Salto and FCS Solutions are integrating electronic access control with day-to-day housekeeping operations. What initially appears to be a convenience feature for hotels touches on a key aspect of modern security architecture: staff no longer gain access to guest rooms via master keys with broad physical access rights, but on the basis of a specific work order. Process data and access rights are thus becoming more closely intertwined.
The master key is one of the simplest yet most problematic tools in hotel operations. It enables housekeeping staff to access numerous guest rooms efficiently, but in doing so concentrates considerable authorisation in a single physical medium. Loss, unauthorised sharing or misuse can be mitigated organisationally, but can only be controlled to a limited extent through technical means. Where large numbers of staff, rotating shifts and external service providers come together, a practical solution can therefore quickly become a security risk.
This is precisely where the integration of Salto and FCS Solutions comes into play. The FCS1 Hospitality Operations Platform is connected to the Salto Space access platform. When an employee starts a cleaning task assigned to them in the FCS1 mobile app, the relevant guest room can also be unlocked via the same app. According to the companies, access authorisation applies exclusively to the assigned room and only for as long as the corresponding work order is active. This changes not only the medium used to open a door, but also the logic behind the authorisation.
From role-based access to situational authorisation
From a security perspective, the architecture behind the integration is therefore more interesting than the elimination of a physical key. Access is no longer granted exclusively via a static role such as ‘Housekeeping’. It arises from a specific operational process: a particular person is granted access to a defined room at a specific time for a specific task.
Physical access control is thus moving closer to a principle that has long been established in IT security: authorisations should be aligned as closely as possible with actual requirements. Instead of granting an employee access to an entire floor or a large group of rooms as a precaution, access rights can be restricted to the specific room required for the task at hand.
This corresponds to the principle of least privilege: an identity is not granted as many rights as possible, but only those necessary for its current task. This is significant for physical security because traditional locking systems are typically organised in a rather static manner. A key or credential opens those doors for which it has been authorised in advance – regardless of whether this access is actually required at that specific moment.
Salto Space already supports differentiated management of individuals, groups of people, rooms, areas and access rights. Mobile credentials and the logging of access events are also part of the digital infrastructure. The integration with FCS1 adds a further layer of context to this architecture: it is not just an employee’s identity or role that determines their access rights, but also their current work assignment. A static authorisation thus becomes a situational one.
The audit trail becomes a security tool
The second key aspect concerns traceability. Whilst physical master keys can be issued, documented and reclaimed, this does not in itself provide a precise picture of their actual use. Digital access control, on the other hand, can log events and associate them with a user, a room and a specific time.
This capability is particularly important in the hospitality sector. A guest room is not an ordinary operational space. Staff must regularly gain access to an area containing personal belongings, where guests expect a high degree of privacy during their stay.
More granular access rights and traceable event data have a dual effect here. Preventatively, they help limit the scope of potential access. Following an incident, security managers can reconstruct much more precisely which authorised individuals had access to a specific room at what time.
The audit trail thus becomes an integral part of the security architecture itself.
However, it replaces neither organisational controls nor secure identity management. Digitalisation does not eliminate risks; it transforms them. Where the mechanical key is replaced by a smartphone, app, platform and interface, other questions take on greater significance: How reliably is a user’s identity verified? How are authorisations granted and revoked? What happens if a device is lost or compromised? How are the systems and interfaces involved secured?
The security benefit therefore depends not solely on the electronic lock, but on the integrity of the entire digital process chain.
Access control becomes part of the operational process
This is where the far-reaching significance of integration lies. Electronic access control is increasingly evolving from an isolated security system into an integral part of the organisation’s IT and building infrastructure.
Salto already envisages integrations for its hospitality platform with property management and room management systems, video surveillance, fire alarm technology, lift control, time and attendance systems and building automation. The partnership with FCS Solutions now brings this principle directly into the operational hotel process.
A work order defines the requirement; the platform links it to a person and a room, resulting in time-limited access. Once the task is completed, the access expires. The door lock thus becomes a physical endpoint of a digital workflow.
For security managers, this is more crucial than the much-cited ‘keyless experience’. It is not the device on the door that determines the quality of the system, but the logic behind it: how precisely rights are granted, restricted and documented.
The integration of Salto and FCS Solutions thus exemplifies the direction in which access control in networked buildings is heading: away from blanket access rights, towards context-dependent access.
The master key combines many rights into a single physical object. The digital architecture distributes them in a targeted manner – according to task, location and time.
[ML]




