Start your EVOTECH request in under a minute.
Access Reader Credential Loading in Katy, TX 77493
A badge that opens a door is the last link in a chain that starts with a number nobody has ever actually looked at. Across 77493 — the new commercial ground north of the interstate, the learning centres and church campuses off Clay Road, the flex bays along Katy-Hockley — most reader systems were installed by a builder’s sub, handed over with a sealed box of cards, and never documented again. Credential loading turns that box into a roster you can defend.
Loading a credential is three separate acts, and any one of them can be skipped
Putting a card into an access system sounds like one operation. On every platform we work on it is three, and because they complete independently a card can be genuinely present in the database and still refuse to open anything.
First comes enrolment of the credential itself: the controller must hold the number the card transmits, in the format the reader is sending. Second is binding that number to a person. Third is authorising that person by attaching them to a group naming doors and hours.
Skip the third and the reader beeps, the indicator changes, the controller logs a clean read, and the door stays shut. The event reads something close to no access level. It is the most common call we get from an office manager who issued a badge an hour earlier.
- Number enrolled, nobody attached: the door opens, but your history shows a digit string instead of a person.
- Person created, number never captured: every presentation is logged as an unknown card and denied.
- Both done, no group assigned: a textbook denial at every reader, which looks exactly like a dead card and is not one.
The digits printed on the fob are usually not the digits the panel stores
Ask anyone to read you the number on their badge and they will read the ink. Whatever is hot-stamped or laser-marked on the outside is a convenience for whoever hands cards out. What your controller cares about is the value encoded inside, and those two agree only when the cards were ordered that way and the stock was never mixed.
Re-orders are where it comes apart. A site buys fifty more badges four years later, the new batch is stamped from one, the original batch started somewhere else, and two cards in the same drawer now carry identical ink over completely different encoded values. Type the ink into the cardholder screen and the panel stores a number no reader will ever transmit.
The dependable way to capture a credential is to make the system report what it actually heard:
- Present it and read the log. Badge the unknown card at a working reader; the denial event on most platforms carries the raw card number and facility code received. That value is true by definition.
- Use an enrolment reader. A desktop USB reader at the administrator’s machine drops the encoded value straight into the record with nobody typing anything.
- Type the ink last, and only after one card from that batch has been checked against a live read.
26-bit, 35-bit, 37-bit: why a perfectly good card becomes invisible
A card does not transmit a number. It transmits a string of bits, and the configured format tells the controller where to cut that string into fields. Choose wrong and the same physical card yields a different decimal value, or nothing the panel accepts. Three formats turn up constantly in Katy commercial buildings:
| Format | How the bits divide | Why it matters to you |
|---|---|---|
| 26-bit (H10301) | 8-bit facility code (0–255), 16-bit card number (1–65,535), plus two parity bits | The open industry default. The address space is small enough that two unrelated buildings in the same metro can legitimately hold matching credentials. |
| 35-bit Corporate 1000 | 12-bit company code, 20-bit card number | A managed, site-unique code with a far larger number space. Blank stock carrying your code cannot simply be bought off a shelf. |
| 37-bit (H10304) | 16-bit facility code, 19-bit card number | Used where a 26-bit range has run out or a wider facility range is wanted. |
The format must exist on the controller and be enabled on the port that reader is wired to. On a site grown in stages — a reader added one year, a board swapped the next — we regularly find one opening configured differently from the rest. The symptom is a badge that works at the front entry and is refused at the stock room, which everybody reads as a hardware fault and it almost never is.
There is a security half to the same conversation. The 125 kHz proximity credentials — thick white cards, older grey fobs — carry no cryptography and are copied at kiosks for pocket change. A 13.56 MHz smart credential such as DESFire EV3 or Seos authenticates against a key held in both card and reader, so a copier without the key produces a blank.
You took the suite, the reader already worked, and nobody left a list
A large share of the credential work we do in 77493 starts that way. The hardware is fine. The roster is a mystery.
Recovery is the first move. If we can reach the controller or the hosted tenant account, the cardholder table normally exports — names, numbers, groups, last-used dates. Read the last-used column first: anything not presented in a year belongs to somebody who has already left.
When the previous vendor has gone and nobody holds the administrative account, recovery is not always available, and fighting it is the wrong instinct. We re-enrol the people who genuinely work there, issue a fresh batch, and void the rest. That converts an inherited unknown into a roster with a date on it in about half a day. Readers often want attention in the same visit — HID units take configuration from a programming card presented at the reader, so one can be brought onto your keying without coming off the wall.
Here is the ownership test. Can you name the holder of every active credential on your system? If not, what you have is not an access system; it is a door that sometimes opens.
Bringing a sealed box of a hundred cards into service in one sitting
This is the part that rewards doing properly once, rather than one badge at a time as people wander into the office asking.
- Verify both ends of the batch. Read the first and last card at a live reader and confirm the encoded values land where the sequence says. Sealed boxes are normally sequential, so proving the ends proves the middle.
- Load the range, not the cards. Most platforms accept a credential range or a spreadsheet import in one operation — minutes rather than an afternoon.
- Load them inactive. Unissued credentials sitting live in a panel are keys with nobody’s name attached. Activate at the moment of issue, not before.
- Bind and authorise at handover. Name, group, start date, and an end date for anyone seasonal, where the platform supports one.
- Test at the doors that person actually uses, not at whichever reader you happen to be standing beside.
Remaining stock then goes in a locked drawer with the range written on the box. Unglamorous, and it prevents one ugly scenario: a spare walking out of an open cabinet already loaded, already authorised, attached to no name at all.
The buildings north-west of the old townsite where we do this most
This ZIP is still filling in, and the credential work here takes its shape from that.
- Learning centres and childcare along the Clay Road and Katy-Hockley corridors carry real staff turnover alongside a duty to control who reaches a classroom. They need credentials that expire on a date, not credentials somebody is meant to remember to collect.
- Church campuses run on volunteers, so the roster changes by ministry season, a lot of rooms are shared, and the group structure has to stay readable by whoever happens to be in the office on a Tuesday morning.
- New flex and small-warehouse bays north of the interstate are usually owner-occupied: a personnel door, a shop door and an office interior on one modest panel, administered by the owner between jobs.
The builder-handover pattern deserves naming. The sub wires the reader, proves the door releases, and moves to the next suite. Formats sit at default, the administrative account is generic, the manufacturer’s stock password is often still in place, and the first tenant inherits a configuration nobody matched to their way of working. Credential loading is normally the visit where that gets straightened out.
What sends us back a second time, and what moves the number
The repeat visits are predictable enough that we run them as a leaving checklist.
- Loaded, never authorised. The credential exists and sits in no group. Clean denial, zero faults.
- Right card, wrong format on one port. Opens the entry, refused at the interior door.
- Schedule collision. Nothing wrong with the card; its group runs on a weekday schedule and the holder works Saturdays.
- Deleted rather than deactivated. Removing a cardholder orphans the history attached to them. Deactivate, keep the record, keep the trail readable.
- Untested openings. A badge proved at the front door and never at the room it was issued for.
Routine issue and revocation are administration and you can run them yourself once the structure is right. Bring in a licensed low-voltage contractor when the format is unknown, when nobody holds the administrative account, when readers span more than one hardware generation, when you are changing credential technology, or when a departure means the roster has to be proved rather than trusted.
Five things shape a quote in this ZIP: how many credentials are loaded and whether they run sequentially; whether format and keying are documented or must be discovered; whether the platform is reachable and licensed or the panel needs administrative recovery first; how many openings need physical testing; and whether you stay on your present credential technology or migrate to a secure one, which changes cards and sometimes readers. All of that is visible on a walk-through, which is why we quote on site and itemise it.
Related services
Frequently asked questions
A new hire’s card beeps at the reader but the door stays shut. Is the card faulty?
Can you find out what number is encoded on our cards if we have no paperwork?
We found a drawer of old cards from the previous tenant. Should we load them?
Is there a limit to how many credentials our panel can hold?
Will the doors be offline while you load credentials?
Free on-site credential audit in 77493
We will read what your readers are actually sending, export the roster you already have, and tell you exactly what it would take to get every active card attached to a name. Itemised quote, no pressure. Call (832) 359-2425.
Book a Free Consultation
Ready for EVOTECH to help?
Before you leave, send the quick version. We will review the page you came from and reply with the clean next step.
