Open letter and invitation to the physical security industry: Welcome to the Intelligence Era of Physical Security.
I will explain by going deep into what it means to access control…our industry is moving from a $10 billion hardware business to a $100 billion software business that has hardware to support it (what some are calling PhysicalAI)…yet…we don’t have a name or a home for the era.
We keep describing all this new with old words, cloud, platform, open, that used to signal real differentiation and now mean almost nothing. New ideas don’t work inside old constructs that were never built to hold them.
So I’m naming it: we are now Intelligent Access Era.
I’ve tested this argument for months, in and out of our industry, before putting it in front of all of you.
Treat this as a framework and something to build off of. I encourage you all to use it and the image attached when explaining what is different today vs yesterday (the Modern Electronic Access Control era).
This is an invitation, specifically, to anyone focused on where this market is going rather than fighting to keep yesterday’s model relevant. Please take it, challenge it, break off the piece that’s yours and build your own differentiated language from it. Whatever you have, it needs a home to build off of and the Intelligence Access Era does just that.
The full paper is live now as a shared, open document inside the PhySec Collective community, anyone can comment and mark it up directly. I am also happy to share a hard copy. Just let me know. Full copy of the paper is posted as a LinkedIn Article as well.
- Lee Odess
[Posted initially in the PhySec Collective community]
For years now, I've circled one simple, inevitable truth: we are firmly in a new era in access control. And today I am naming it: Welcome to the Intelligence Era.
I'm doing this because things are truly different now for many, though for some, nothing has changed, and this difference needs a home. Companies working toward this era have had to use modern vocabulary, like open, cloud, mobile, and platform, in outdated eras, which no longer signal differentiation, as every company claims them, regardless of underlying architecture, go-to-market strategy, product-market fit, talent, or truth. This mismatch isn't just a branding problem, but a market failure. A company in prior eras built or rebuilt around identity, AI, mobile, software, and infrastructure has no language to prove its difference, because the prior construct can't contain it. Intelligent Access is that home: a place for companies to anchor, showcase, highlight real differentiation, share future visions, and stake their claim in a new era, rather than blending into generic language from the previous one. Concretely, that means treating this era's opportunity as enterprise infrastructure, the layer that powers security, operations, compliance, and workplace intelligence together, not a vertical called access control that occasionally touches those other functions.
Intelligent Access is not a product category. It's an era, like electronic access control and mechanical locking before it. Each era holds a core promise, a record system, channel dynamics, truths, and companies that recognized the shift early and worked within it. Each era is important. Each is different and needs to be treated as such. This overview introduces, names, and defines the era. It lays out its distinguishing tenets. And it invites companies to share their stories, their promises for this era, and showcase how they stand out. The overview provides a backbone for companies competing in this new era.
Note: naming this era doesn't mean another era will follow or that it will be the era for the foreseeable future. In fact, just as there was an Intelligence Access Era preceding the Modern Electronic Access Era, there will be one after this (and another after that). What I'm doing here is breaking away from the old constructs of the past era and creating a home for this new era.
The physical security industry often presents its history as a single, uninterrupted journey of continuous improvement, moving from rolling boulders in front of caves to today's advanced security technologies. Access control is described as a steady progression: better readers, controllers, and cameras each year. However, this perspective overlooks the major shifts that have taken place. Instead of a linear story, the industry has evolved through distinct eras, each offering different answers to four core questions: the promise to customers, delivery methods, value creation, and ways of being rewarded. The distinctions between these eras mark fundamental shifts rather than incremental changes.
The first era, known as the Electronic Access Control Era (roughly 1970–2020), created a $10 billion high-security industry, evolving from the Mechanical Lock and Key Era. Its distinguishing promise was clear: replace physical keys with electronic credentials, control who enters, maintain records, and verify access when needed. The threat it defended against was physical: a person trying to pick a lock, clone a badge, or walk in behind someone who held the door open. We are the experts, and you should trust us. In this era, the door, which includes its panel, attached locks, and accessories, access rights, and event log, was the system of record. Value stemmed from system complexity, making certified experts indispensable. Identity was simply a number on a card, not tied to the individual's true identity. Manual provisioning and infrequent deprovisioning led to a growing gap between technical and actual access. Despite this, the era succeeded in its core aim of keeping bad people out and providing reliable access control. This approach was fundamentally different from the refinements of later eras, as its complexity and exclusion were features, not issues to be solved.
The second era, called the Modern Electronic Access Control Era (2020–2025), grew at a 5-7% incremental pace and rapidly saw the emergence of a new market to be addressed at a $70 billion opportunity, driven by enterprise software and accelerated by COVID. Unlike the first era, this era promised to combine the security of specialized systems with modern conveniences: cloud-based access, mobile credentials, user-friendly software, and a balance of convenience and security. The system of record started shifting from the door to the credential and its management in the cloud, though it still resided within the access control system. Technology additions and new market entrants, like Brivo, Openpath, Kisi, Prodatakey, and Genea, further distinguished this era. Enterprise sales strategies began to resemble SaaS, separating this period from the expert-driven, hardware-centric past. IT departments grew in buying influence, and some in the industry saw brand-building as a strategic asset. These changes, mobile access, cloud management, and IT-influenced decision-making, contrasted sharply with the previous era's manual, expert-driven processes. The shift was not gradual but marked, with a change in technology and the go-to-market approach. Outside capital flowed into the market.
But this home, this era, is not where the mainstream opportunity is, and it cannot hold as a construct for the opportunity in front of it. Many of the companies I mentioned, and an even larger group I have not, are set up and have strategies for much more, and a third era has arrived.
I call the third era Intelligent Access, representing a mainstream market opportunity potentially exceeding $100 billion. What distinguishes this era most is that access control transforms from a product category to essential infrastructure, spanning physical, identity, software, and enabling technologies. In some respects, the promise of the Internet of Things (IoT) is realized. The system not only regulates door entry but also continuously interprets identity (human or agentic), contextual data, current risk, and required access, across physical and digital realms, often with no human administrator involved. Intelligent Access unifies functions like access, video, automation, IAM, GSOCs, and threat intelligence, adapting across use cases and integrating flexibly. Here, the system of record shifts yet again: it is now the authoritative identity itself, such as one found in enterprise IAM or government-issued records. It is no longer tied to a single platform, door, or credential. In direct contrast to past eras, physical access control is demoted to a feature within a significantly larger value proposition. Ultimate value now belongs to those bridging authoritative identity, enablement, and physical enforcement. The ultimate value lies not just in traditional hardware or PACs. The threat has changed shape along with everything else. It is no longer a person trying to pick a lock. It is a hacker looking to leverage a networked device, a camera, a reader, a badge system, to reach IP, move laterally, or hold an operation hostage. And the buyer solving for that threat has changed too, from a facilities director signing off on a lock schedule to a CISO signing off on an identity and risk architecture. This is a step change, not an incremental evolution.
To clarify what has changed from the second to the third era: the distinction is not just down to better software, the models around it, and the art of the possible that results from them. The Modern Electronic Access Control Era introduced speed, bolted-on mobility, and cloud-native technology, but identity largely remained within the access control system. By contrast, the Intelligent Access Era operates and is built with mobile, cloud, and hybrid data, supported by AI architectures. It is mobile-first, AI-first, data-accessible, and hybrid by design. The real shift is that identity now lives outside the access control platform, in systems the platform neither owns nor fully controls. The platform's role is now to enforce access policies in real time, based on that external identity source, across both digital and physical domains. This change repositions who controls the source of truth and what value is created. This change is unlike prior eras, where system ownership and in-platform control defined value. This change breaks old truths and rules from past eras and opens the way for new truths and rules beyond what I list in this document. The transition is clear and fundamental, not just a technical improvement.
People keep asking me the right question: why is Intelligent Access actually worth more than the market before it? It is not enough to say software is better than hardware. Someone has to be willing to pay for it, and pay more, and I want to be specific about where that extra value is actually coming from, because I do not think anyone has laid this out plainly yet.
The addressable market itself is bigger. Legacy access control was a security line item, funded out of a security budget, argued for by a security director against a facilities budget that never had enough. Intelligent Access is an infrastructure line item, and infrastructure gets funded by IT, real estate, workplace experience, HR, and operations, not just security. That is not a bigger slice of the same pie. It is a different, much larger pie, with more people at the table who have a reason to be there.
It goes deeper into the building, not just wider across it. The old economics justified instrumenting only the doors that mattered most: the perimeter, the high-security zones, and the places where the cost of wiring and a certified integrator justified the risk. Untethered, mobile-first, AI-configured systems collapse that cost curve. Every interior door, every person moving through a space, becomes economically addressable, not just the entrance. This is not selling more of the same doors. It is selling doors that were previously unreachable.
The dollar value expands past security entirely. The same infrastructure that controls a door also generates space utilization data, feeds workplace analytics, supports building automation, and, in some models, becomes a revenue driver: tenant billing, capacity planning, and dynamic resource allocation. Security alone was always going to be a bounded market. Operations, automation, and revenue enablement are not, and this era is the first one where access control infrastructure is positioned to actually participate in that value rather than sit next to it.
Pricing power goes up. A cost center gets negotiated down every renewal. The infrastructure that a business actually depends on gets priced like infrastructure. Moving from capex hardware-margin thinking to platform and subscription pricing is not just a business model change; it is a TAM expansion, because willingness to pay tracks perceived value, and perceived value shifts the moment the product goes from keeping bad people out to running the building. That pricing shift is really a symptom of something bigger. Physical security has spent decades justifying its own existence as risk mitigation, a number you spend to avoid a worse number. Intelligent infrastructure flips that logic. The same system that secures a door also improves operational efficiency, informs real estate decisions, and feeds workforce productivity data that leadership actually wants. A cost center gets asked to justify its budget every year. A strategic asset gets asked what else it can do. That is the more durable version of the TAM argument: not just that this era prices differently, but that it changes which conversation security gets to have with the rest of the business.
Geography and market reach expand. The old model was gated by the availability of a trained, certified integrator network, meaning huge parts of the world and the mid-market were functionally unreachable. Cloud-native, remotely configurable, mobile-first systems do not need that gate. They open markets that previous-era channel economics could never serve.
Compliance and regulatory exposure further widen the buyer base. This is not a security-only conversation, and it has not been for a while. FICAM, PIV, TWIC, and NERC CIP already forced parts of this industry into identity-grade compliance. NIST 2 is doing the same thing to a much wider set of commercial buyers who never thought of themselves as a regulated industry before. NPSA is doing it in the UK. Every one of those frameworks assumes identity, not the door, is the thing being governed, which means every company that has to comply with one of them now has a budget-holder whose job is explicitly to solve this problem. That budget did not exist in the prior era.
And there is a simpler, less exotic driver sitting underneath all of this: fewer people doing more. Security and facilities teams are not growing headcount at the same rate as their footprint, and a system that actually reasons rather than just reports lets a smaller team cover more ground. That is the classic AI TAM expansion story, and it applies here as directly as it applies anywhere else.
Put those together, and the honest answer to "why is the TAM bigger" is not one thing. It is five or six things stacking on top of each other at once, most of which had never been true for this industry before this era. Our industry has spent decades apologizing for itself, hedging every claim, qualifying every number, deferring to whatever the integrator said was possible. This era does not have to. That posture alone, unapologetic instead of apologetic, is worth more to the TAM than any single feature on this list.
If Intelligent Access is going to function as a real era rather than a marketing label companies borrow for a quarter, it needs tenets specific enough that a company can fail them. Here are the five I use. Before I start, I want to be clear about what this list is and is not. These five tenets are not exhaustive nor exclusive, and I do expect some to and others not to stay fixed as the market matures. This is the beginning of a conversation and a framework for us to build off of, not the final word on it. Categories get sharper through argument, not through one person's framework being right the first time, and I expect other experts, operators, and companies to push back on some of these, add tenets I have not thought of, and challenge the ones written here that do not hold up under real market pressure. That is the point. Please do! As this era matures, companies and brands will start to differentiate themselves inside it, not just against it, staking out which tenet or combination of tenets they intend to own and build their identity around. The company that wins the architecture tenet will look different from the company that wins the infrastructure tenet, and both are legitimate positions within the same era. Even within the same tenant, there are opportunities to differentiate. Naming the tenets makes that differentiation clear, rather than every company claiming the same vague ground of being intelligent, AI-powered, a platform, or identity-first, without anyone able to tell the difference. So here are some of my tenants…
Identity, human and agentic, is the system of record, not the door and not the credential. A company operating in this era can point to an authoritative identity source, its own or a partner's, that governs access decisions, rather than maintaining a closed local database of cardholders that duplicates what a real identity platform already knows. And that identity source can no longer assume the identity on the other end of the decision is a person. Agentic AI systems, robots, and service accounts are showing up at doors and within networks with the same basic need: to be provisioned, verified, and deprovisioned, and most access architectures were never built to reason about non-human identities at all. I have called the human-only version of this gap the Shadow Database problem in prior Briefs I've written, and it is not a niche issue. Every large health network and financial institution, for example, runs multiple disparate identity systems stitched together by acquisitions, and the access control layer is usually the least trusted, least up-to-date copy of the truth in that stack. Add agentic identity to that picture, and the gap widens before it narrows. There is a bigger version of this claim worth stating plainly. Owning the identity record is necessary in this era, but it is not the same as owning the control plane. The control plane is the layer that actually orchestrates across identity, devices, policies, workflows, and now AI agents, deciding not just who someone is but what happens next, which device responds, which policy applies, which workflow triggers, which agent gets looped in. Identity is one input into that layer. It is not the layer itself. The companies that only solve identity will find themselves supplying data to whoever builds the control plane on top of them, the same fate PACs vendors are heading toward if they only solve the door. This is the tenet I expect to be the most contested of the five, and the one most worth watching, because the control plane, not the identity record, may end up being the actual seat of value in this era.
The architecture enables and removes constraints rather than manages around them. A company in this era can point to a specific engineering or architectural decision made before the commercial strategy was built that eliminates a dependency the rest of the market still treats as fixed. That could be a physical constraint, such as wiring or power. It could be a data constraint, such as batch processing rather than real-time event streaming. It could be a configuration constraint, such as requiring a certified technician for every change. The test is the same regardless of whether the constraint was removed by design or quietly worked around by marketing.
The architecture is mobile-first, AI-first, and hybrid by design, not cloud or onsite-only orthodoxy. Cloud-first was the right rallying cry for the previous era, but it was never the finish line, and treating it as one is exactly the kind of incremental thinking this era moves past. Companies operating in Intelligent Access build for a world where mobile is the starting point credential, AI is present in configuration and decisioning from day one rather than added later, data is accessible rather than trapped in a proprietary format, and the deployment model flexes across cloud, mobile, and onsite depending on what the customer's environment, latency, and resilience requirements actually demand. Hybrid here is not a hedge or a compromise. It is a recognition that a hospital network, a data center, and a corporate campus do not have the same tolerance or needs, and that a genuinely intelligent architecture accounts for that rather than assuming everyone is the same all the time.
This is also where Intelligent Access absorbs a promise that our industry and many others have made. The Internet of Things (IoT) was supposed to mean a world of connected devices that sensed, reasoned, and acted on our behalf, and what it actually delivered for most of two decades was a world of devices that sensed and reported, leaving the reasoning to a human staring at a dashboard. The sensors got cheap and plentiful. The intelligence and the computing power never showed up. What is happening now, and what the broader market has started calling Physical AI, is that the gap is finally closing. Cameras, locks, badges, and sensors are no longer just collecting data. They are running inference at the edge, making decisions in real time, and acting on those decisions without waiting for a human to review a report days later. And every one of those decisions throws off something the device was never designed to produce on purpose: metadata. A reader knows more than who is badged in. It knows when, how often, alongside whom, and whether that pattern just changed. A camera generates occupancy and movement data as a byproduct of doing its actual job. None of that data was the point when these devices were sold as security hardware. In this era, it is the point, or at least it is supposed to be, and the companies that treat their own hardware as a sensor network first and a security product second are the ones actually capturing the value sitting inside devices that have been shipping this data for free for years without anyone architecting for it. This is less of a new category and more of hardware finally becoming what IoT always promised, an old bill finally getting paid, twenty years late. RealSense's perception layer and Verkada's edge processing are both early proof of what that payoff looks like in this industry specifically, and I expect Physical AI to become the term the broader market uses to describe this tenet.
Platforms, composability, and infrastructure thinking replace closed, single-vendor stacks and closed self-conception. Open architecture is the baseline expectation in this era, not a selling point that companies get credit for mentioning in a deck. This shows up as published APIs used by real third-party developers, partner ecosystems that go beyond a logo wall and restrictive onboarding for no reason, and a willingness to let other companies build on top of the platform rather than requiring every layer of value to be captured internally. The unbundling and rebundling pattern I have written about, where companies pull identity, hardware, and workflow apart and let the market recombine them into faster, more flexible offerings, is a direct expression of this tenet.
But composability in the product is only half of it. The harder, less fakeable half is composability in how the company sees itself. A company operating in this era wants to be the layer that other companies' platforms depend on, not another logo competing for the same spec sheet line item, and it wants physical access to be one visible expression of a broader identity and enablement platform rather than the entire business. This is also precisely why traditional PACS vendors and the hardware manufacturers that serve them are structurally disadvantaged in this era, no matter how much AI they bolt onto their dashboards or how many APIs they publish. Their business model, their channel incentives, and their organizational memory are all built around defending the door and the companies they have won over the past 30 years as the center of value. A company can open its APIs and still think like a closed business underneath. Open, though, does not mean unlimited. The more this era leans into cyber resilience and hardening, and it has to, the more responsible interoperability becomes the actual baseline, not open for the sake of open. I know operators who used to run 120 integration partners and have deliberately cut that down to 20, filling the gaps with fewer, more qualified partners who do the job better, rather than defaulting to breadth. That instinct comes from an enterprise, regulated mindset, and I will be honest that it will not resonate the same way with a multi-tenant OEM whose entire business model depends on broad, low-friction partner reach. Both postures can be right for the company running them. What matters for this tenet is whether the curation is deliberate, built around resilience and trust, or just the old closed stack wearing an open-architecture pitch deck. The companies winning this tenet do not think of the door as the product. They think of the door as one execution point in a much larger system, and they build, price, and partner accordingly.
Data is a continuous, accessible asset, not a static log locked inside one vendor's database. Legacy systems treated the access event log as an audit trail to be reviewed after something went wrong, and treated that log as proprietary, a retention tool as much as a record. In some cases, we did nothing with the data. Companies in this era treat access to data as a live behavioral signal, streaming and processing it as it happens to feed risk models, workforce analytics, and anomaly detection, rather than storing it in a database for a compliance officer to pull a report once a quarter. They treat that data as something the customer, not just the vendor, has a right to access. This is also where the industry starts to genuinely intersect with zero-trust security architecture, where identity-centric access decisions replace the old assumption that anything inside the perimeter can be trusted by default.
I expect the list of companies in the Intelligent Access Era to grow, and I expect incumbents to shift strategies to align with it. I expect new companies we haven't heard of to enter the market and challenge companies and our conventional wisdoms as they execute these and other tenets more convincingly over the next few years. That is a feature of naming an era, honestly, not a flaw in the framework. A category with credible examples is more useful than a category with one, and a category with none is just an essay.
I also expect pushback on the claim that traditional PACs and their OEMs are structurally disadvantaged in this era, and I want that pushback, because it is the part of this argument that creates valuable work. My position is not that these companies cannot add AI, cannot open their APIs, or cannot rebrand around identity. Many are teasing about doing it, some will, and some already are. My position is that the center of gravity in this era sits with whoever reimagines the promise to the market and delivers on the opportunity in front of it. Whether that is owning the authoritative identity and enablement layer, human and agentic, or, you name your piece of the pie, what it is no longer is that the value is the door. A company can retrofit a great deal onto a legacy business. It is much harder to retrofit the belief that the door is the asset, and that belief is the actual starting condition from which every company in this era was built. And do not forget that they need the desire and courage to do it. I know some will, but many will not. And that is ok.
None of this is an argument against hardware, and I want to be direct about that, too. Everything I have said about identity, software, and infrastructure should not be read as software eating hardware, or as hardware quietly disappearing. Untethered proved that great hardware engineered around a real constraint remains one of the sharpest ways to win in this era. If anything, this era needs hardware to get more interesting, not less. We need to bring sexy back to hardware, not retire it.
The invitation underneath this paper is straightforward: If you run a company, work in a company, are looking to start a company, or want to invest in a company in this industry, and you believe you belong inside the Intelligent Access Era, measure yourself against the five tenets honestly, and share your tenets that make you uniquely great for this new era.
Join in the conversation.
Do something.
Bring something different.
There is no better time to be in our industry now.
Welcome to the new era in access control.
Welcome to the Intelligent Access Era.