Cloud vs. On-Prem Access Control: Which One Fits a Small Commercial Building?
· Erik Short

Quick answers
- What's the real difference between cloud access control vs on premise? Cloud platforms run the door logic from a vendor's servers with a per-door annual fee; on-prem systems run it from a small controller in your building that you own outright.
- UniFi Access vs Verkada — which is cheaper? UniFi is almost always cheaper over five years because there's no per-door license, but Verkada buys you hands-off multi-site management and vendor-hosted support.
- What happens when the internet goes down? Both keep unlocking doors on schedule and honoring valid credentials locally; the difference is that on-prem keeps full admin and event history available on site, while cloud admin waits for the connection to come back.
- What's the best door access control for a small business with one building? A local-hub system like UniFi Access, if someone on staff is comfortable logging into a network console a few times a year.
- How many doors do most small offices actually start with? Two to four — front entry, back/warehouse door, and one or two interior rooms like IT or records.
If you've already decided keys are a dead end — and if you haven't, that's the conversation to have first — the next fork in the road is where the brains live. Everything else in an access control bid is roughly the same: readers, locks, power supplies, door position switches, request-to-exit, cable. The architecture decision is what drives your five-year number and who you call when something misbehaves.
Here's how I explain it on a site walk.
The short version in a table
| On-prem / local hub (UniFi Access) | Cloud-native (Verkada, Brivo, Avigilon Alta) | |
|---|---|---|
| Ongoing cost | One-time hardware, no per-door license | Per-door annual or monthly subscription |
| Where logic runs | Controller in your IT closet | Vendor cloud, with local caching at the door |
| Admin access | Local console or vendor's remote portal | Browser/app from anywhere, always |
| Multi-site | Workable, better with some IT comfort | Strongest feature — built for it |
| If internet drops | Doors work; admin and logs still reachable on site | Doors work; admin waits for connectivity |
| Who it fits | Single building, owner-occupied, someone semi-technical | Multiple sites, no IT staff, lots of turnover |
| You own | The hardware and the database | The hardware; the service is rented |
That table is the whole post. The rest is the detail that decides which column you're in.
What "on-prem" actually means in 2026
The phrase makes people picture a server rack and a licensed software install. That's not what this is anymore.
With UniFi Access, the controller is a small appliance — a UniFi Dream Machine, a Cloud Key, or a dedicated Access hub — sitting in the same rack as your switch. Door hubs on each door talk to it over PoE. The database of users, schedules, and door events lives in that box, in your building. You still get remote administration through Ubiquiti's remote access portal, so "on-prem" doesn't mean "you have to drive over to add an employee." It means the system keeps working, in full, whether or not the vendor's cloud or your ISP is having a day.
The part customers actually care about: there's no per-door fee. You buy the hub, the door hubs, the readers, and the locks once. Adding a fifth door costs you hardware and labor, not a bigger annual bill. And if you already run UniFi cameras and networking, access shows up in the same console as everything else — same user list, same site, same app on your phone. Unlock a door from the same screen where you're watching the camera pointed at it.
The tradeoff is that you own the uptime. If that appliance dies, somebody has to swap it and restore the config. That's a one-hour job for an integrator and a non-event if the config is backed up — but it's your problem, not a vendor's.
What cloud-native gets right
I'm not going to pretend the subscription platforms are a scam. They're not. Verkada, Brivo, and Avigilon Alta (formerly Openpath) are genuinely good at things a local-hub system has to work harder at:
- Multi-site at scale. One pane of glass across eight clinics in three states, with role-based admin so the Nampa office manager can badge people in at Nampa and nowhere else. Cloud platforms were designed around this. It shows.
- Zero on-site infrastructure. No controller to maintain, no local backup to think about, no firmware window to schedule. The door hardware phones home and that's the architecture.
- HR and directory integration. Push from Okta, Google Workspace, Azure AD, or an HR system so terminations revoke badges automatically. You can get there other ways, but the cloud vendors make it a checkbox.
- Support that owns the whole stack. When something's wrong, there's one vendor who can look at your tenant and tell you what happened. For a business with no IT person and no patience for finger-pointing, that's worth real money.
- Mobile credentials done well. Bluetooth and NFC phone unlock with good wave-to-unlock behavior, and fast credential issuance by email.
If you have four sites, 120 employees, meaningful turnover, and no IT staff, I'd tell you to buy a cloud platform and I'd sleep fine. The subscription is buying labor you don't have.
The honest fit guide
Lean on-prem (UniFi Access) if:
- One building, maybe two on the same campus.
- Owner-occupied or long lease — you'll be there long enough to amortize hardware.
- Somebody on staff is comfortable logging into a web console. Not an engineer. Just someone who isn't scared of it.
- You already have or want UniFi networking and cameras, and you like the idea of one contractor and one app.
- You're allergic to recurring fees on principle. (Plenty of Treasure Valley owners are. It's a legitimate position.)
Lean cloud-native if:
- Three or more locations, especially in different cities.
- No IT staff and no interest in becoming one.
- Heavy turnover — restaurants, staffing agencies, clinics with rotating contractors.
- Compliance or insurance requirements that want a vendor-attested audit trail and SOC 2 paperwork.
- Corporate already standardized on a platform. Don't be the one site that's different.
It genuinely doesn't matter much if: you have two doors, five employees, and low turnover. At that size both architectures work and the deciding factor is whoever's going to service it well.
When the internet drops — what actually happens
This is the question I get most, and the answer is less dramatic than people expect. Every credible platform, cloud or local, caches credentials at the door controller. When the WAN goes down:
- Doors still unlock for valid cards, fobs, and PINs.
- Unlock schedules still run — the lobby still opens at 7:30.
- Events still get logged locally and sync up when the connection returns.
The differences are at the edges:
- Mobile credentials. Bluetooth phone unlock generally still works because the phone talks to the reader directly. Some implementations want a brief cloud handshake for a first-time credential — which is exactly when you don't have internet. A card or fob on every keyring is cheap insurance.
- Admin during the outage. On-prem, you can walk to the console on the LAN and add a user, pull a report, or unlock a door right now. Cloud, you're waiting — or tethering off your phone to reach a portal that still can't reach your door.
- Cellular backup. Some cloud door hubs offer LTE failover. Nice feature. Ask what it costs monthly before you fall in love.
And one thing that matters more than architecture: power. A door that fails secure with no backup power and a dead battery is a door you're drilling out. Spec a UPS on the rack and the door power supply, both. I've written about why systems fail exactly when you need them — same discipline applies to doors.
Credentials: fob, PIN, phone, or all three
Both camps support the same basic menu. What differs is polish and cost per credential.
- Fobs and cards. Still the workhorse. Cheap, no phone required, easy to hand a temp. Use encrypted smart credentials (DESFire EV2/EV3), not legacy 125 kHz Prox — old Prox cards can be cloned with a $30 gadget off the internet. If a bidder specs Prox in 2026, ask why.
- PIN codes. Good for a back door or a shared space where nobody wants to carry anything. Shoulder-surfable, and codes get shared. Fine as a secondary factor, weak as the only one.
- Phone / NFC / Bluetooth. Great for salaried staff who always have their phone. Provisioning is instant and revocation is instant. Apple Wallet support is where the cloud vendors have historically led; UniFi's phone unlock via the Identity app works well and keeps improving.
- Touch/biometric. UniFi has a fingerprint-capable reader; the cloud vendors mostly integrate third-party. Nice for a server room or a pharmacy cabinet. Overkill for a front door.
Practical advice: issue phone credentials as the daily driver and keep a drawer of fobs for guests, contractors, and the day someone's battery dies. Dual credential types cost almost nothing to support and eliminate a whole category of Monday morning phone calls.
Five-year cost on a 3-door office
I won't invent competitor pricing, but I can show you the shape of it, which is what matters.
On-prem (UniFi Access), 3 doors:
- Year 0: controller/hub, three door hubs, three readers, three locks (maglock or electric strike depending on the door), power supplies, request-to-exit, door contacts, cable, labor, commissioning.
- Years 1–5: $0 licensing. Budget a service visit or two for a lock adjustment, a closer, or a reader swap.
Cloud-native, 3 doors:
- Year 0: similar hardware and labor cost — sometimes a bit higher on door controllers, sometimes bundled — plus first-year licenses.
- Years 1–5: per-door annual subscription × 3 doors × 5 years. Multiply it out before you sign. Then ask what happens at renewal if the price goes up, and what happens to the hardware if you stop paying. (Usually: the doors keep working on cached credentials, but you lose admin. Get that answer in writing.)
Across five years on three doors, on-prem is reliably the lower number. The gap widens with every door you add, because you're paying hardware once instead of licensing forever. The gap narrows — and can flip — when you're paying someone to administer the system, because the cloud platforms genuinely reduce admin hours per site at scale.
Two costs both sides forget: door hardware and doors themselves. A hollow metal door with a worn frame, an aluminum storefront that needs an electric latch retrofit, a fire-rated door that can't take a maglock without a code-compliant release — those are the line items that surprise people. The reader is the cheap part. Also budget for cable: every door needs a composite or multi-conductor home run back to the closet, and that gets priced like any other structured cabling work.
Code and life safety, briefly
Not architecture-dependent, but it kills bids when it's missed. In Idaho commercial buildings you're looking at IBC/IFC egress rules and your local AHJ:
- Free egress always. Push bar, motion-sensing request-to-exit, or a lever that mechanically releases — no "turn the knob twice."
- Maglocks on egress doors need the full package: request-to-exit, fire alarm release, and usually a push-to-exit button. If somebody quotes a maglock with none of that, they're quoting you a red tag.
- Delayed egress and stairwell doors have their own rules. Involve the fire marshal early, not at final inspection.
- Keep a mechanical key override somewhere. Fire department access and dead batteries both exist.
A good integrator walks the doors with you and tells you which ones need a locksmith before they need a reader. If a bidder quotes three doors from a floor plan without looking at the hardware, that number will change.
What we do and why
We standardize on UniFi Access for most Treasure Valley buildings, for the same reasons we standardize on UniFi Protect for cameras: the customer owns the hardware, there's no per-door subscription, and doors, cameras, network, and Wi-Fi all land in one console with one contractor to call. For a single office, church, clinic, or warehouse in Boise or Meridian, that's usually the right answer and the cheaper one.
But I've also told people to buy Verkada or Brivo. If you're a multi-site operation with no IT staff, or corporate has already picked a platform, fighting that is bad advice dressed up as loyalty. We'll still pull the cable, hang the readers, get the doors right, and hand you a system that passes inspection.
Either way, it starts the same: walk the doors, check the hardware, count the cable runs, and give you a fixed number. You can see how we scope access control and door entry work, or just have us come look.
Frequently asked questions
Can I mix access control brands with cameras from someone else?
Yes, but you lose the easy wins. Same-ecosystem gear gives you one login and automatic door-event-to-video linking. Mixed stacks usually mean two apps and manual timestamp matching — workable, just more friction every time you pull footage.
Do I need a dedicated network for access control?
Not a separate physical network, but put the door hubs on their own VLAN with the cameras and other infrastructure, off the guest and employee networks. It's basic hygiene and it costs nothing at install time if your installer plans for it.
Can I keep my existing card readers and just change the back end?
Sometimes. If your current readers are Wiegand-output, some controllers will accept them, which saves hardware but keeps you on an older, less secure credential format. Usually the better move on a retrofit is new readers and new encrypted credentials — the readers aren't the expensive part.
How long does a 3-door install take?
Typically one to three days once hardware is on site, assuming existing door hardware is serviceable and cable paths are accessible. Add time for door prep, a locksmith, or an aluminum storefront retrofit. Occupied buildings stretch it because you're working around business hours.
What happens to my data if I cancel a cloud subscription?
Ask before you buy, and get it in writing. Typically doors keep functioning on cached credentials while you lose administration, remote access, and historical event logs. That's precisely the scenario worth pressure-testing with any subscription platform.
If you're weighing cloud against on-prem for a building here in the Treasure Valley, request a site walk and we'll price both honestly before you commit.



