Audit the whole access lifecycle
Review badge issuance, access-level approval, temporary access, visitor handling, terminations, lost cards, mobile credentials, and periodic recertification instead of looking only at door events.
LenelS2 auditing is about proving who had access, what changed, which events occurred, how exceptions were handled, and whether the access-control program still matches the risk of the building. A useful audit does not stop at exporting a report. It connects OnGuard or NetBox activity to people, doors, credentials, policies, video evidence, retention rules, and real review ownership.
Review badge issuance, access-level approval, temporary access, visitor handling, terminations, lost cards, mobile credentials, and periodic recertification instead of looking only at door events.
Door forced, door held, invalid credential, reader offline, alarm acknowledgement, operator login, badgeholder edit, and access-level changes answer different audit questions and should be reviewed separately.
Access-control logs, video clips, visitor records, help-desk tickets, HR termination records, and alarm notes often have different retention windows. Know what must be exported before it disappears.
Repeated forced-door alarms, shared badges, after-hours entries, inactive cardholders, stale contractor access, and unexplained operator changes should lead to corrective action, not just a saved spreadsheet.
A strong audit proves four things: the right people had the right access, important access changes were approved, unusual events were reviewed, and evidence can be reconstructed when an incident or compliance review occurs. For enterprise OnGuard deployments and smaller NetBox environments, that means comparing system data with HR, contractor, visitor, tenant, and facilities records rather than trusting the access-control database by itself.
Start with cardholder status, access levels by person, people by access level, recently modified badgeholders, inactive credentials, expired or never-expiring credentials, operator logins, operator permission changes, door forced events, door held events, invalid card attempts, reader or panel communication faults, alarm acknowledgements, and manual unlock or override activity. Export the report parameters with the report so another reviewer can reproduce the result later.
Access-level review is where many audits find real risk. Look for terminated employees still active, contractors with no end date, executives with broad legacy access, duplicate cardholders, shared or generic credentials, doors included in groups by mistake, and temporary permissions that became permanent. The best control is a recurring owner review where department or facility managers certify access by role, building, floor, lab, server room, pharmacy, warehouse, or other sensitive zone.
Door forced and door held events deserve context. A single event might be maintenance, a delivery, a bad closer, tailgating, or a real security incident. Pair event logs with camera footage where available, alarm-monitoring notes, guard-tour records, service tickets, and corrective actions. Repeated events at one opening usually point to a design, hardware, training, or enforcement issue that should be fixed.
Auditors should be able to identify who created or disabled a credential, who changed an access level, who acknowledged an alarm, who unlocked a door, and who changed an operator role. Keep administrator accounts named to real people, remove stale operator accounts, restrict broad permissions, and document emergency overrides. For larger environments, tie system changes to tickets or written approvals so the audit trail explains why the change happened.
Decide how long access events, operator activity, visitor records, video clips, and incident notes must be retained for your environment. Regulated sites may need longer retention, legal holds, or immutable exports. When an incident occurs, export the relevant reports promptly, record the time range and filters, preserve related video before overwrite, and store evidence where it cannot be casually edited.
Run lightweight exception reviews monthly, formal access recertification quarterly or semi-annually, and a deeper configuration audit at least annually or after major organizational, building, or system changes. High-risk doors and regulated areas should be reviewed more often than ordinary office entrances. The goal is a repeatable control owners can maintain, not a once-a-year scramble.
It is the review of access-control events, cardholder records, access levels, operator actions, alarm handling, and related evidence from LenelS2 systems such as OnGuard or NetBox to confirm that access is authorized, monitored, and reviewable.
Start with active cardholders, access levels by person, people by access level, recently changed badgeholders, inactive or expired credentials, operator activity, door forced events, door held events, invalid credential attempts, and alarm acknowledgements.
Most organizations should review exceptions monthly, recertify access quarterly or semi-annually, and run a deeper annual audit. Sensitive areas may need more frequent review.
Usually no. A report is evidence, but auditors also look for approval records, ownership, retention rules, incident handling, corrective actions, and proof that inappropriate access was removed.