// KANTECH ENTRAPASS HEALTH CHECK · HANS STUDY · ONTARIO, CANADA
Kantech EntraPass Health Check
EntraPass sells in editions, and editions have ceilings. Most estates were sized for the building they started in, then grew. The constraint that eventually bites is usually commercial rather than technical, and it surfaces at the point somebody wants to add a site.
What the Health Check covers
EntraPass environments are usually smaller and simpler than an OnGuard or C-CURE estate, which changes what matters. The questions here are about headroom, topology and whether the system was ever configured beyond getting the doors working.
Edition and capacity headroom
Which edition is installed, what it limits, and how close the estate is to those limits on doors, gateways, sites and workstations. The most common finding on this platform and the one with the longest lead time to fix.
Gateway and site topology
How gateways are deployed and what depends on each one, whether the layout still matches the estate, and what happens to the sites behind a gateway when it is unavailable.
Controller firmware and field devices
Firmware consistency across controllers, reader and lock configuration, downstream device health, and offline behaviour when the gateway or server is unreachable.
Database and event history
Database size and maintenance, event history growth, archiving strategy, and whether backups have ever been restored rather than merely scheduled.
Cardholders and access levels
Stale records, schedule and access level sprawl, and whether the permission model reflects the organisation as it is now or as it was at installation.
Video and integrations
Video integration where present, intrusion, elevator and visitor management, and whether integrations are genuinely operational or configured once and never verified since.
Doors and supervision
Held and forced door handling, request to exit behaviour, lock power and battery calculations, and whether alarms are acted on or routinely cleared unread.
Security and hardening
Operator accounts and privilege, workstation access, encryption posture, audit trail retention, and version currency against support.
Where EntraPass estates commonly sit
- Approaching an edition ceiling that nobody has checked, so the next expansion turns into an unbudgeted platform decision.
- A gateway topology inherited from the original building, with sites added onto it in whatever way was convenient at the time.
- Controller firmware drifted across successive service visits, so field behaviour is inconsistent between doors that should be identical.
- Event history growing without a retention decision, because nobody was ever asked what the policy should be.
- Configured to the point where the doors worked and then left, with supervision, alarms and reporting never taken past defaults.
- Backups scheduled but never restored, which is a plan rather than a capability.
Who this is for
Organisations running EntraPass across one site or several, particularly where the system has grown past its original design or where an expansion is being planned. Commercial property, education, healthcare, light industrial and municipal.
Most useful before adding a site, before a budget cycle, or when doors have started behaving in ways nobody can explain.
What you receive
The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.
- A findings report organized by severity and by system layer, readable by both the security team and the IT team.
- A clear position on edition headroom, with what the next expansion would actually require.
- Specific, configuration-level recommendations tied to published guidance.
- A working session to walk through the findings and answer what the report raises.
Recommendations do not change based on who is selling. There is no product being steered toward at the end of this.
Scope and pricing
Fixed price, agreed in writing before the work starts. No hourly meter, no scope creep, and no invoice larger than the conversation suggested. Nothing is sold at the end of it either, which is the independence policy.
// Start here
Starter health check
$500
One system, any size
Remote, 90 minutes, live
- Version position against end of life and end of support
- The upgrade path in order, with the traps on it
- Obvious risks visible without a full review
- A straight answer on whether a full health check is worth your money
Credited in full against a full health check booked within 30 days.
// Most common
Health check, single site
$4,500
One site, up to 150 doors
Remote. Remote unit or on site available
- Full review across every layer listed on this page
- Findings report by severity and by system layer
- Configuration-level recommendations tied to published guidance
- Prioritized action list separating now, scheduled, and design-around
- A 90-minute working session to walk it through
// Multi-site
Health check, multi-site
$9,500
Up to 3 sites, up to 500 doors
Remote. Remote unit or on site available
- Everything in the single-site review, across the estate
- Redundancy, failover and database availability reviewed as one system
- Cross-site behaviour checked against what the design assumed
- A 90-minute working session to walk it through
// Larger estates
Enterprise
From $18,000
Beyond 3 sites or 500 doors
Scoped per engagement
- Scoped and priced in writing before anything starts
- Unusual integration, compliance or jurisdictional requirements accommodated
Extend a tier instead of jumping to the next one
Estates rarely land neatly on a boundary. If yours sits just past one, add to the tier below rather than paying for the one above. The rates follow the same slope as the tiers, so extending is never a worse deal than upgrading.
Cameras, doors, readers or controllers beyond the tier allowance. Counted as configured, not as licensed. (per 100)
A further site beyond the tier allowance, reviewed to the same depth and included in the same report. (per site)
Pre-configured appliance shipped to site and returned. See delivery below. (per deployment)
Where physical inspection is required. Travel agreed in writing before it is incurred. (per day, plus travel at cost)
A further 90-minute session, usually for a different audience such as IT, operations or a vendor. (per session)
The findings translated into a short document for a board, council or executive, written to be read by somebody non-technical. (one-off)
Findings inside five business days rather than the standard window. Subject to availability.
How the work is delivered
Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.
A pre-configured unit ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.
Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.
Where the work genuinely requires being in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Day rate plus travel at cost, agreed in writing up front and never added afterwards.
What a health check does not include
Listed because an unstated exclusion is what turns a fixed price into an argument at invoice time, and that is the exact failure this practice exists to review other people for.
- Remediation. The report says what to fix; fixing it is a separate engagement or your own team.
- Configuration changes. Nothing is altered on a live system during a review.
- Licence, hardware or software costs, which are yours and are bought direct.
- Vendor support cases, escalations, or dealings with your integrator on your behalf.
- On-site attendance, unless added explicitly.
- Ongoing monitoring or a retainer. A health check is a point-in-time assessment.
Prices are for a Kantech EntraPass environment and are held for 30 days from quotation. Travel, where an on-site day is added, is charged at cost and agreed in writing before it is incurred.
Health checks for other platforms
Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.
Genetec Security Center →
Architecture, roles and sizing under real load.
C-CURE 9000 →
CrossFire, iSTAR estate, SQL dependency and integrations.
Milestone XProtect →
Edition, Device Pack currency and support entitlement.
Avigilon Unity and Alta →
Which product family you are in, and what that decides.
AXIS Camera Station →
Edge analytics, and the device estate that limits them.
Lenel OnGuard →
Version position, database age, and access level sprawl.
Check the headroom before you need it
Edition limits are cheap to plan around and expensive to discover. The good time to find out is a budget cycle ahead of the expansion, not during it.
Independent of Kantech, Johnson Controls, and every integrator involved. See the independence policy.