Skip to content
PIAGO
All insights
GO! Site ApprovedOperations · Compliance

Access control and compliance should be one decision, not two systems

24 June 2026 · 5 min read · PIAGO

Most operations we see have both halves of this problem solved, separately.

There is an access control system — WinDsx, Gallagher, something equivalent — that decides whether a card opens a boom gate. And there is a compliance process, usually some combination of a portal, a shared drive and a spreadsheet, that decides whether somebody should be allowed through.

Between the two is a person, and a delay.

What the gap actually is

The access system knows who has a valid card. It does not know whether the person holding it still has a current medical.

The compliance process knows the medical expired last Tuesday. It has no way to tell the gate.

So the mechanism for closing that gap is somebody noticing, and then somebody else deactivating a card. Both of those steps happen during business hours, performed by people with other jobs, and neither is instant.

The window between a credential lapsing and access being withdrawn is the exposure. On most sites nobody has measured it. When it is measured, it is usually days and occasionally weeks.

Nothing goes wrong in that window, almost always. But "almost always" is the whole of the risk, and the window exists by design rather than by accident — it is what a two-system architecture produces.

The inverse failure is more common and more expensive

The gap runs both ways, and the direction that costs money every week is the other one.

Somebody renews their ticket on Monday. The certificate goes to their employer. Their employer sends it to the mine. Somebody at the mine updates the record and reactivates the card.

Each of those steps is a queue. The worker is compliant on Monday and through the gate on Thursday, and for three days a competent person has been sitting in a demountable or driving home.

Multiply by a contracting company workforce and this is not a rounding error. It is one of the largest and least visible costs of running contracting companies on a mine site, and it appears in nobody's budget because it is distributed across other people's businesses — which is precisely why it never gets fixed.

What changes when the gate reads the register

The alternative is not a new gate. It is making compliance the input to the access decision that already exists.

The requirements for a work area are held in the register. A person's credentials are held as dated records. When something lapses, access reflects it — not because somebody was told, but because the two are the same fact.

Three things follow, and only one of them is the obvious one.

The exposure window closes. The lapse and the loss of access are simultaneous. That is the obvious one.

The reinstatement window closes too. A renewal restores access without a queue of three people, which is where the recovered cost actually is.

The gate stops being a discovery mechanism. This is the one that changes how the site feels. When compliance is checked at the boom, the first anybody learns of a problem is a stopped vehicle with a crew in it and a supervisor being called. When it is checked in the register, the problem surfaces days earlier as a line on a list, and the conversation happens by phone with time to fix it.

The same gate, the same information, a completely different experience of the same day.

The integration question

Operators quite reasonably do not want to replace working access hardware to solve a records problem. Boom gates and readers are capital, they are installed, and they work.

That is the right instinct, and it is why the question to ask a compliance vendor is not "do you do access control" but "what do you do with the access control we already have". A product that requires you to replace WinDsx or Gallagher to get compliance-driven access is asking you to buy the wrong thing to fix the right problem.

The useful shape is compliance as the authority and the existing hardware as the actuator. The register decides; the gate does what it is told.

Why this is now an obligation rather than an efficiency

Until recently this was a straightforward operational argument: fewer stopped vehicles, less admin, faster reinstatement.

Since 1 June 2026 it has also been part of demonstrating critical control management under the Resources Safety and Health Legislation Amendment Act 2024. Operators have to show a systematic, verifiable approach to the controls preventing fatal events — and where competency is the control, "we check at the gate" is a weaker demonstration than "the gate is driven by a register that knows".

The difference is between a control that is performed and a control that is assured. One of those is much easier to evidence four years later, in front of somebody whose job is to find the gap.

Where to start

You do not need to solve this all at once, and the first step is diagnostic rather than technical.

Pick one contracting company. Work out, for their last five credential renewals, how many days elapsed between the credential becoming current and the person being able to work. Then work out, for the last five lapses, how many days elapsed between expiry and access being withdrawn.

Those two numbers are the size of the problem. Most sites are surprised by both, and by which one is larger.

Talk to people who know mining, not a sales team.

PIAGO is Australian owned and operated, out of Brisbane. Book a time and we will walk through your operation and tell you honestly whether we are the right fit.

Talk to Carl