Tailgate detection for badge-controlled doors

One badge.
Two people.
You'll know.

PassMatch compares every valid badge read with the number of people an Axis camera counts walking through the same door. When someone follows without a badge, it raises an alarm in your access control system within a second.

No internet or cloud No software link to the access control Low-voltage dry contacts 1 to 100+ doors

Badges count cards, not people

An access control system knows a valid card was presented. It has no idea whether one person walked in or three.

Tailgating is the easy way in

Holding the door for the person behind you is polite and common. It also defeats the whole point of the badge reader.

Catch it when it happens

PassMatch flags the extra person at the door, in real time, in the system your guards already watch.

How it works

Two counts per door, compared every second

The badge count comes from your access control panel over a pair of wires. The people count comes from the camera's own on-board analytics. A small program on a local PC compares them.

Signal flow: reader to access control panel, aux relay to I/O device input, camera counts people, monitor compares and pulses an alarm input on the panel Card reader at the door Access control panel e.g. Mercury · unchanged Spare AUX relay pulses on "access granted" Spare alarm input "Tailgate – Front Door" I/O-to-network device 4 inputs · 4 relays Input 1 counts badges Relay 1 alarm pulse PassMatch local PC / server people > badges within the door's delay? → TAILGATE Axis camera counts people crossing a line badge wire LAN LAN pulse wire badge signal people count tailgate alarm
01 · Badge

Valid read

The panel pulses a spare auxiliary relay on "access granted". The I/O device counts the pulse and tells the monitor.

02 · People

Camera counts

The Axis camera counts each person crossing the door line with its on-board analytics and sends the count.

03 · Compare

Per-badge timer

Each badge is good for one person within the door's delay (for example 12 s). Every person uses one badge.

04 · Alarm

Within a second

A person with no badge left pulses an I/O device relay into a spare alarm input. Guards see "Tailgate – Front Door".

What the monitor sees

The rule, door by door

Only a badge starts a timer. A person who walks in with no badge is a tailgate on their own and never uses up the next person's badge.

TimeEventResult
09:25:33Badge Front Door, delay 12 sBadge good until 09:25:45
09:25:36Person walks inOK uses the badge
09:25:41Person follows right behindTailgate 2 people, 1 badge · alarm sent
09:26:10Person walks in, no badge readTailgate 1 person, 0 badges · alarm sent
09:27:02Badge Badge two people badge in 3 sBoth badges good for 12 s
09:27:09Person PersonOK 2 people, 2 badges
How the devices connect

Everything stays on your local network

The camera, the I/O device and the monitor talk over the building's LAN. The access control panel is connected by wires only, with no network link and no software integration.

System diagram: local network with monitor PC, I/O devices, Axis cameras and guard browsers; access control panel wired by dry contacts only; no internet connection LOCAL NETWORK (LAN / security VLAN) PoE network switch powers cameras + I/O devices PassMatch PC Windows server, mini PC or Pi listens :8080 · :1883 live page :8081 Guard desk / admins any web browser, sign-in live view · history · CSV Axis cameras one per door · counts only I/O-to-network device one per 4 doors 4 inputs · 4 relays Access control panel its own network – untouched AUX relay ──▶ badge alarm input ◀── tailgate Connected by 4 low-voltage wires per door. No IP link. wire wire Internet / cloud not needed

Optional email alerts can use a mail server on the local network. Nothing has to leave the building.

No internet needed

Runs entirely inside the building

The camera counts people on its own processor, the I/O device counts badge pulses, and the monitor compares them on a local PC. There is no cloud service, no subscription and no outside connection. It keeps working when the internet is down.

The camera sends only numbers, never video. The monitor stores counts and events, not images.

No network link to the access control

Wired in like a door contact

The access control system connects with two dry-contact pairs per door: a spare auxiliary relay out, a spare alarm input in. There's no API, no driver, no integration license and no change to the panel's firmware or network.

That keeps the access control system's cybersecurity boundary exactly as it is, makes IT approval simple, and works with Mercury-based panels and most other panels that have a spare relay and input.

Basic wiring · one door

Four low-voltage wires per door

As installed and tested with a Mercury panel. The second, third and fourth doors on the same I/O device repeat the pattern on inputs and relays 2–4.

Wiring for one door: 12–24 VDC supply, Mercury aux relay common fed from the supply, normally open contact to the I/O device input 1; I/O device relay 1 and common to Mercury alarm input 1 12–24 VDC supply fused · or PoE-powered models Access control panel Mercury · use your board's labels AUX RELAY (access granted) C NO ALARM INPUT (tailgate) IN1 + IN1 − I/O-to-network device voltage inputs · relays 24 VDC / 1 A Power + Input 1 + Relay 1 Relay com counts badges tailgate pulse Power − to supply − ① supply + → relay C (signal voltage) ② relay NO → Input 1 (badge pulse) ③ Relay 1 → IN1+ (tailgate) ④ Relay com → IN1− +

Use a spare AUX relay

Program it to pulse on "access granted" for that door. Not the lock or strike relay, which also fires on request-to-exit and held-open.

Dry contacts both ways

Every signal crosses a relay contact, so the panel and the I/O device stay electrically separate. Their grounds don't need to be joined.

Alarm input as normal

Set the panel input as a normally-open alarm point, with the end-of-line resistors your input configuration uses.

Life safety

Built to stay out of the life-safety path

PassMatch only watches and reports. It never decides whether a door locks or unlocks, and it is wired so it can't.

Free egress unchanged

Exit hardware, request-to-exit and fire-alarm release are not connected to it. People leave exactly as before.

Fails quiet

If the PC, camera, I/O device or network stops, doors and access control keep working normally. You only lose the tailgate alarm, and the monitor reports the device as down.

Low voltage, signal only

12–24 VDC signal circuits through relay contacts rated 1 A. No mains wiring at the door.

Privacy by design

No video leaves the camera, and nothing is stored but counts and times.

Door circuitConnected?
Lock / strike / maglock powerNo
Request-to-exit (REX)No
Fire alarm door releaseNo
Panic / exit hardwareNo
Door position contactNo
Spare AUX relay (listen only)Yes
Spare alarm input (report only)Yes

Install by a qualified installer to the panel maker's instructions, local codes and the authority having jurisdiction. Use spare panel points only.

Cybersecurity

Safe for your network and the PC it runs on

PassMatch is a small, closed system on your own LAN. It talks only to the devices you list, accepts nothing from the outside, and never touches the access control system's network.

On the network

  • No internet, no cloud. Nothing leaves the building. The only outgoing traffic is to your own I/O devices, plus your mail server if you turn on email.
  • Only listed devices get in. Each camera and I/O device must be in the door list by its IP address. Anything else is refused.
  • Every device signs in. Each one has its own username and password. Five wrong logins block that address for five minutes.
  • Numbers, not video. Cameras send people counts only. No images are streamed, stored or shared.
  • No link to access control. The panel is wired with dry contacts, so its network stays completely separate.

On the PC

  • Small and self-contained. One program and one web page. No third-party software packages, drivers or plug-ins to keep patched.
  • No admin rights to run. It only needs to listen on its ports and write its own log files in its own folder.
  • Never runs what it receives. Incoming messages are only read as counts; it accepts no files, scripts or remote commands.
  • Protected web page. Sign-in with viewer and admin roles; passwords stored only as salted hashes; sign-in lockout; protection against cross-site requests and framing.
  • Secrets stay put. Device and email passwords are never shown in or sent to a browser. Every admin change is checked, backed up and logged with who made it.
  • Light footprint. Under 1% of one CPU core and about 40 MB of memory, even at 100 doors.

Ports it uses (all local)

PortDirectionFrom / toPurpose
8080InI/O devices onlyBadge counts
1883InCameras onlyPeople counts
8081InGuard and admin PCsLive web page (sign-in)
80OutI/O devices and camerasAlarm pulse, health check, camera reconnect
587 / 465 / 25Out (optional)Your mail serverEmail alerts

Recommended setup

Put the cameras, I/O devices and monitor PC on a security VLAN, and allow each port only from the device addresses above (step-by-step firewall rules are in the install guide). Traffic on the LAN is not encrypted today, so keeping it on a security VLAN is the right place for it. Encrypted connections are on the roadmap.

The live page

Every door, live, in any browser

Guards and admins sign in from any PC on the network. Filter by site with NYC* or pick one door, switch to tailgates only, or look back over any date range and download it for Excel.

Live view: 62 doors with today's badges, people and tailgates, device status, and a live event list
Live view: every door's counts today, device status, and events as they happen.
Dates view filtered to NYC* doors for the last 7 days, with totals and the event history
Dates view: the NYC* doors over the last 7 days, with totals and every event.
Open the interactive demo Runs in your browser on made-up sample data. Try the door search, Dates, and the Doors, Settings and Users tabs.
What you get

Alarm, live view and records

Alarm in your ACS

A tailgate shows up as an alarm point in the access control software your guards already watch.

Live web page

Every door with today's badges, people and tailgates. Filter by site with NYC*, or pick one door.

History and CSV

Pick any date range, see every event and download it for Excel. Weekly tailgate reports are kept automatically.

Device health

Every camera and I/O device is checked each minute. A device that drops off is flagged on screen and by email.

Email alerts

Optional emails for tailgates, devices down and a daily summary, through a mail server you choose.

Users and roles

Viewers watch. Admins edit doors and settings in the browser, with every change checked, backed up and logged.

What's needed

Per site

1 / door
Axis camera with Object Analytics

Overhead or angled at the door, "crossline counting" scenario. Tested with the Axis P3288-LVE.

1 / 4 doors
I/O-to-network device

4 counting inputs and 4 relays on the network. PoE-powered models available.

2 / door
Spare panel points

One auxiliary relay (access granted) and one alarm input (tailgate).

1
Monitor PC

Any always-on Windows PC or server, or a small Linux PC. No internet connection needed.

—
12–24 VDC supply, PoE switch, cabling

Standard low-voltage installation materials.

Specifications

Light on the PC

Alarm timeUnder 1 second from the person crossing
Doors1 to 100+ per monitor
Delay per doorSet per door, e.g. 5–15 s
CPUUnder 1% of one core at 100 busy doors
MemoryAbout 35–40 MB
NetworkAbout 1 KB per badge or person
InternetNone
Event historyKept 90 days by default (adjustable)
Ports (local only)8080 I/O devices · 1883 cameras · 8081 web page

See it at one of your doors

We can install PassMatch on a single door alongside your existing access control, with no changes to how the door works, and show you the tailgates it catches.

hello@passmatch.io

Email us to book a door demo