Serving Katy, Houston & surrounding areas • Licensed & Insured • 20+ Years (832) 359-2425
EVOTECH technician working inside a network cabinet
Fast EVOTECH reply

Start your EVOTECH request in under a minute.

1 minsimple request
Texaslocal and remote help
Inboxlead saved and emailed
Get a fast EVOTECH response Most requests only need name, phone, city, and service.
Choose a service and EVOTECH will guide the next step.
(832) 359-2425

EVOTECH uses your details only to reply, quote, schedule, or help with your requested service.

Brazoria County – Shops, Yards, Clinics and Offices

Access Credential Management in Alvin, TX 77511

In Alvin the badge problem usually surfaces long after the readers went up: a fabrication shop whose headcount doubles for a plant turnaround and then shrinks, a drawer of old proximity cards nobody can account for, a supervisor who left in March whose fob still opens the yard. EVOTECH IT LLC puts the technology and the habits in place so every credential maps to one current person.

Prox-to-secure card migrationTurnaround crew badgesMonthly badge reconciliationStorm-ready controllers5.0-star rated installer

Credential management is a routine, not a box on the wall

A credential is any token your system trusts: a card, a key fob, a keypad PIN, a phone. Managing them means that at any moment you can say who holds each one, what it opens, and when it stops working.

Most systems we open up at Alvin-area businesses answer the first of those poorly and the other two not at all. Cards were handed out from a box, names were typed in as “Shop 4” or “Temp”, and access levels were cloned from whoever happened to be enrolled last. The hardware is usually fine; the records have drifted, and fixing them takes both technical work and a routine your office manager can keep up without calling us.

Alvin’s business mix is why that routine matters. Service and fabrication companies supporting the Brazoria County plants swing headcount hard around turnarounds. Medical and dental practices need a record of who entered after hours. Churches and nonprofits run on volunteers who come and go. We cover 77511 from our Katy and Houston base, so phone (832) 359-2425 and ask when a technician can realistically reach your address.

Why the old 125 kHz prox card is the weakest link

The plain white or beige proximity cards found in many older systems operate at 125 kHz and transmit a fixed number with no encryption at all. A handheld copier small enough to sit in a jacket pocket can read one at close range and write a working duplicate in seconds, and nothing in the access system can tell the copy from the original.

Newer 13.56 MHz smart credentials solve that with cryptographic authentication between card and reader – but not all of them do. Early MIFARE Classic cards rely on a cipher that was publicly broken years ago, so the words “smart card” alone settle nothing. This is how we sort what we find on site:

CredentialHow it identifies itselfCopy riskOur use for it
125 kHz proximity card or fobBroadcasts a fixed number, unencryptedHigh – inexpensive tools duplicate itStopgap only, during a migration
MIFARE Classic, 13.56 MHzOlder proprietary cipherElevated – the cipher has known attacksReplace when readers are upgraded
MIFARE DESFire EV2/EV3, HID Seos, iCLASS SEMutual authentication with modern encryptionLow, provided keys are managed properlyDefault choice for new cards and fobs
Mobile credential on a phoneEncrypted credential in an app or wallet, sent over Bluetooth or NFCLow – the phone’s own lock screen adds a factorStaff who always carry a smartphone
Keypad PINA number the person remembersEasily shared or watchedSecond factor, or a backup method

The card is only half of the chain. Many older readers pass the card number to the controller over Wiegand wiring, which is unencrypted and can be tapped right behind the reader. When we replace readers we prefer OSDP with Secure Channel, which encrypts that last stretch of wire and lets the controller notice if a reader is pulled off the wall.

Migrating a whole workforce off prox without a lockout day

  1. Inventory what is out there. Export every active credential and read a sample of physical cards to confirm their format. Many 125 kHz systems use the standard 26-bit format, which allows only 256 facility codes with roughly 65,000 card numbers under each, so two separate card orders can carry duplicate numbers.
  2. Install multi-technology readers that accept both the old prox and the new secure credential. For a few weeks, both work.
  3. Issue new credentials department by department, attached to the same person record so each cardholder’s history carries forward.
  4. Collect each old card as its replacement goes out, and disable that old number the same day.
  5. Switch off prox reading at the readers once reports show no old card has been used for an agreed period. Until that setting changes, a copied prox card still opens doors.

When you reorder cards, we recommend a format with a number range reserved for your company rather than generic 26-bit stock, which removes the chance that someone else’s card happens to match a number enrolled in your system.

Issue, change, suspend, revoke – and what each step should record

Issue

Every credential goes to a named person with an employee or contractor ID, an access level picked from a short list of roles, and – for anyone who is not permanent staff – an end date. Turnaround crews and temporary labor are exactly where an end date earns its keep: the badge stops on the last scheduled day even if the paperwork runs late.

Change

Promotions and transfers are where access quietly piles up. When someone moves from the shop floor into the office, remove the old role in the same sitting as you add the new one, or the yard gate stays on their card for years.

Suspend

For a leave of absence, a lost card awaiting replacement or a subcontractor between jobs, suspending keeps the record and history intact while the credential stops working; reactivation is one click.

Revoke

When employment ends, disable the credential the same day, ideally before the person walks out. Disable rather than delete – the event history attached to that record is what you will want if a question comes up months later, and how long to keep it is a decision for your records policy, not the software’s default.

A monthly check that finds ghost badges

Once a month, whoever owns the system spends half an hour on this list. It catches problems a year sooner than an annual audit would.

  • Match active cardholders against current payroll and the active contractor list. Any badge name with no match gets suspended pending an answer.
  • Run a report of credentials unused for 60 days. They are either unneeded or riding around in someone’s truck console.
  • Look for a single card used at two doors or two sites too close together in time for one person to have done it – a sign of sharing or copying.
  • Review who holds after-hours access and whether each person still needs it.
  • Count the blank cards in the drawer against last month’s count. Unissued stock that disappears is an unrecorded credential waiting to be enrolled.
  • Check the administrator list itself. A former office manager who still has an admin login is a bigger exposure than any single lost card.

When a Gulf storm takes out power, internet or the office

Alvin has flooded badly in past storms, and credential data tends to become unreachable in exactly the week you need it most. A handful of decisions made in advance keep the system usable:

  • Controllers and batteries off the floor, mounted above the level water has reached in that building before, with standby batteries sized for a realistic outage rather than a brief flicker.
  • A controller that decides locally. Valid credentials should keep opening doors while the internet link is down; administrative changes can wait for reconnection.
  • A copy of the database away from the building – the cloud host’s own backup, or a scheduled export if the software lives on a local PC.
  • A written list of mechanical key holders for the override cylinders, so a dead system never means prying a door.
  • A post-storm check: confirm the controller clock, confirm each door reports its correct status, and read the event log for forced or held-open alarms logged during the outage.

What we handle on the call, and what stays in your hands

Day-to-day credential work should belong to someone inside your company; an installer should never be your only way to enroll a new hire. On a typical Alvin engagement EVOTECH:

  1. Audits the existing system – readers, card formats, controller firmware, software version, administrator accounts and the full cardholder list.
  2. Rebuilds access levels around roles instead of individuals, so enrolling a new hire is one selection instead of a dozen door checkboxes.
  3. Plans and runs any card migration in the order described above.
  4. Creates templates with end dates for temporary and contractor credentials.
  5. Trains two administrators and writes the monthly check up in plain language.

A single office with one door and a handful of staff may need none of this. A keypad plus the discipline to change codes when people leave can be enough, and we will tell you that rather than sell a platform.

Cost drivers, and the habits behind most callbacks

Pricing follows an on-site estimate and arrives as an itemized quote. The pieces that move it:

  • Cardholder and door counts, and how many readers must be swapped to accept a secure credential.
  • Credential type and quantity – secure cards, fobs, or mobile licenses.
  • How the software is licensed: per door, per user, or by subscription.
  • Data cleanup. A tidy cardholder list takes an afternoon; one carrying years of “Temp 3” entries takes considerably longer.
  • Integration with cameras, intrusion panels or payroll exports.

The callbacks we see in credential work trace back to a short list of habits: deleting former employees instead of disabling them, handing contractors a staff access level because it was quicker, issuing temporary cards without end dates, leaving prox reading switched on after a migration, and relying on a single administrator who then leaves.

Frequently asked questions

A foreman quit this morning and still has his fob. What do we do first?
Disable that credential in the software right away – from a phone if your platform is cloud-hosted – then watch the event log over the next few days for any attempt with it. Ask whether he also knew a shared keypad code or carried a mechanical key, because those need changing too. Getting the fob back is nice but stops being urgent once it no longer works.
Can we keep using our old prox cards while we switch?
For a transition period, yes. Multi-technology readers accept both kinds, so nobody is locked out while new credentials go out. The copying risk remains until prox reading is turned off at the readers, so agree on a cut-off date at the start and hold to it.
Should we delete people who no longer work here?
Disable them instead. A disabled record opens nothing but keeps its history, which is what you will want if a theft or injury question comes up later. Set a retention period with whoever handles your records and purge on that schedule.
Our crews come and go with plant turnarounds. What is the cleanest way to badge them?
Build a contractor access level covering only the doors and hours they need, import the roster from a spreadsheet if your software allows it, and give every temporary credential an end date matching the job. When the turnaround wraps up, those badges expire without anyone lifting a finger.
Is card plus PIN worth the extra step?
At the doors that matter most – a tool crib, a server closet, a records room – yes, because a lost or copied card alone will not open it. At a busy staff entrance it slows everyone down for little gain. Most businesses use it on one or two openings, not all of them.

Get every badge in your Alvin building accounted for

Book an on-site estimate: we audit your readers, card formats and cardholder list, then quote the cleanup and any migration line by line. Licensed and insured, 20+ years in low-voltage.

Book an On-Site Estimate
EVOTECH technician working inside a network cabinet
Before you go

Ready for EVOTECH to help?

Before you leave, send the quick version. We will review the page you came from and reply with the clean next step.

1 minsimple request
Texaslocal and remote help
Inboxlead saved and emailed
Send the quick request No long questionnaire. A real EVOTECH lead comes straight to the inbox.
Choose a service and EVOTECH will guide the next step.
(832) 359-2425

EVOTECH uses your details only to reply, quote, schedule, or help with your requested service.

Need a fast quote?
Call, message, or request your free estimate now.
Fast quote today • Same-day response available
Call Now: 832-359-2425 Chat on WhatsApp Book Appointment
Free Estimate Request
Thank you. EVOTECH received your request.
Fast quote • Call, WhatsApp, or send your request now
Free Estimate Available
Send your details now and EVOTECH will contact you quickly with pricing.
Thank you. EVOTECH received your request.
Call 832-359-2425