What you need to know
Anti-passback depends on reliable door-position state, entry and exit topology, controller communication, and a method to correct occupancy state after exceptions.
Potentially affected
AXIS Camera Station Secure Entry deployments using anti-passback to limit credential sharing or enforce entry and exit sequence.
DSE recommendation
Model the complete movement zone, prove every sensor and reader path, document offline behavior, and establish an authorized state-reset and exception process.
Bottom line: anti-passback is a state machine, not a reader checkbox. If the system misses an exit, accepts a door state incorrectly, or loses coordination across controllers, a valid user can be denied and the occupancy record can become unreliable.
Source fact: the feature has explicit sensor and topology dependencies
The AXIS Camera Station Secure Entry User Manual documents anti-passback modes and configuration. It states that doors participating in anti-passback need door-position sensors. It describes hard, soft, and timed behavior and explains that some offline operation depends on the relevant doors being connected to the same controller. The manual also places conditions on a zero timeout, including reader coverage on both sides.
These dependencies mean a logical area must match the physical route. An unmonitored emergency exit, propped door, elevator, gate, or door on another controller can change a person’s actual location without producing the transition that the anti-passback state expects.
Source boundary and applicability
The manual applies to compatible Axis products and documented versions. It does not establish that anti-passback is suitable for a life-safety, labor, occupancy, privacy, or high-security requirement. The feature does not prevent tailgating by itself and should not be treated as an authoritative people count. Fire and emergency egress must remain compliant.
Applicability questions
- What physical area and every legitimate entry, exit, transfer, and emergency route form the zone?
- Are door-position sensors installed, supervised, aligned, and mapped correctly?
- Are paired doors on one controller when offline behavior depends on it?
- Should a violation deny access, log an exception, or clear after a defined time?
- Who may reset a person’s state, for which reasons, and with what audit evidence?
DSE recommendation: commission movement sequences and state repair
The following steps are DSE recommendations based on the cited source.
Draw the zone with readers, sensors, controllers, doors, gates, stairs, elevators, emergency exits, and alternate routes. Test correct entry and exit, repeated entry, repeated exit, tailgating observation, held and forced door, missed sensor transition, credential use at two points, controller offline state, server loss, and reconnection. Use test identities and an approved window so no person is trapped or denied required egress.
Define hard, soft, or timed handling from the operational consequence. Create a least-privilege reset procedure that records identity, old state, corrected state, reason, approver, operator, and related incident. Reconcile state after evacuation or a broad emergency release.
Verification and evidence
Retain the zone drawing, version and controller topology, sensor tests, configuration export, sequence matrix, access and violation events, offline and recovery results, reset audit, emergency reconciliation procedure, and acceptance signatures. Re-test after route, reader, sensor, controller, timeout, or software changes.
Official references
- AXIS Camera Station Secure Entry User Manual – Axis Communications
Review the official source
AXIS Camera Station Secure Entry User Manual · Verified August 25, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE