Walk into any George Street office tower and you’ll see both: a fob reader at the lobby, a keypad on the server room, and a physical deadlock on the back-of-house entry that nobody has touched in three years.
Sydney CBD businesses have layered access control onto physical locks over decades without much of a design framework. The result is systems that look comprehensive but have gaps that aren’t obvious until they matter.
Access control vs traditional locks Sydney CBD offices need to understand isn’t a binary choice — it’s a question of what each actually does, and where each one belongs.
What Access Control Really Does
Electronic access control — swipe cards, fobs, PIN keypads, biometric readers — manages who can open a door and logs when they do it. That’s it. The electronic credential authorises the request. The physical locking mechanism executes it.
This distinction matters because the two components fail independently. An access control system can be functioning perfectly while the physical lock it controls is worn, misaligned, or inadequate. The credential management is electronic; the forced-entry resistance is always physical.
What access control does well:
- Credential management at scale — adding, removing, and adjusting access for dozens or hundreds of users without cutting keys
- Access logging — timestamped records of who opened which door, essential for compliance and incident investigation
- Remote management — revoking access for a lost card or departed staff member from anywhere, immediately
- Time-based access — cleaners active only between 6pm and 8pm, contractors limited to specific floors
What access control doesn’t do: provide physical resistance to forced entry. The strongest access credential system in the building stops working the moment a determined person applies mechanical force to the door itself. The physical lock behind the reader is what determines how much force that requires.
Where Traditional Locks Still Matter
In Sydney CBD commercial buildings, physical locks remain the primary security mechanism in several specific configurations that electronic access control doesn’t adequately address:
After-hours physical security. Electronic access control manages authorised entry. It doesn’t physically resist unauthorised entry — that’s the deadlock’s job. A CBD office with card reader entry and a standard-grade deadlock behind it has a credential management system protecting a physical lock that may not resist sustained attack. The access control system is only as secure as the physical hardware it sits in front of.
Power failure and system outage. Electronic access control systems have backup power. Backup power has duration limits. In an extended outage, the fallback is physical. Every CBD building with access control should have documented physical key access for every controlled door — and that physical access should be audited, not assumed.
Service and maintenance access. Cleaners, building maintenance, fire safety inspectors — service access in CBD buildings often happens outside normal credentialed hours via physical key. The physical key management for these access events is frequently the least-managed part of a CBD building’s security system.
Emergency egress override. Fire exits in CBD buildings must allow exit without any credential — physical, electronic, or otherwise. The fire exit hardware is always physical. In buildings where access control has been applied to fire exit doors (which creates compliance problems), the physical egress hardware must still function unconditionally.
💡 Pro Tip:
For CBD office tenants managing their own tenancy access control within a building’s larger system: audit your physical key management annually alongside your electronic credential audit. Count the physical override keys for every access-controlled door in your tenancy. If you can’t produce a complete, documented count, the physical key management has drifted. Electronic audit logs tell you who badged in; they don’t tell you who has physical override access.
The Sydney CBD Office Access Setup
Most Sydney CBD office tenancies in commercial towers operate within a two-layer access system:
Building-level layer — managed by building management. Lobby access, lift destination control, car park, and common areas. The building’s access control platform manages credentials for this layer. Tenants interact with it but don’t control it.
Tenancy-level layer — managed by the tenant. The entry door to the specific floor or suite, internal meeting room and server room access, kitchen and amenities. This is where most CBD office security gaps live, because the tenancy layer is specified by whoever fitted out the space and managed by whoever happens to be responsible for it — often nobody specifically.
The friction point between the two layers: when a staff member leaves a CBD office, the building-level credential (access card) gets deactivated by building management. The tenancy-level physical key — if they had one for the back of house, the server room, or the fire stair access — often doesn’t get tracked or retrieved. The electronic layer is managed; the physical layer is assumed.
What Happens When Access Control Fails
Electronic access control systems fail in CBD buildings more frequently than most occupants realise, because most failures are invisible. A fob reader that doesn’t log entries. A credential database that hasn’t synced correctly across all doors. A card that works at the lobby but not at a specific internal door because the permission wasn’t correctly assigned.
The visible failures — doors that won’t open at all — get reported and fixed. The invisible failures — doors that open when they shouldn’t, or log entries that aren’t recorded — often aren’t discovered until an incident makes them relevant.
Physical locks don’t have invisible failure modes in the same way. A deadbolt either throws or it doesn’t. A cylinder either operates or it doesn’t. The failure is visible.
For CBD offices specifying or auditing their security setup, this asymmetry matters: electronic access control requires active monitoring to confirm it’s working as intended; physical locks require periodic mechanical assessment to confirm they’re functioning correctly.
“The CBD tenancies that call us after a security incident have almost always had the same conversation: the access control system showed no unauthorised entry, the logs were clean, but the back-of-house physical lock had a cylinder that hadn’t been changed in five years and had a key count nobody could account for. The electronic layer was fine. The physical layer was the gap. Both need active management — they’re not interchangeable.”
— Locksmith, Sydney CBD
Choosing the Right Security Combination
The framework that produces the right access security setup for a Sydney CBD office tenancy:
Primary tenancy entry: Access control with card or fob credential plus a physical deadlock rated to AS 4145.2. The electronic layer manages daily access; the physical layer provides forced-entry resistance. Both are required. Neither alone is sufficient.
Internal restricted areas (server room, records room, executive suite): Physical deadlock with restricted key blanks and documented key management, with access control logging if the compliance requirement warrants it. These areas are typically accessed by a small number of people; key management at this scale is more practical than credential management.
Service and back-of-house entries: Physical deadlock with master key system integration. Service access happens via physical key under documented authorisation. This layer is frequently the least-considered and most often the security gap in CBD tenancy audits.
Fire exits: Physical egress hardware only, conforming to BCA requirements. No credential requirement, no lock that impedes exit from inside. Electronic monitoring of fire exit door status (open/closed sensor) is acceptable; credential control of fire exit egress is not.
⚠️ Warning:
If your CBD tenancy’s access control system includes a card reader on a fire exit door that prevents exit without a valid credential, this is a Building Code of Australia compliance violation regardless of how the system was specified or installed. Fire exit doors must allow egress from inside without any credential during occupancy. If this configuration exists in your tenancy, it should be corrected before the next fire safety inspection, not after.
Managing Keys Alongside Access Control
The most common CBD office security gap isn’t the access control system itself — it’s the physical key management running alongside it.
Most CBD commercial buildings have physical override keys for every access-controlled door. Building management holds a set. Facility management may hold another. The previous tenant’s facilities manager may have held one and not returned it at end of tenancy.
For CBD office tenants taking over a new space:
- Request a complete physical key audit from building management as part of the fitout handover — not as an afterthought
- Confirm that cylinders on tenancy-controlled doors were changed at end of previous tenancy
- Establish a documented key register for every physical key issued to tenancy staff
- Confirm the integration between your electronic credential management and the building’s master key system — particularly whether building management emergency physical override access extends to tenancy-controlled areas
A CBD office where the electronic access logs are clean and the physical key management is undocumented is a system with one layer working well and another not managed at all.
The Compliance Side of Office Security
Several CBD office categories have compliance requirements that directly specify security standards:
Legal practices holding client records. Medical suites with patient data.
Financial services with regulatory requirements around information security. Government-adjacent tenancies with specific fit-out standards.
For these occupants, the access control vs physical lock question isn’t just operational — it’s a compliance specification that the relevant regulator or lease condition defines. Confirming what the applicable standard requires should happen before any security system is specified, not after a compliance audit surfaces a gap.