For years, physical access in India has run on a mix of paper logbooks, RFID cards and standalone biometrics. Each answers a narrow question — did a card open a door, did a finger match a template — but none answers the one that matters most: is this person who they claim to be, and should they be here? That's the gap the next few years will close.
From credentials to identity
A card or a fob proves possession, not identity — it can be shared, lost or cloned. The shift underway is from 'a credential opened the door' to 'a verified person entered'. Identity-first access checks who someone is at the moment of entry, then grants access, rather than trusting a token issued long ago.
Aadhaar and DigiLocker make it practical
India has rare infrastructure for this: Aadhaar lets you verify identity at source (online or offline), and DigiLocker provides issuer-signed documents on demand. Together they make consent-based, source-verified identity checks practical at a reception desk or a plant gate — see Aadhaar visitor verification.
Offline is not optional
India's connectivity reality means any serious access system has to work without a live lookup. Offline verification (OVSE) — validating a UIDAI-signed QR or Paperless e-KYC with no OTP or live call — is what makes identity-first access workable at gates, plants and remote sites, not just connected offices.
Privacy becomes a design constraint
The DPDP Act turns data protection from an afterthought into a design constraint: consent, purpose limitation, minimisation, and never storing more than you need (for Aadhaar, not the number itself). Access systems that bolt privacy on later will struggle; those built consent-first won't. See the DPDP Act and visitor data.
Visitor management and verification converge
The last shift is consolidation: visitor management (the visit) and identity verification (the person) stop being separate tools and become one flow. That's the model Certopact is built around — manage the whole visit globally with Access, and verify identity where it matters with Entry.
This is a perspective piece, not legal or procurement advice — evaluate any approach against your own risk and compliance needs.