who.<\/span><\/b><span data-contrast=\"auto\">\u00a0The specific credential (a card, fob,\u00a0PIN\u00a0or mobile key) tied to a named individual, not a generic master key shared by a dozen people.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Where.<\/span><\/b><span data-contrast=\"auto\">\u00a0The exact door or zone the credential was used at, down to individual rooms if the system is set up that way.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">When.<\/span><\/b><span data-contrast=\"auto\">\u00a0A precise,\u00a0accurate\u00a0timestamp for every access event, not just an approximate window.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Whether it was expected.<\/span><\/b><span data-contrast=\"auto\">\u00a0Access outside normal hours or patterns can be flagged, rather than sitting unnoticed in a log nobody checks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">This is the baseline. Without it, &#8220;prove who accessed the building&#8221;\u00a0isn&#8217;t\u00a0really answerable, no matter how good your locks are.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">Why Data Retention Is the Gap Nobody Plans For<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Capturing the data is only half the job. The other half is keeping it long enough to be useful, and this is where\u00a0SimonsVoss&#8217;s\u00a0survey found a bigger gap:\u00a046% of facilities and security professionals said they cannot search or\u00a0retain\u00a0access data for a meaningful period.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">There&#8217;s\u00a0no single fixed retention period set out in UK law for access control logs. What does apply is UK GDPR&#8217;s storage limitation principle, which requires\u00a0organisations\u00a0to keep personal data only as long as necessary for the purpose it was collected for, and to be able to justify that period if asked. In practice, that means the right retention window depends on what the data is for: a short window might cover routine building management, but investigations, insurance claims and safeguarding reviews often surface weeks or months after the event in question. If the data&#8217;s already been overwritten by then, it\u00a0doesn&#8217;t\u00a0matter how good the system was on day one.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A searchable archive that only goes\u00a0back\u00a0a few days\u00a0isn&#8217;t\u00a0really an audit trail.\u00a0It&#8217;s\u00a0a temporary log that happens to be useful if\u00a0you&#8217;re\u00a0lucky with timing. The storage limitation\u00a0principle\u00a0cuts both ways too: once data has served its purpose and the retention period has passed, it should be securely\u00a0deleted\u00a0rather than left to accumulate indefinitely. A system that\u00a0can&#8217;t\u00a0do either, keep data long enough or dispose of it properly, creates risk at both ends.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">Where This Actually Matters<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">This\u00a0isn&#8217;t\u00a0a hypothetical compliance exercise. It shows up in ordinary situations that most estates and facilities teams deal with at some point:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Security incidents.<\/strong><span data-contrast=\"auto\">\u00a0Theft,\u00a0vandalism\u00a0or\u00a0unauthorised\u00a0entry all raise the same first question: who had access to that area, and when. Without a searchable log, the answer starts with a shrug.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Contractor and visitor access.<\/strong><span data-contrast=\"auto\">\u00a0Contractors,\u00a0cleaners\u00a0and temporary staff often need short-term access to specific areas. When something goes wrong during that window, being able to pull an exact record of who was where matters far more than remembering who was booked in.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Staff turnover.<\/strong><span data-contrast=\"auto\">\u00a0People leave, change roles, or lose credentials. A clear log shows exactly when access was revoked and whether it was used after that point, which protects the\u00a0organisation\u00a0as much as it protects the departing employee.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Insurance claims.<\/strong><span data-contrast=\"auto\">\u00a0Insurers increasingly ask for evidence of access control and monitoring after a claim, not just confirmation that a system exists. A documented, searchable audit trail is what turns &#8220;we had security measures in place&#8221; into something an insurer can\u00a0actually verify.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Martyn&#8217;s Law readiness.<\/strong><span data-contrast=\"auto\">\u00a0For\u00a0organisations\u00a0already reviewing their access control approach ahead of Martyn&#8217;s Law, an audit trail is one of the clearest, most concrete things to get right. Under the Act&#8217;s Enhanced Tier, premises expecting 800 or more people are expected to carry out formal risk assessments and put in place reasonably\u00a0practicable\u00a0physical security measures. A searchable, time-stamped record of who accessed what is direct, demonstrable evidence that those measures\u00a0actually work, not just that they exist on paper.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Board and governance reporting.<\/strong><span data-contrast=\"auto\">\u00a0This is often the version of the question that actually gets budget released.\u00a0Facilities managers are\u00a0frequently\u00a0the influencers rather than the final decision-makers, and getting sign-off from senior leadership depends on being able to answer a different, harder set of questions: can you\u00a0demonstrate\u00a0that permissions align with defined roles? Can you evidence that access is revoked\u00a0immediately\u00a0when it should be? Can you produce a searchable audit trail on demand, in front of a board, a regulator or an auditor? An access control system that only answers &#8220;did the door open&#8221;\u00a0doesn&#8217;t\u00a0help here. One that produces a clear, searchable\u00a0record does.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>IT and infrastructure oversight.<\/strong><span data-contrast=\"auto\">\u00a0For IT managers increasingly involved in access control decisions, the audit trail itself is data that needs to be handled properly: stored securely, access to the logs restricted and recorded, and the system able to sit alongside existing infrastructure rather than as an isolated island. An audit trail that\u00a0isn&#8217;t\u00a0itself secure and well-governed undermines the case\u00a0it&#8217;s\u00a0meant to support.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">How\u00a0SimonsVoss\u00a0Systems Support This<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">This is exactly what\u00a0SimonsVoss&#8217;s\u00a0software platforms are built to provide. Access events are logged centrally against named credentials, giving estates and facilities teams a searchable record rather than a scattered set of assumptions. Permissions can be set,\u00a0changed\u00a0or revoked instantly when someone\u00a0leaves\u00a0or a credential is lost, and that change is itself recorded. Retention settings can be configured to match what the\u00a0organisation\u00a0actually needs, rather than defaulting to whatever the system happens to store by default.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The result is a system that answers &#8220;who accessed this building, and when&#8221; as a straightforward search, not a project.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">FAQ<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<p><strong>How long should access data be\u00a0retained?\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">There&#8217;s\u00a0no single legal minimum or maximum. UK GDPR requires you to keep data only as long as necessary for a documented, justifiable purpose, which for most\u00a0organisations\u00a0means balancing routine storage costs against the realistic time it takes for an incident,\u00a0claim\u00a0or investigation to surface. Many\u00a0organisations\u00a0retain\u00a0access logs for several months to a year, but the right period depends on your sector, risk profile and any specific compliance requirements that apply to you.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Can this data be used as evidence?\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">Access control logs can support an investigation or claim, but their evidential weight depends on the integrity of the system:\u00a0accurate\u00a0timestamps, credentials tied to named individuals, and a clear record of who can access and edit the logs themselves. A system that&#8217;s well configured and consistently used is far more useful as evidence than one bolted on as an afterthought.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>What&#8217;s\u00a0the difference between logging and monitoring?\u00a0<\/strong><\/p>\n<p><span data-contrast=\"auto\">Logging is the record itself, the who, where and when of every access event, stored for later review. Monitoring is watching that activity in real\u00a0time, or\u00a0setting up alerts for unusual patterns as they happen. A good access control system does both, but logging is the non-negotiable foundation. You\u00a0can&#8217;t\u00a0monitor\u00a0effectively, or\u00a0investigate after\u00a0the fact, without a complete log to work from.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">If\u00a0you&#8217;d\u00a0like a wider view of how this fits into a broader access control strategy, our\u00a0<\/span><a href=\"https:\/\/www.simons-voss.com\/en\/digital-locking-systems.html\"><span data-contrast=\"auto\">digital locking systems for compliance-ready buildings<\/span><\/a><span data-contrast=\"auto\">\u00a0page covers the core capabilities, audit trails included, that estates and facilities teams should expect as standard. And if\u00a0you&#8217;re\u00a0specifically weighing this up against Martyn&#8217;s Law, our piece on\u00a0<\/span><a href=\"https:\/\/blog.simons-voss.com\/en\/technology\/does-wireless-locking-comply-with-martyns-law\/\"><span data-contrast=\"auto\">whether wireless locking complies with Martyn&#8217;s Law<\/span><\/a><span data-contrast=\"auto\">\u00a0covers the tiered requirements and where the common compliance gaps sit.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Not ready to talk to a person yet? Get the\u00a0<\/span><a href=\"https:\/\/go.simons-voss.com\/hubfs\/UK\/SimonsVoss%20Martyn%E2%80%99s%20Law%20Whitepaper%202026.pdf\"><span data-contrast=\"none\">Access Control Readiness Checklist<\/span><\/a><span data-contrast=\"auto\">\u00a0first.\u00a0It&#8217;s\u00a0a practical, non-technical walkthrough covering access control, monitoring, staff training and audit-trail readiness, built to help you see exactly where your current setup stands before you make any changes.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Ready to see where your current setup stands?<\/span><\/b><span data-contrast=\"auto\">\u00a0<a href=\"https:\/\/www.simons-voss.com\/en\/who-we-are\/contact.html\">Speak to our UK team about audit-trail capability and what &#8220;meaningful retention&#8221; should look like for your estate.<\/a><\/span><a href=\"https:\/\/www.simons-voss.com\/en\/who-we-are\/contact.html\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An electronic access control system with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system\u00a0actually delivers\u00a0this in practice depends on how\u00a0it&#8217;s\u00a0configured and how long the data is kept.\u00a0 It&#8217;s\u00a0the question [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":6365,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[182],"tags":[],"class_list":["post-8733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sv-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How Do I Prove Who Accessed a Building?\u00a0 &#187; SimonsVoss Magazin<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Do I Prove Who Accessed a Building?\u00a0 &#187; SimonsVoss Magazin\" \/>\n<meta property=\"og:description\" content=\"An electronic access control system with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system\u00a0actually delivers\u00a0this in practice depends on how\u00a0it&#039;s\u00a0configured and how long the data is kept.\u00a0 It&#039;s\u00a0the question [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/\" \/>\n<meta property=\"og:site_name\" content=\"SimonsVoss Magazin\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-02T08:27:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-02T08:28:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2025\/06\/entreprise.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"667\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Bruce Donald\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bruce Donald\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/\"},\"author\":{\"name\":\"Bruce Donald\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#\\\/schema\\\/person\\\/cc07e3fde7637adbe87c4857ee31e681\"},\"headline\":\"How Do I Prove Who Accessed a Building?\u00a0\",\"datePublished\":\"2026-09-02T08:27:31+00:00\",\"dateModified\":\"2026-09-02T08:28:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/\"},\"wordCount\":3420,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.simons-voss.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/entreprise.jpeg\",\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/\",\"url\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/\",\"name\":\"How Do I Prove Who Accessed a Building?\u00a0 &#187; SimonsVoss Magazin\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.simons-voss.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/entreprise.jpeg\",\"datePublished\":\"2026-09-02T08:27:31+00:00\",\"dateModified\":\"2026-09-02T08:28:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.simons-voss.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/entreprise.jpeg\",\"contentUrl\":\"https:\\\/\\\/blog.simons-voss.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/entreprise.jpeg\",\"width\":1000,\"height\":667},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/sv-news\\\/how-do-i-prove-who-accessed-a-building\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Do I Prove Who Accessed a Building?\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/\",\"name\":\"SimonsVoss Magazin\",\"description\":\"Alles, was Sie \u00fcber digitale Schlie\u00dfsysteme wissen m\u00fcssen!\",\"publisher\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#organization\",\"name\":\"SimonsVoss Technologies GmbH\",\"url\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/blog.simons-voss.com\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/SV-logo.png\",\"contentUrl\":\"https:\\\/\\\/blog.simons-voss.com\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/SV-logo.png\",\"width\":600,\"height\":154,\"caption\":\"SimonsVoss Technologies GmbH\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/simonsvoss\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCv-1cCpIedcgsgZzGbOohdQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/#\\\/schema\\\/person\\\/cc07e3fde7637adbe87c4857ee31e681\",\"name\":\"Bruce Donald\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3edfaf47e835acdcaa05759f3aed4a7bb8f43ba857060feba2cae41170344f5?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3edfaf47e835acdcaa05759f3aed4a7bb8f43ba857060feba2cae41170344f5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3edfaf47e835acdcaa05759f3aed4a7bb8f43ba857060feba2cae41170344f5?s=96&d=mm&r=g\",\"caption\":\"Bruce Donald\"},\"url\":\"https:\\\/\\\/blog.simons-voss.com\\\/en\\\/author\\\/bruce\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How Do I Prove Who Accessed a Building?\u00a0 &#187; SimonsVoss Magazin","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/","og_locale":"en_US","og_type":"article","og_title":"How Do I Prove Who Accessed a Building?\u00a0 &#187; SimonsVoss Magazin","og_description":"An electronic access control system with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system\u00a0actually delivers\u00a0this in practice depends on how\u00a0it's\u00a0configured and how long the data is kept.\u00a0 It's\u00a0the question [&hellip;]","og_url":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/","og_site_name":"SimonsVoss Magazin","article_published_time":"2026-09-02T08:27:31+00:00","article_modified_time":"2026-09-02T08:28:44+00:00","og_image":[{"width":1000,"height":667,"url":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2025\/06\/entreprise.jpeg","type":"image\/jpeg"}],"author":"Bruce Donald","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bruce Donald","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#article","isPartOf":{"@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/"},"author":{"name":"Bruce Donald","@id":"https:\/\/blog.simons-voss.com\/en\/#\/schema\/person\/cc07e3fde7637adbe87c4857ee31e681"},"headline":"How Do I Prove Who Accessed a Building?\u00a0","datePublished":"2026-09-02T08:27:31+00:00","dateModified":"2026-09-02T08:28:44+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/"},"wordCount":3420,"commentCount":0,"publisher":{"@id":"https:\/\/blog.simons-voss.com\/en\/#organization"},"image":{"@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2025\/06\/entreprise.jpeg","articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/","url":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/","name":"How Do I Prove Who Accessed a Building?\u00a0 &#187; SimonsVoss Magazin","isPartOf":{"@id":"https:\/\/blog.simons-voss.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#primaryimage"},"image":{"@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2025\/06\/entreprise.jpeg","datePublished":"2026-09-02T08:27:31+00:00","dateModified":"2026-09-02T08:28:44+00:00","breadcrumb":{"@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#primaryimage","url":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2025\/06\/entreprise.jpeg","contentUrl":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2025\/06\/entreprise.jpeg","width":1000,"height":667},{"@type":"BreadcrumbList","@id":"https:\/\/blog.simons-voss.com\/en\/sv-news\/how-do-i-prove-who-accessed-a-building\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/blog.simons-voss.com\/en\/"},{"@type":"ListItem","position":2,"name":"How Do I Prove Who Accessed a Building?\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/blog.simons-voss.com\/en\/#website","url":"https:\/\/blog.simons-voss.com\/en\/","name":"SimonsVoss Magazin","description":"Alles, was Sie \u00fcber digitale Schlie\u00dfsysteme wissen m\u00fcssen!","publisher":{"@id":"https:\/\/blog.simons-voss.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.simons-voss.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/blog.simons-voss.com\/en\/#organization","name":"SimonsVoss Technologies GmbH","url":"https:\/\/blog.simons-voss.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.simons-voss.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2023\/07\/SV-logo.png","contentUrl":"https:\/\/blog.simons-voss.com\/wp-content\/uploads\/2023\/07\/SV-logo.png","width":600,"height":154,"caption":"SimonsVoss Technologies GmbH"},"image":{"@id":"https:\/\/blog.simons-voss.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/simonsvoss\/","https:\/\/www.youtube.com\/channel\/UCv-1cCpIedcgsgZzGbOohdQ"]},{"@type":"Person","@id":"https:\/\/blog.simons-voss.com\/en\/#\/schema\/person\/cc07e3fde7637adbe87c4857ee31e681","name":"Bruce Donald","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d3edfaf47e835acdcaa05759f3aed4a7bb8f43ba857060feba2cae41170344f5?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d3edfaf47e835acdcaa05759f3aed4a7bb8f43ba857060feba2cae41170344f5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d3edfaf47e835acdcaa05759f3aed4a7bb8f43ba857060feba2cae41170344f5?s=96&d=mm&r=g","caption":"Bruce Donald"},"url":"https:\/\/blog.simons-voss.com\/en\/author\/bruce\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/posts\/8733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/comments?post=8733"}],"version-history":[{"count":8,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/posts\/8733\/revisions"}],"predecessor-version":[{"id":8945,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/posts\/8733\/revisions\/8945"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/media\/6365"}],"wp:attachment":[{"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/media?parent=8733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/categories?post=8733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.simons-voss.com\/en\/wp-json\/wp\/v2\/tags?post=8733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}