Back

Airport Access Control Systems: Zones, Badging, Compliance

A guide to airport access control systems: security zones, badging programs, TSA Part 1542 compliance, and the audit trail records inspectors look for.

Stu Waters
Stu Waters
Published
Sep 10, 2026

An airport access control system regulates who can move through the restricted areas of a terminal and the airside operation. Credentials and permissions define where each badgeholder is authorized to go, and controlled entry points record where they actually went. Perimeter security protects the airport's outer boundary. Access control decides who can open the doors inside it.

Under 49 CFR Part 1542, a TSA-regulated airport has to prove both halves of that: that only authorized people reach the secured area, and that it can show who reached it.

That gets complicated once thousands of badgeholders answer to no single employer. Airlines, contractors, ground handlers, tenants, and vendors each bring people who need access to different parts of the airport, and none of them share a common system for tracking who is still authorized. Your access control system has to keep those permissions current: issuing and renewing badges, changing access when someone's role changes, removing credentials when people leave, and holding a record of who was authorized to enter each controlled area.

One scope note before the detail. At a large commercial service airport running an incumbent enterprise physical access control system (PACS) under a TSA-approved security program, Coram is not a replacement for that core system, and this guide does not pretend otherwise. Coram's fit at those airports sits around the core system: tenant spaces, landside doors, and adjacent facilities. At general aviation airports and FBOs, it can serve as the primary system. Everything below is written to be useful either way.

This guide covers the zone structure, the differences between commercial and general aviation requirements, badge administration, contractor access, and the records inspectors expect to see.

How airport access control is structured

Airport access control makes the most sense when you trace one person's movement through the building. A passenger walking into the terminal does not need the same access as a baggage handler, an airline employee, or a maintenance contractor working airside. Each person's access should match where they work and what they are authorized to do.

The layered zone model

The four zones that matter are defined in 49 CFR 1540.5, not in Part 1542. Part 1542 imposes the duties. Part 1540 supplies the vocabulary, and the definitions carry more weight than they look like they do.

  • Public / landside: Areas open to passengers, visitors, and the public. These generally do not require an airport credential.
  • Sterile area: The passenger area beyond the security checkpoint, where access is controlled through the screening process.
  • Secured area: A portion of the airport, specified in the airport security program, in which certain individuals are authorized unescorted access. It covers areas such as passenger enplaning and deplaning, baggage handling, and aircraft operations.
  • AOA (air operations area): A portion of the airport specified in the security program that includes aircraft movement areas, aircraft parking areas, loading ramps, and safety areas, plus adjacent areas such as general aviation areas that are not separated by adequate security measures. The AOA does not include the secured area.
  • SIDA (security identification display area): A portion of the airport, specified in the airport security program, in which the security measures of the part are carried out. The SIDA includes the secured area and may include other areas of the airport.

These are not one escalating ladder, and reading them that way is where most zone diagrams go wrong. The actual relationship:

  • Every secured area must be a SIDA (1542.205(a)(1)).
  • A SIDA can extend beyond the secured area into other parts of the airport.
  • The AOA is a separate zone that excludes the secured area, and an operator may designate all or portions of its AOA as a SIDA (1542.203(b)(5)).

The FAA puts the same relationship plainly in the Aeronautical Information Manual, paragraph 2-3-15: a SIDA is a limited access area requiring a badge issued under Part 1542, the AOA may or may not be a SIDA, and a secured area always is.

Which doors and portals are controlled

Most of the work happens where one controlled area meets another. Depending on the airport, that includes:

  • Jet bridge doors, restricting movement between passenger areas and aircraft-side operations.
  • Baggage handling and screening areas, limiting entry to employees who need it for baggage operations.
  • Ramp access doors, controlling movement between terminal or operational buildings and airside.
  • Secure corridors, preventing free movement between areas with different authorization requirements.
  • ATC and equipment rooms, restricting access to personnel whose jobs require critical operational spaces.
  • Tenant back-of-house areas, covering airlines, ground handlers, concessions, and cargo operators.

An airline employee, a baggage handler, a maintenance contractor, and a concession worker may all carry valid credentials. Their permissions should reflect their actual responsibilities. Which zone a badge opens is the whole of what an airport security coordinator has to keep accurate.

Where perimeter control ends and access control begins

Airport perimeter security and access control solve different problems, and they meet at specific points: a vehicle gate that is both a fence line and a badge reader, a cargo dock that is part of the airport boundary and a controlled interior door. Perimeter systems answer whether someone breached the property line. Access control answers whether the person standing at a specific door is authorized to open it. An airport that treats the two as interchangeable tends to have gaps at exactly those overlap points.

Not every airport operates under the same rules

The right approach depends heavily on what kind of airport you are running.

Commercial service airports under a TSA-approved security program

At a major commercial airport, you operate inside an approved security program with defined restricted areas, established badging processes, and set procedures for determining who receives unescorted access. TSA reviews and approves these programs under 49 CFR Part 1542.

Any access control change has to work inside that program, that badging process, that infrastructure, and that set of stakeholders. With thousands of employees, contractors, tenants, and other badgeholders relying on the system, replacing an enterprise PACS outright is rarely realistic. Modernization happens in pieces, usually starting at the edges.

General aviation airports and FBOs

General aviation airports serve private, business, recreational, training, and other non-scheduled activity. The FAA classifies them separately and states that Part 139 certification typically does not apply to general aviation airports.

With fewer badgeholders and access points, issuing credentials, changing permissions, revoking access, and reviewing activity often falls to an airport manager or a small operations team. Cloud-managed systems are a practical primary option at that scale, where the airport's requirements and existing infrastructure support them. TSA publishes General Aviation Security Guidelines covering recommended practices for GA airports and operators. Work from your own security program and applicable TSA and FAA guidance for any specific requirement.

Tenants, cargo, and airport-adjacent facilities

Airports house airlines, ground handlers, cargo operators, concessionaires, MRO teams, and contractors who manage their own employees inside the airport's security environment. Each organization needs access suited to its work; permissions change as people join, leave, or switch roles; and the airport still needs visibility into who can enter the areas it controls.

Keeping tenant-level permissions aligned with the airport's own security posture is the harder problem. The same applies to cargo, MRO, and rental-car facilities that run their own day-to-day access while sitting inside the airport's security boundary.

The two technology buckets you are choosing between

Facility type is one axis. The other one, which most guides skip, is the technology bucket:

  • Legacy enterprise PACS. Lenel, Software House, AMAG, Genetec and similar. Deep integration, heavy administration, on-premise servers, and long procurement cycles. This is what the core of a large commercial airport runs on, and it is not going anywhere quickly.
  • Cloud-managed platforms. Faster to administer, browser-based, and easier to scope by tenant. Lighter on integration depth with legacy aviation systems.

Most airports end up running both for a period. The useful question is not which bucket wins, but where the boundary between them sits and who owns each side of it.

Badging consumes more staff time than anything else in the program

For regulated airports, granting unescorted access involves identity verification, a fingerprint-based criminal history records check, required approvals, and issuance of a badge tied to that person's authorization. The work does not stop at issuance. Role-based access keeps permissions aligned with a person's job. The rest is ongoing: renewals, revoked or lost badges, and employee changes.

Vetting and issuance

Before someone receives unescorted access to a restricted area, the airport has to establish that they are eligible for it.

  • Identity and background checks. 49 CFR 1542.209 requires a fingerprint-based criminal history records check (CHRC) for individuals seeking unescorted access authority.
  • SIDA access. A SIDA badge is issued under the procedures in Part 1542, and movement into or through the area requires authorization and displayed identification.
  • Application and issuance. The badge office processes the applicant, completes the applicable vetting and approvals, issues the credential, and ties it to the right authorization.
  • Ongoing administration. Every new employee, contractor, or tenant worker adds another record to maintain.

TSA also publishes best-practice guidance for airport badge offices covering staff training, document verification, software, and issuance procedures. TSA describes it explicitly as guidance rather than a regulatory requirement, so treat it as operational context and not a compliance checklist.

Scoping access by role and tenant

Permissions should match the role, not the credential type. An airline employee may need broad operational access while a tenant employee needs three doors. Two people at the same employer can legitimately end up with different permissions. Issuing a badge should also mean confirming that its permissions match the areas that person actually needs.

This is ordinary role-based access control applied to a tenant population, and it is worth writing down. A physical access control policy that names who approves access to which zone is what stops permissions drifting upward one exception at a time.

Renewal, revocation, and lost credentials

Under 49 CFR 1542.207(a)(2), access control measures must ensure that an individual is immediately denied entry to a secured area when that person's access authority for that area is withdrawn. Not at the end of the week. Immediately.

Section 1542.207(d) covers secondary access media: an airport may issue a second credential to someone temporarily without their original, provided its procedures verify the person's authorization, restrict the time period of entry, retrieve the second medium when it expires, and deactivate the original until the second one is returned. The public text sets no numeric day limit. That detail lives in the airport's security program.

Badge audits and reconciliation

Two numbers govern this, and only one of them is a recommendation.

Section 1542.211(a)(3)(iv) requires airports to audit the identification media system at a minimum of once a year, or sooner as necessary, to ensure the integrity and accountability of all identification media.

The 5% figure is a requirement, not a best practice. In its FY2017 report to Congress on SIDA airport security, DHS states that TSA's regulations and security programs require badge audits and require workers to be rebadged when an airport exceeds 5 percent of unaccounted-for credentials for secured areas, sterile areas, or the AOA. The threshold applies per access category. Crossing it triggers a mandatory rebadge of that category, which is a very different operational event from a finding letter.

That makes the annual audit a dated obligation with a known cost of failure attached, which is the practical reason to fix badge reconciliation before the audit month rather than during it. Funding usually comes out of the airport's capital program rather than an operating line, so the real question is which capital cycle the work lands in.

Reconciliation is also where multi-employer airports lose the thread. A ground handler's contract ends in March, the airport is told in June, and twelve badges sit active in between. That gap is the finding.

Escort, contractors, and temporary access

Escorted access lets an airport grant temporary entry without issuing a permanent credential. Construction crews need to reach a work site, vendors need to service equipment, delivery drivers need a controlled loading dock.

  • Sponsorship. Establish who the visitor is, why access is needed, where they need to go, and how long the visit should last.
  • Escort. Under 49 CFR 1542.211(e), the escort must have unescorted access authority for the area and must continuously accompany or monitor the individual, closely enough to identify activity outside the approved purpose.
  • Temporary identification. Where temporary media are issued, procedures need to control how long the credential stays valid and ensure it is retrieved or otherwise accounted for.
  • Escort ratios. The appropriate ratio and supervision requirements should come from the airport's approved security program, not from a generic industry rule.
  • Recordkeeping. Log who entered, who sponsored or escorted them, the area, the purpose, and the period of access.

A contractor who needed two days for a repair should not still appear as an authorized visitor in August.

What auditors and inspectors ask for

An inspection asks whether access is being controlled as intended. The inspector may look at how credentials are issued and managed, who is authorized to enter restricted areas, and whether the airport can produce records showing that access happened under that authorization. Part 1542 requires measures that prevent and detect unauthorized entry, presence, and movement in the secured area.

Audit trails and reporting

A useful access record answers five questions about any event:

  • Who used the credential? The record should identify the person, not just the card number.
  • Which door did they use? The event should identify where access occurred.
  • When did it happen? A reliable timestamp.
  • Were they authorized for that area? Including whether they were authorized for the entire secured area or only a portion of it, which 1542.207(a)(3) requires you to be able to differentiate.
  • Can the event be investigated further? Where video is available, matching the access event to footage shows what happened at the door.

A facility that can answer all five owns a complete audit trail. Person, location, time, authorization, each one connected to the others.

Common findings

The same handful of findings show up in inspection after inspection:

  • Stale credentials. Authorization changed; the badge did not.
  • Incomplete access records. The system cannot produce enough information to explain an event.
  • Unreconciled badge counts. Active credentials do not match current employment or authorization records.
  • Undocumented escorts. No clear account of who was brought in, why, or who was responsible.
  • Overly broad permissions. A credential opens more than the person was authorized to enter.

All five point at one question: can the airport prove that the people entering its secured areas are the people it authorized to be there?

Where airport access control programs break down

Audit findings are symptoms. The operational patterns underneath them show up in the same few places.

Credential sprawl across tenants

One tenant sends new employees, another removes a contractor, and those updates have to be reconciled continuously against the badges and permissions already in the system, not just at audit time. Every active credential has to keep belonging to an authorized person.

Piggybacking and tailgating at interior doors

A badge reader can confirm that an authorized credential was presented. It cannot confirm that only one person went through the door. Someone follows an employee through, or the employee holds it open for them. This matters most where a door separates two restricted areas and every person crossing it is supposed to be individually authorized. Our guide on tailgating versus piggybacking covers the distinction.

Detection is the part worth specifying in an RFP. Coram Access Control generates a tailgating alert as one of its standard door alert types, alongside held-open, forced-entry, tamper, and low-battery alerts. Ask any vendor whether the condition raises an alert or only appears in a log someone has to go read.

Deprovisioning lag

The lag is the window between the day authorization ends and the day the system reflects it. An employee leaves on the 15th, HR closes the record on the 20th, the badge office hears about it on the 28th. Access stays live for thirteen days.

The mechanism that closes that window is identity integration, not diligence. Where an access control system reads from your identity provider, a disabled account can cascade to door permissions. Coram supports SAML and OIDC for single sign-on. Automated user provisioning and deprovisioning through SCIM is not available today, so if HR-driven deprovisioning is a hard requirement for your airport, ask every vendor on your list to demonstrate it rather than describe it.

Access logs that do not reconcile with video

The gap shows up at 10:15 a.m. on a Tuesday, when the log names a credential and the investigation needs a person. Staff go looking in a second system for footage that may or may not be time-synced to the first, and the answer arrives an hour later than it should have.

When door events and video sit together, the team sees the credential, the door, the time, and the footage in one place.

Evaluating an airport access control system

Start with what your team deals with every day rather than a feature list. These questions are worth asking every vendor, including us.

1. Will it work with your existing readers and credentials? Wiegand and OSDP readers are widely supported, including by Coram. Existing cards usually carry over if they are unencrypted; encrypted cards typically do not. Ask for the rule, not a reassurance, and confirm the panel question separately, because most cloud platforms replace the panel even when they keep the readers.

2. Can you scope access by tenant and role? Different organizations and employees need different access. Permissions should be easy to assign and update without defaulting to broad access.

3. What does the audit export actually show? Ask to see one. Check whether it names the person, the door, the time, and the authorization associated with the event, and whether you can filter it by area for a reconciliation.

4. What happens during a network outage? With Coram, doors keep making decisions locally: existing schedules continue to apply, existing permissions stay enforced, existing cards and PINs keep unlocking doors, and events log locally. Queued events sync when the connection returns, with no audit data lost. Ask other vendors the same question and listen for whether events survive the outage or just the unlocking.

5. How are badge audits handled? Look at how easily your team can review active credentials, spot outdated access, and reconcile badges against current authorization before the annual audit rather than during it.

6. Can you see the video tied to a door event? Where a platform pairs door events with footage, an investigation stops being a two-system exercise. Confirm whether that pairing requires the vendor's own cameras.

7. How deep does identity integration go? SSO is table stakes. Ask specifically about SCIM provisioning from Entra ID, Okta, or an HR system, and about whether group membership changes flow through automatically. This is where cloud-managed entrants, Coram included, are generally behind mature enterprise PACS.

8. What is the mobile credential story? If you expect to move part of your badgeholder population to phones, ask which credential standards are supported and what reader hardware that requires.

9. What happens to your data and your doors if the vendor is acquired or the contract ends? Airports run 15-year infrastructure cycles. Ask about export formats, local survivability, and what an exit looks like.

If a vendor cannot answer the outage question on the call, that is your answer.

Two adjacent reads if you are earlier in the process: access control system components covers what sits behind the door, and physical access control systems covers the general architecture. For non-aviation badging programs specifically, our guide to badge access control systems goes deeper on issuance and card technology without the Part 1542 layer.

Where Coram fits

Access Control is one of four product lines on the Coram platform, alongside Video Security, Guest Management, and Emergency Management. That matters here for one specific reason: the audit trail this article keeps arriving at is stronger when the door event and the video of that door live in the same system instead of two.

Coram Access Control is cloud-managed and works with existing card readers, locks, and wiring. Where the readers are compatible, you keep them. Unencrypted existing cards carry over. The control panel is replaced.

Capabilities

  • Unified audit logs. Access records in one place, filterable for review and reconciliation.
  • Simpler credential administration. Issue a badge, change a role, revoke access, without a ticket to a systems integrator.
  • Works with existing readers and wiring. Wiegand and OSDP supported, including 125 kHz proximity on the included DR-U1 reader.
  • Door alerts that fire. Tailgating, held-open, forced entry, tamper, and low battery.
  • Video-linked access events. Where Coram cameras are deployed, each door event carries its clip.

Limitations

Coram is newer than the incumbent enterprise PACS platforms used in the most heavily regulated commercial-airport deployments. For those airports, it is not a replacement for the established core system. Its fit is at the tenant, landside, or adjacent-facility level, while GA airports, FBOs, and similar operators can use it as a primary system.

Two other honest boundaries: the control panel gets replaced rather than integrated, so Coram does not sit on top of an existing Brivo, HID, or S2 head end. And SCIM-based automated provisioning is not available today.

What to do next

Map your current credentialing process first: who sponsors, who approves, who issues, who revokes, and where each step waits on someone else. Then check your last badge reconciliation against your next audit date and see how much of the gap is manual work.

If you want to go deeper before talking to anyone, access control system components and our physical access control policy guide are the two most useful next reads. If you are a GA airport, FBO, or airport-adjacent operator and want to know whether Coram fits your setup, our team can walk through your reader and panel configuration with you and tell you where it does and does not.

FAQ

What is an airport access control system?
What is the difference between airport perimeter security and access control?
What are SIDA, AOA, and the secured area?
Who needs an airport badge, and how is it issued?
How often should airport badge audits be conducted?
Can airports keep existing readers when upgrading access control?
Do general aviation airports need access control systems?
What records do TSA inspectors expect from an access control system?

Get an Instant Quote