Guides & How-Tos

Tennessee Access Control: Check the Exit Before Buying the Lock

By TN Security Review Editorial Team · · 8 min read

Retrospective: the week of May 12, 2026, during week two of Building Safety Month. This article was not published in May. It explains buyer questions, not a new Tennessee door law or approval of a specific access-control design.

An electronic lock can keep an unauthorized person outside and still be the wrong device for the door. Before a Tennessee buyer approves hardware, the project team needs to explain how authorized users enter, how occupants leave, what happens when equipment fails and who approves the finished work.

The Tennessee Department of Commerce and Insurance announced Building Safety Month on April 28. Week two, May 11-17, was titled “Voices of the Built Environment” and focused on the people responsible for building safety. The agency also reported that building codes address fire prevention, structural integrity and energy efficiency. TDCI’s April 28 announcement.

That theme applies directly to access control. A property manager may describe the security problem, yet the answer can involve the owner, installer, system administrator, design professional, fire or building official, accessibility adviser and people who use the entrance. A product brochure cannot settle their separate responsibilities.

Name every door before naming a product

Start with an opening schedule, not a shopping list. Give each affected door a stable identifier and record the spaces it connects, who uses it, the hours it operates and the present hardware. Note whether it is part of an exit route, an accessible route, a fire-rated assembly or a controlled entrance. Have the qualified project team confirm those classifications.

The purpose matters. A staff-only office door, an exterior employee entrance, a public lobby and a door from an occupied room do not present the same questions. Neither do a new building and an alteration to an existing facility. The State Fire Marshal’s Office says its Codes Enforcement section administers adopted fire and building construction safety codes and provides plan-review information, while exempt jurisdictions may handle their own review. Tennessee Codes Enforcement.

Ask who has jurisdiction over the actual property and whether plans, permits or inspections are needed. Do not infer the answer from an installer having completed a similar project in another Tennessee city. Local responsibility and building use can change the review path.

Record the security outcome in plain terms. Perhaps a door should remain available for exit while preventing uncredentialed entry from the other side. Perhaps a reception door needs a controlled release for visitors. Perhaps an accessible entrance needs a communication method when it is secured after hours. These statements allow the project team to test the result later.

“Install card access” is not a testable outcome. It names a technology.

An exit must still work as an exit

For covered workplaces, the federal exit-route standard says employees must be able to open an exit door from the inside without keys, tools or special knowledge. It also says an exit-route door must be free of a device or alarm that could restrict emergency use if that device or alarm fails. The standard contains narrow provisions for certain mental, penal and correctional facilities; a buyer should not generalize from those exceptions. 29 CFR 1910.36(d).

Tennessee operates an OSHA-approved State Plan. Federal OSHA’s state page says TOSHA has adopted applicable federal standards along with several identified state-specific standards. The page also lists activities outside state-plan coverage. A project team should confirm which authority and rules apply to a particular workplace rather than treating a general article as a compliance opinion. Federal OSHA’s Tennessee State Plan overview.

For each controlled door, ask the designer to document operation from both sides during ordinary use, power loss, fire alarm activation and a component or network failure. The proper response may depend on the opening and applicable code. This article does not prescribe a universal lock state.

Now ask what a person must know or do to leave. A credential reader outside an employee entrance does not explain the inside operation. Nor does a request-to-exit sensor, by itself, prove that every failure condition preserves required egress. The approved design and its test need to cover the complete opening, including lock, latch, closer, release controls and related alarm functions.

Inspect the route around the door as well. OSHA’s maintenance standard requires exit routes to remain free and unobstructed and requires safeguards designed to protect employees during an emergency to stay in working order. A secure door is not a reason to store deliveries in the path that leads to it. 29 CFR 1910.37.

Security screening cannot erase accessibility

The U.S. Access Board’s guide says security barriers and screening devices at accessible entrances cannot obstruct accessible routes or accessible means of egress. It also explains that at least one door serving each accessible room, space and entrance must meet the applicable door requirements. Access Board guide to entrances, doors and gates.

That matters before hardware is ordered. The same guide describes door-hardware operation, maneuvering clearances and two-way communication systems at entrances. A card reader mounted where a wheelchair user cannot approach it, a barrier placed across the accessible route, or an intercom without the required visual and audible signals may create a new access problem while solving another one.

Include people with varied mobility, reach, hearing and vision needs in the review. That is not a claim that a brief user review replaces an accessibility assessment. It is a way to expose ordinary-use problems before the project is accepted.

Consider a hypothetical after-hours lobby. Staff use credentials, while a visitor uses an entry communication system. The project team needs to consider the visitor’s ability to locate and operate that system, the response at the staffed location, and the visitor’s route once entry is granted. The door opening and the communication workflow are one user experience even if two vendors supplied them.

Name the person who owns the accessibility determination. If the answer is “the hardware vendor probably checked it,” the responsibility is not clear enough.

Access is a system.

Make the proposal describe failure, administration and change

A useful proposal identifies more than part numbers. It should show which openings change, the intended operation, connections to other systems, work by other trades, assumptions about existing doors and the acceptance criteria. It should state who supplies permits, drawings, configuration records, training and closeout documents.

Ask the proposer to describe dependencies. Does the opening rely on a local controller, a central server, a network link, a fire-alarm interface, backup power or remote administration? Which functions continue when one dependency is unavailable? Who receives a fault notification, and what manual procedure applies until repair?

These are questions, not predetermined specifications. Requiring every door to respond in one way could create a safety or operational error. Require the qualified designer and responsible authority to approve the intended behavior for each affected opening.

Administration deserves equal space. List who may issue a credential, change a schedule, unlock a door remotely, review access events and remove access after a departure. Decide how emergency changes are recorded. Set a method for vendor technicians to receive time-limited access instead of leaving a permanent shared account available after installation.

Preserve privacy in the design. Collect the data needed for the stated security purpose; do not add employee or visitor details merely because the system has an empty field. Establish who can retrieve records and how the organization handles requests, retention and disposal under its applicable policies and obligations. Obtain legal or policy advice where needed.

The owner should also receive the current configuration and operating instructions in a form the organization can use. A building should not depend indefinitely on one installer’s memory of why a door behaves a certain way.

Test what people will depend on

Write the acceptance script before installation. That lets vendors price the testing and prevents the final walkthrough from becoming an informal demonstration of one successful badge swipe.

For each affected opening, the qualified team should test the approved ordinary-use cases and every failure or alarm condition in the design. Include entry for each authorized user group, exit from the occupied side, visitor operation where provided, rejected credentials, scheduled locking changes, power or component failures, relevant alarm interfaces and recovery after service returns. Test the accessibility provisions and usable route alongside the reader’s status light.

Do not conduct an alarm or power interruption without coordination. Notify the responsible facility and life-safety personnel, protect occupants, and follow the approved test procedure. A publication cannot determine when an occupied building should be placed into a test mode.

Record the date, opening, scenario, observed result, person responsible for a correction and retest outcome. Photograph equipment only where the record will not expose credentials, wiring details or sensitive security information. Keep a short list for staff training that explains how to report a door fault without publishing the building’s system design.

Closeout should include as-built information, approved changes, administrative ownership, warranty and service contacts, spare or replacement credential procedures, and evidence that unresolved items were assigned. If a temporary bypass was used during construction, remove it or document its authorized disposition.

A stronger lock is not the project. A safer, usable and accountable opening is.