Skip to content
IDMATICNET

Platform and the digital physical right

IDMATIC NET treats physical access as a governed right with grounds, constraints, validity and an evidential trail.

Definition

A digital physical right is a verifiable record defining the subject, the object of the right, the permitted action, the zone, the validity period and the grounds. The right is a managed entity: it can be approved, constrained, changed, suspended, revoked and completed.

An identifier — a card, a mobile device, a secure QR container, a biometric template — is a means of presenting the right, not the right itself. Replacing an identifier does not change the right, while revoking the right invalidates every associated identifier.

Subjects and objects of rights

SubjectsObjects of rights
EmployeesSite
VisitorsZone
ContractorsDoor
DriversTurnstile
PassengersVehicle
Key
Physical asset
Equipment

Architecture model

Core

Right data model, grounds, approval routes, policies, revocation lists and the audit journal.

Facade

Operator and requester interfaces, REST API, OpenAPI description, webhooks, event exchange and batch integration.

Edge

On-site decision execution, local store of rights and revocations, offline operation, event buffering and synchronisation.

Separation of responsibility between Core, Facade and EdgeData flows: policy downwards, events upwards.

Modularity and incremental rollout

The platform consists of functional modules: permanent access, visitors, contractors, vehicles, working time, keys, assets, equipment and mobile control points. Modules are enabled as the customer's processes become ready.

Rollout on top of existing infrastructure is possible. The set of integrated devices and external systems is determined during the survey stage: compatibility is confirmed for a specific model and version rather than declared in advance.

Deployment

On-premise

Hosted within the customer's infrastructure, including closed networks.

Cloud

Hosted in a cloud environment with centralised policy management.

Hybrid

Central governance with autonomous execution at sites and on mobile controllers.

Related pages