Use this before you cancel the old panel, order new readers, or promise a cutover date. Hardware is the easy part. The user list is what stalls migrations.
The two starting points
Every migration starts one of two ways. Figure out which one you are in before you do anything else.
- Path A — you can export from the old system. Most software-based platforms let an admin export users as a CSV or spreadsheet.
- Path B — you cannot export anything useful. Older proprietary panels and some dealer-locked systems either do not support export, or the file is a format no one else can read. That is a known limitation of those systems — not something you did wrong. If this is you, skip to Path B.
Path A: export what you can
- Ask the old admin console (or your current integrator) for a user export, not just a badge report
- Confirm the export includes, at minimum: first name and last name
- Check whether it also includes email — if not, you will need to add it before import
- Pull a separate credential export (card numbers, PINs) if the system allows it — do not assume it is bundled with the people list
- Capture door groups / access levels as a reference (even screenshots) — you usually rebuild these in the new system, not import them
- Sanity-check the row count against current headcount. A mismatch usually means terminated staff were never deactivated
If the export is unreadable, incomplete, or the vendor wants a fee just to hand you your own data — fall back to Path B rather than losing weeks to it.
Path B: build a clean user list from scratch
No usable export means you start over with a list — and that is fine. Most new systems onboard faster from a clean roster than a messy legacy dump.
- Get the current employee roster from HR / people ops, not from memory or the old badge system
- Confirm the list reflects who is currently employed, not who ever had a badge
- Add contractors, part-timers, and after-hours cleaning or maintenance staff — HR’s roster may omit them
- Flag anyone who needs access before their official start date (new hires, seasonal staff)
Minimum fields vs. nice-to-have
Most modern access platforms import people on first name, last name, and email as the core fields. Email is usually the unique match key, and it is what triggers mobile-app invitations when the site uses phone credentials. UniFi Access, for example, imports users from CSV with those basics — then you add cards, PINs, or mobile credentials against each person.
Minimum to start:
- First name
- Last name
- Email address
Add once the base import works:
- Department / site (for grouping later)
- Employee ID or badge alias (optional, for your records)
- Access group name (e.g. “All staff,” “Warehouse”)
- Card number / facility code (only if reusing existing cards)
- PIN (if the system uses keypad codes)
- Mobile credential opt-in
Keep people, credentials, and door groups conceptually separate. Stuffing all three into one giant spreadsheet is how rows get corrupted.
Download a free starting spreadsheet with those columns already laid out: access-control-user-import-template.csv (opens in Excel, Google Sheets, or Numbers).
Credentials: what transfers, what you re-issue
- Mobile credentials usually do not transfer — plan to re-invite everyone from the new system.
- PINs sometimes transfer if you have the export; otherwise, reset them.
- Physical cards may or may not carry over. Compatibility depends on card format and facility code between the old and new readers. Do not assume a card that worked on the old system will work on the new one — confirm with whoever is installing the readers, and budget for re-enrollment if it is not compatible.
Do not email card numbers or PINs. Keep the spreadsheet on a restricted shared drive, not in your inbox.
Groups, access levels, and schedules
Do not rebuild your entire door/schedule matrix in a spreadsheet before cutover. Capture it at a high level:
- List the door groups you actually use (e.g. “All staff,” “Warehouse,” “After hours”)
- Note which schedule applies to each (business hours, 24/7, weekends)
- Note who belongs in which group — a column on the people list is enough
The detailed access-level build happens in the new system’s setup, not in the migration file.
Cutover day hygiene
- Deactivate every terminated employee before cutover — do not migrate ghosts
- Confirm the final user count against current HR headcount one more time
- Test a handful of credentials (a card, a PIN, a mobile invite) before going live building-wide
- Keep the old export and your prep spreadsheet on file for 30–60 days in case something needs a re-check
When to bring in a designer
If you are touching more than a handful of doors, mixing card formats, or migrating alongside a camera or network refresh, get the openings scoped before you pick software — not after you have already imported a broken list.
Access control consulting — door schedule, hardware path, and a package you can actually order.