2026 rankings updated · Independent editorial guidance for safer home-security decisions
Enterprise access control audit guide · Updated 2026

LenelS2 Auditing: Access-Control Logs, Compliance Evidence, and Review Checklist

LenelS2 auditing is about proving who had access, what changed, which events occurred, how exceptions were handled, and whether the access-control program still matches the risk of the building. A useful audit does not stop at exporting a report. It connects OnGuard or NetBox activity to people, doors, credentials, policies, video evidence, retention rules, and real review ownership.

Audit the whole access lifecycle

Review badge issuance, access-level approval, temporary access, visitor handling, terminations, lost cards, mobile credentials, and periodic recertification instead of looking only at door events.

Separate events from administration

Door forced, door held, invalid credential, reader offline, alarm acknowledgement, operator login, badgeholder edit, and access-level changes answer different audit questions and should be reviewed separately.

Preserve evidence before it ages out

Access-control logs, video clips, visitor records, help-desk tickets, HR termination records, and alarm notes often have different retention windows. Know what must be exported before it disappears.

Use exceptions to improve controls

Repeated forced-door alarms, shared badges, after-hours entries, inactive cardholders, stale contractor access, and unexplained operator changes should lead to corrective action, not just a saved spreadsheet.

Archived page, refreshed: This legacy Lenel auditing URL has been rebuilt for security managers, IT teams, auditors, and facility leaders who need practical access-control audit guidance rather than a thin archive page. LenelS2 is a Honeywell physical-security brand used for access control, video, and credential workflows in commercial environments.

What LenelS2 auditing should prove

A strong audit proves four things: the right people had the right access, important access changes were approved, unusual events were reviewed, and evidence can be reconstructed when an incident or compliance review occurs. For enterprise OnGuard deployments and smaller NetBox environments, that means comparing system data with HR, contractor, visitor, tenant, and facilities records rather than trusting the access-control database by itself.

Reports and logs to pull first

Start with cardholder status, access levels by person, people by access level, recently modified badgeholders, inactive credentials, expired or never-expiring credentials, operator logins, operator permission changes, door forced events, door held events, invalid card attempts, reader or panel communication faults, alarm acknowledgements, and manual unlock or override activity. Export the report parameters with the report so another reviewer can reproduce the result later.

Badgeholder and access-level review

Access-level review is where many audits find real risk. Look for terminated employees still active, contractors with no end date, executives with broad legacy access, duplicate cardholders, shared or generic credentials, doors included in groups by mistake, and temporary permissions that became permanent. The best control is a recurring owner review where department or facility managers certify access by role, building, floor, lab, server room, pharmacy, warehouse, or other sensitive zone.

Door events, alarms, and video evidence

Door forced and door held events deserve context. A single event might be maintenance, a delivery, a bad closer, tailgating, or a real security incident. Pair event logs with camera footage where available, alarm-monitoring notes, guard-tour records, service tickets, and corrective actions. Repeated events at one opening usually point to a design, hardware, training, or enforcement issue that should be fixed.

Operator activity and change control

Auditors should be able to identify who created or disabled a credential, who changed an access level, who acknowledged an alarm, who unlocked a door, and who changed an operator role. Keep administrator accounts named to real people, remove stale operator accounts, restrict broad permissions, and document emergency overrides. For larger environments, tie system changes to tickets or written approvals so the audit trail explains why the change happened.

Retention, export, and chain of custody

Decide how long access events, operator activity, visitor records, video clips, and incident notes must be retained for your environment. Regulated sites may need longer retention, legal holds, or immutable exports. When an incident occurs, export the relevant reports promptly, record the time range and filters, preserve related video before overwrite, and store evidence where it cannot be casually edited.

Practical audit cadence

Run lightweight exception reviews monthly, formal access recertification quarterly or semi-annually, and a deeper configuration audit at least annually or after major organizational, building, or system changes. High-risk doors and regulated areas should be reviewed more often than ordinary office entrances. The goal is a repeatable control owners can maintain, not a once-a-year scramble.

LenelS2 audit readiness checklist

  • Confirm the audit period, buildings, doors, access groups, and systems in scope before exporting reports.
  • Compare active cardholders with HR, contractor, tenant, and visitor records.
  • Review access levels by role and by sensitive area, not only by individual cardholder.
  • Identify stale credentials, missing expiration dates, duplicate users, generic badges, and terminated users.
  • Review operator logins, administrator accounts, permission changes, and manual unlock activity.
  • Investigate repeated door forced, door held, invalid credential, reader offline, and panel communication events.
  • Preserve related video, alarm notes, service tickets, and approval records with the exported access reports.
  • Document findings, owners, corrective actions, and the next review date.

LenelS2 auditing FAQ

What is LenelS2 auditing?

It is the review of access-control events, cardholder records, access levels, operator actions, alarm handling, and related evidence from LenelS2 systems such as OnGuard or NetBox to confirm that access is authorized, monitored, and reviewable.

Which LenelS2 reports are most useful for an audit?

Start with active cardholders, access levels by person, people by access level, recently changed badgeholders, inactive or expired credentials, operator activity, door forced events, door held events, invalid credential attempts, and alarm acknowledgements.

How often should access-control logs be reviewed?

Most organizations should review exceptions monthly, recertify access quarterly or semi-annually, and run a deeper annual audit. Sensitive areas may need more frequent review.

Is a report export enough for compliance?

Usually no. A report is evidence, but auditors also look for approval records, ownership, retention rules, incident handling, corrective actions, and proof that inappropriate access was removed.