A 40-story commercial tower with 300 tenants and 800 card readers needs centralized access management. A six-unit medical office building with three common doors and tenant-specific suite entrances probably does not. The question is not which architecture is better in the abstract — it is which architecture fits the operational reality of the building. In multi-tenant properties, the operational reality often includes independent tenant move-in/move-out schedules, limited on-site IT staff, and lease agreements that give each tenant control over their own suite access.
Standalone Access Control: One Door, One Brain
A standalone access controller is a self-contained unit that manages a single door or a small cluster of doors. All credential data — PIN codes, card serial numbers, biometric templates — is stored locally on the controller. Programming is done at the door via a master card, a built-in keypad, or a Bluetooth connection from a service app. There is no server, no database to maintain, and no dependency on a network connection for door operation.
The architecture maps naturally onto multi-tenant buildings. Each tenant suite door can have its own standalone controller, programmed and managed by the tenant themselves through a master credential. The building owner maintains a separate set of standalone controllers on common-area doors — lobby, parking garage, stairwell — without the two credential databases ever needing to synchronize. A panel like the Vauban Systems VERSO+ 220 integrates a TCP/IP access control panel with its own power supply, supporting up to 2,200 users per door without requiring a dedicated server or software license — a practical scale for most multi-tenant buildings where per-door user counts rarely exceed a few hundred.
When Standalone Hits Its Ceiling
The limitation of standalone architecture crystallizes at scale. If a tenant with 50 employees leaves the building, an administrator must visit every door that tenant had access to — potentially 10–20 doors across suites, common areas, and parking — and delete credentials one controller at a time. With PC-based centralized management, that same offboarding is a single operation: disable one user record, and every door in the system updates on the next credential check or via a scheduled push. The same logic applies to time-based access schedules, temporary visitor credentials, and audit trail retrieval — all possible with standalone but operationally burdensome beyond about 20–30 doors.
PC-Based Centralized Access: Power at a Price
A PC-based system runs access control management software on a dedicated server or VM, communicating with door controllers over the LAN. All credentials, schedules, and audit logs reside in a central database. The operational advantages are real: global user management, real-time event monitoring, integration with video management systems (VMS) for door-forcing alerts, and automated reporting for compliance. The costs are equally real: the server hardware or VM, the software license (often priced per door or per reader), the IT overhead of maintaining a Windows or Linux server with regular security patches, and the single point of failure — if the server goes down, administrators lose the ability to add or revoke credentials (though doors continue to operate from cached controller memory).
Decision Rule: Count the Doors, Then Count the IT Staff
The threshold where PC-based management becomes cost-justified is not a fixed door count — it is the number of user changes per door per month. A building with 50 doors but only 2–3 tenant turnovers per year and stable access schedules will run efficiently on standalone controllers for a decade. A building with 15 doors but daily visitor processing, frequent tenant churn, and compliance-driven audit requirements will outgrow standalone controllers within its first year of operation. For the physical security layer beyond access control, explore our safety and security category for complementary systems including alarm annunciators, safety gate switches, and emergency stop devices.



