Secure by Design: Rethinking Access Control Around Real-World Behavior
Key Highlights
- Access control often fails because it doesn't consider how people behave under pressure or when in a rush.
- Redesigning systems around user needs—like self-service portals and biometric verification—can significantly reduce delays and workarounds.
- Clear feedback at entry points and intuitive admin interfaces improve compliance and reduce security risks.
- Small, targeted design improvements can address friction points without complete system overhauls.
- When security measures are easy and fast to use, users are more likely to follow the rules, enhancing overall security.
On a busy Monday morning, a member of staff arrives at a controlled entry point, hands full and running late. They badge in, hold the door, and the person behind them walks through without presenting a credential. Just like that, vulnerability exists.
In most cases, fingers are pointed at a flawed policy or insufficient training.
But I'd like to introduce a third problem that doesn't get highlighted as much as possible: not designing around human behavior. Because in this scenario, the system made it easier to let someone follow you in than to enforce the rule.
The Gap Nobody Talks About
Access control is typically designed around the system's needs: authentication, authorization, and auditing. What isn't always taken into consideration are the people using it: how they move, what they’re carrying, or how much patience they have at 8:47 on a Monday morning.
That gap is where human behavior takes over. Under pressure, in a rush, or simply on autopilot, people make the quickest decision available to them. If the system hasn't made the secure option the easiest one, that decision won't always be the right one. The industry's default response is to push more training and stronger enforcement, but that only papers over the gap.
The question worth asking isn’t whether users are following the rules; it’s whether the system is making the rules easy to follow.
What Good Design Actually Delivers
This isn't theoretical. Real deployments show what happens when access control is redesigned around the user rather than the policy.
Tampa General Hospital's workforce had to rely on helpdesk support whenever they were locked out of an account. This was a slow, frustrating process that took an average of 4.5 days to resolve. In a busy clinical environment, that kind of friction doesn't just inconvenience people; it encourages them to find shortcuts. They replaced the process with biometric verification so that staff could complete it themselves, resulting in a drop-in resolution time from 4.5 days to 20 minutes. For clinical staff, that's the difference between a frustrating multi-day wait and getting back to work within the hour.
At the University of Basel, new employees and associates waited weeks for their physical access cards and system credentials to be processed manually. Starting without access doesn't just slow people down; it pushes them toward informal arrangements, borrowed credentials, and workarounds that become habits. A central self-service portal changed that, letting users request access and upload their own ID photo with automated approval flows handling the rest. System access now arrives within minutes or hours, and physical access cards within a few days rather than weeks.
For a new employee, that's the difference between starting a new job frustrated and starting it ready to work.
Agora's 6,000-employee site in Budapest was running on cards and fobs, and the friction of that system was showing up as tailgating risk at the door. When entry feels like an obstacle, people hold doors open, wave colleagues through, and avoid confronting someone. Facial biometric access replaced the cards, with self-enrolment on tablets and entry logic designed to keep movement touchless and fast. That meant bottlenecks disappeared, crowding was eliminated, and tailgating risk was addressed through design rather than relying on staff to enforce the rule.
For 6,000 people moving through that building every day, the secure path became the effortless one. Three deployments, three different contexts, the same principle: when you design for how people actually behave, security improves alongside the experience.
Where to Start Without Starting Over
None of these organizations rebuilt from scratch. They identified specific points of friction and redesigned those interactions.
Look at where your users are struggling. Where are the support calls coming from? Where are the workarounds happening? Where does the process take longer than it should? Those are your design problems and your biggest opportunities.
Here are four starting points worth examining in almost any access control deployment:
Credential recovery
If regaining access after a lockout requires a helpdesk call, that’s a solvable design problem. Self-service recovery flows with clear interface guidance can resolve this and remove the frustration that affects every user who gets locked out.
Onboarding
First impressions shape long-term behavior. If new users hit a wall on day one, they’ll find ways around the system for as long as they’re in the building.
Entry feedback
Does the reader clearly tell the user what just happened? Denying entry without explanation creates hesitation and tailgating opportunities. Clear, immediate feedback — a specific message, a distinct sound, or an unambiguous light — changes behavior at the door.
Admin interfaces
If the people managing your system find it hard to navigate, permissions drift, alerts get ignored, and configurations go stale. Access rights linger too long when approval logic is hard to interpret. Alerts get dismissed when urgency isn’t clear. Exception requests go unresolved when the process requires too many steps. None of that is negligence; it’s what poor interface design produces.
The Opportunity
Design investment in access control is still in its early stages. Most products were designed by engineers who solved technical problems, and they did so well. But the user experience layer hasn't kept pace, and that gap is now a differentiator for manufacturers, integrators, and consultants willing to close it.
For manufacturers, it's an opportunity to build products that people actually want to use. For integrators and consultants, it's a conversation worth having at the specification stage because a system that works well for its users performs better in the field and generates fewer callbacks.
Design that path well, make it fast, clear, and frictionless, and the secure choice becomes the obvious one. When the secure path is also the easiest path, people take it. That's not just a design ideal; it's what happens when access control is designed to work with human behavior rather than against it.
About the Author

Vikrant Pelia
freelance Product Designer specializing in the physical security industry.
Vikrant Pelia is a freelance Product Designer specializing in the physical security industry. With experience spanning design, product strategy, and marketing, he brings a commercial perspective to user-centered product design — helping security companies design access control products and experiences that work better for the people who use them every day. Reach him at [email protected].
