
Most facilities land somewhere in between, which is why the realistic answer is usually hybrid rather than replacement.
This covers where mobile access credentials genuinely outperform cards, the four constraints that disqualify them, and the questions to settle (BYOD policy, reader compatibility, privacy) before committing.
A credential in a wallet app or vendor app, transmitted over NFC or Bluetooth to a compatible reader. This is what most people mean. Bluetooth long-range credentials, which permit reading at greater distances (useful at vehicle gates, and a genuine capability cards don’t have).
QR codes are displayed on screen, read by an optical scanner. Lower infrastructure cost, weaker security, common in visitor and event applications.
A digital badge image — a photo of a credential in an app, for visual identification only, with no access function. A different thing entirely, and worth naming because it’s frequently confused with the above.
Five situations, stated without hedging because they’re real advantages.
Instant issuance and revocation. A credential can be issued to a new hire before they arrive and revoked in seconds from anywhere. No printing, no shipping, no physical recovery. For a distributed workforce, this is a significant operational advantage.
No replacement cost for loss. Phones are lost less often than badges, and a lost phone’s credential is revoked remotely rather than reissued physically. In high-reprint environments, this is the strongest economic argument.
Long-read-range applications. Bluetooth credentials read at vehicle-gate distances, which cards cannot do. Parking and gate access are the clearest use cases.
Multi-site and contractor access. A contractor working across several sites can be granted and revoked per site without physical logistics.
Phones are rarely forgotten. People forget badges routinely and phones seldom. That meaningfully reduces the temporary-credential and piggybacking burden.
"People forget their badge and remember their phone. That single behavioural fact eliminates a surprising share of temporary-credential administration."
Where mobile access credentials fail, in order of how often they’re decisive.
A credential inside a phone identifies no one to anyone. This disqualifies mobile-only deployment wherever visual identification matters—which is most verticals in your market.
In each, the badge’s primary function is visual, and access control is secondary. Mobile addresses the secondary function while eliminating the primary one.
Requiring an employee to install an employer application on a personal device raises questions that many organizations haven’t settled. In unionized environments, it may require negotiation. Sub-issues: employees without smartphones, employees who decline installation, and whether the employer will supply devices.
Phones are prohibited or impractical in many work environments, such as cleanrooms, some production areas, wet or hazardous environments, and settings where hands are gloved or occupied. A worker in PPE retrieving a phone from under a smock to badge in is worse than using a card.
Mobile access credentials require compatible readers. A facility running legacy readers faces the same reader-replacement project as a credential migration, and mobile capability doesn’t reduce that cost. If you’re replacing readers anyway, specifying mobile-capable, multi-technology readers makes sense; if you aren’t, mobile is a reader project in software disguise.
Worth its own section — this is where mobile deployments generate objections that surprise employers.
App permissions. Access control apps commonly request Bluetooth and sometimes location permissions. Employees reasonably question what’s collected on a personal device, and the answer needs to be documented before rollout rather than improvised afterward.
Location inference. Even without location permissions, credential reads generate a movement record. That’s equally true of cards — but placing the mechanism on a personal device changes how employees perceive it, and perception drives adoption.
Personal device data on employer systems. Where the credential platform holds device identifiers, that’s personal information with retention obligations.
Practical recommendation: publish a short, plain-language statement of what the app accesses and what the employer can see, before deployment. Mobile credential rollouts fail more often because of employee resistance than because of technology, and resistance is usually an information problem.
For most facilities, the realistic answer.
Physical card as the primary credential, carrying a photo, name, role, and visual identification — retaining every function a badge serves beyond opening doors.
Mobile credential as an optional additional factor, for employees who want it, in situations where it’s convenient.
Cost consideration: hybrid means paying for both. It’s justified where mobile solves a specific problem — multi-site contractors, vehicle gates, distributed staff — and not justified as a general convenience upgrade.
Where mobile-only is defensible: corporate office environments, no visual identification requirement, modern readers already installed, a resolved BYOD policy, and an alternative for employees without suitable devices. That’s a narrow set of conditions, and worth stating as such.
Reviewing mobile alongside physical credentials? Request a specification review
For door access, yes, with compatible readers. For visual identification — role recognition, public-facing verification, screened-adult identification — no. Facilities requiring both typically run a hybrid program.
Modern mobile credentials use encrypted, authenticated communication and compare favourably to legacy proximity cards. Against a properly configured modern smart card, the security difference is smaller than the operational differences.
Yes. Readers must support the relevant mobile protocol. If reader replacement isn't already planned, this is the dominant cost.
This raises BYOD policy questions and, in unionized environments, potentially bargaining questions. Settle policy and provide an alternative for employees without suitable devices before deployment.
No spam, no cadence anxiety. Just practical badge intel when we publish it.