
UniFi Access Control and UniFi Identity: Tenants with User-Managed Visitor Access
Originally published August 12, 2025 | Fully Updated & Revised July 30, 2026
By Anton Kuznetsov
Co-Founder & Chief Network Architect, YesTechie Corp
California C-7 Low Voltage Systems Contractor | License #1148851
EXECUTIVE SUMMARY
A first-person network architecture breakdown and deployment guide evaluating UniFi Identity and UniFi Access user-managed visitor permissions. Drawing from high-stakes field deployments across Southern California commercial structures, gated communities, and multi-tenant facilities, this paper analyzes decentralized visitor pass delegation, QR code and PIN credential generation, UniFi Intercom hardware integration, and policy segregation (Shared vs Tenant Doors) designed to eliminate expensive third-party software licensing and reduce property management workload.
Clients often approach us with a specific requirement: They want to implement an Access Control system in their building where each tenant can independently grant access to particular doors or groups of doors. This is common in offices that regularly receive visitors, such as medical practices, law firms, accounting offices, and similar businesses, as well as condominiums where apartments have different owners who rent them out on platforms like Airbnb. Building management finds it highly inconvenient to handle temporary access for every single visitor.
With modern UniFi Access and UniFi Identity platforms, this decentralized capability is built natively into the ecosystem.
In this article, I'll share insights from the engineers at our company, YesTechie, based on a real-world setup in a Medical Office Building.
Building Overview
- Five-story structure.
- Two main pedestrian entrances from the street.
- Two entrances from the parking area.
- 15 individual doctor and clinic offices (tenants).
- 10 restroom doors (2 per floor).
- 10 utility room doors (Electrical Room and Janitor's Closet on each floor).
In our enterprise and multi-tenant installations, facility managers routinely waste dozens of hours processing routine guest credentials. Delegating visitor pass creation directly to individual tenant staff or residents without exposing core system administrative settings is the single most effective way to optimize daily site operations.
Setup Steps
- Start by defining policies for various door categories. The first policy, "Shared Doors," should encompass all common visitor entrances: the two main doors, the two parking entrances, and the restrooms. Additionally, establish a schedule dictating when access is permitted.
- Next, configure separate policies for every tenant. For instance, "Policy 302" grants access to the door of Office 302. In medical offices, this is typically set to 24/7 availability.
- Generate user accounts exclusively for permanent office staff. These users will have permissions to create visitor invitations. Click "Send Invitation" to deliver an invite to each user via the UniFi Identity App.
- In each user's settings, under Access > Access Policies, select "Shared Doors" along with the tenant-specific policy (e.g., Policy 302 for a doctor in Office 302).
- Once all users and policies are in place, navigate to Settings > Visitors and toggle on "Allow user-managed visitor passes."
After completing these configurations, the UniFi Identity App will display a new "Visitor Pass > Create New" button for authorized users.
During our field deployments, I always stress to client administrators that door policy naming conventions are critical. Keeping common ingress routes strictly separated from individual suite policies prevents permission overlaps when syncing user profiles across the UniFi Identity app.
Adding New Visitors
- In the UniFi Identity App, tap "Visitor Pass > Create New."

- Enter the visitor's First Name and Last Name (only one field is required). For enhanced privacy, use the full first name and just the initial of the last name, such as "Christine H."
- Under Locations, select the doors for access: e.g., "Shared Doors" and "Suite 302."

- Tap "Schedule" and choose from two options:
- One-Time Visit: Access is granted once; the pass is revoked after the initial use.
- Recurring Visit: Unlimited access within the specified timeframe.
- Select the validity period. Default options include "Today," "3 Days," "7 Days," or "Custom" (which lets you define precise start and end dates/times).
- Tap "Create" to generate the electronic pass.

- The pass will appear on-screen, displaying the visitor's name, start and expiration times, the host's name (the user who created it), and a QR code for unlocking intercoms and video readers.
- Save the image or send it automatically via email or text to the visitor.
This feature is incredibly convenient and cost-effective, saving significant time and resources; previously, custom software built on the UniFi Access API was often required. Additionally, you can assign an "Admin" role to select users, enabling them to issue PIN codes and NFC cards for visitors, edit existing passes, and add extra details like the creator's phone number, company name, and notes.
If you’re planning a project for your building, YesTechie is happy to offer our expertise in delivering projects of any complexity.
In addition to instant QR codes scanned at UniFi Intercom terminals or G3 Pro readers, hosts can generate temporary numeric PIN codes. This gives delivery drivers, contractors, or visitors without smartphones a seamless entry path.
Field Evidence: Real-World YesTechie UniFi Access Deployments
To see how UniFi Access and Identity workflows handle complex real-world entry requirements, here are three field case studies engineered by the YesTechie team:
1. Residential Perimeter: Malibu Gated Community (150+ Residents)
- The Challenge: Modernizing a fire-damaged, obsolete DoorKing and Hikvision entry infrastructure for a high-profile gated community in Malibu. Over 150 residents needed seamless vehicle access across two remote gates, while property managers were overwhelmed by manual guest logbooks and lost physical remote clickers. Cellular service at canyon gate points was virtually non-existent.
- Architectural Solution: I managed the network backbone, running a dedicated fiber optic link between both gate points back to a central UDM Pro Max core. We deployed UniFi U7 Pro Outdoor APs at the entry lanes to eliminate cellular dead zones, paired with six UniFi G6 Pro cameras for dual-view License Plate Recognition (LPR). For visitors, we installed UniFi Intercom terminals connected to UniFi Gate Hubs and LiftMaster barrier controllers. Residents use the UniFi Identity app to generate temporary Visitor QR Passes and send them directly to guests.
- Measurable Outcome: Achieved 100% LPR capture accuracy, onboarded 160 residents in under one hour using automated migration scripts, and enabled touchless QR and Mobile Tap entry, completely removing manual guest gate processing.
2. Commercial Logistics: 1 Gate Hub, 2 Independent Vehicle Gates
- The Challenge: A commercial industrial client required automated entry for an employee parking gate and a separate commercial delivery gate. Standard installer practice required buying two full controller panels, unnecessarily inflating hardware costs and system complexity.
- Architectural Solution: Rather than over-engineering the hardware stack, our team engineered a custom hardware workaround. We mapped two UniFi Intercoms (UA-G3-Intercom) and two G6 Bullet cameras into a single UniFi Gate Hub. To convert the hub's secondary 12V-powered lock output into an unpowered dry contact loop required by the delivery gate board, we integrated an industrial Schneider Electric 12V DPDT power relay (782XBXM4L-12D) with a matching RPZF2 DIN-rail plugin socket.
- Measurable Outcome: Saved the client thousands of dollars in controller and licensing fees by running two independent motorized vehicle gates off a single Gate Hub, maintaining full camera synchronization and instant app-based visitor triggering.
3. High-Traffic Campus: Chinese Christian Church (29-Door Multi-Building Layout)
- The Challenge: Securing a multi-building church and childcare/Sunday school campus in Thousand Oaks featuring 29 doors, administrative suites, a nursery, and high-traffic weekend sanctuaries. The client suffered from key fragmentation, unmonitored perimeter blind spots, and frequent 8-hour grid blackouts that shut down legacy systems.
- Architectural Solution: We electrified 29 doors using a combination of UniFi Access Reader G3 Pros, heavy-duty magnetic locks, and internal electrified lever sets with concealed thru-door wiring. The central cabinet was equipped with a UNVR Pro, Enterprise Access Hubs, and a commercial UPS with external battery banks engineered for 10 hours of failover. U6-LR access points act as Bluetooth Low Energy (BLE) gateways for UniFi multipurpose door sensors across all playground gates and perimeter doors.
- Measurable Outcome: A one-year field audit confirmed zero system crashes, 100% uptime during regional blackouts, total elimination of physical brass keys, and zero recurring monthly software fees across the entire 29-door ecosystem.
From a network architecture standpoint, native user-managed visitor access replaces what previously required complex API middleware or high monthly software seat fees, dramatically lowering total cost of ownership for building owners.
UniFi Access & Identity vs Legacy PACS: Multi-Tenant Architecture Comparison

UniFi Access & Identity vs Legacy PACS Comparison
For quick reference and mobile accessibility, here is the text-based breakdown of the UniFi Access vs. Legacy PACS comparison matrix shown in the image above:
UniFi Access & Identity Platform
- Visitor Pass Delegation: Decentralized (Delegated to tenant staff or residents via mobile app)
- Supported Credential Stack: Mobile QR Codes, numeric PINs, NFC cards, LPR, Mobile Tap, Face ID
- Software Licensing Model: Zero monthly subscription seat fees or recurring cloud API costs
- Perimeter & Vehicle Automation: Native LPR (G6 Pro), UniFi Intercom, and Gate Hub dry-contact relays
- System Onboarding Speed: Automated batch migration via custom scripts (e.g., 160 users in under 1 hour)
- Video Architecture Integration: Native single-pane linkage between Access audit logs and Protect NVR feeds
- Power Blackout Resilience: Low-voltage DC core supported by extended commercial UPS matrix (up to 10 hours)
- Infrastructure Flexibility: Long-distance fiber connectivity and localized wireless AP fields at gates
Traditional Legacy Physical Access Control (PACS)
- Visitor Pass Delegation: Centralized (Requires manual processing by property management or front desk)
- Supported Credential Stack: Physical plastic keycards, printed paper badges, physical RF clickers
- Software Licensing Model: High recurring monthly fees per user, per door, and third-party API seats
- Perimeter & Vehicle Automation: Patchwork of isolated systems (e.g., DoorKing, legacy analog controllers)
- System Onboarding Speed: Slow manual data entry introducing typos, formatting errors, and operational delays
- Video Architecture Integration: Disconnected third-party NVR siloes requiring manual timestamp cross-checking
- Power Blackout Resilience: Basic 15–30 minute consumer battery backups vulnerable to multi-hour blackouts
- Infrastructure Flexibility: Rigid copper constraints prone to signal attenuation across large perimeters
Conclusion: Enterprise Access Governance Without Subscription Friction
The evolution of UniFi Access 4.3.3 and UniFi Identity has fundamentally disrupted traditional multi-tenant access control architecture. By shifting temporary credential management away from overwhelmed property managers and delegating it directly to suite administrators, commercial facilities eliminate operational friction while maintaining absolute audit visibility.
From an engineering perspective, deploying a unified ecosystem centered on UniFi Intercom hardware, high-density Access Reader G3 Pro units, and Gate Hubs delivers three critical B2B advantages:
- Zero Recurring Licensing Fees: Unlike legacy access control platforms (such as Kisi or Verkada) that charge per-user, per-door, or per-month cloud API seat fees, UniFi Access operates on a single-investment hardware model.
- Unified Hardware Interoperability: Integrating License Plate Recognition (LPR) via G6 Pro cameras, touchless mobile credentials, and physical gate relays into one interface drastically reduces system complexity and physical footprint.
- Proactive Security Governance: Operating on current firmware branches like UniFi Access 4.3.3 guarantees protection against legacy control-bypass vulnerabilities, maintaining compliance across critical commercial spaces.
Whether you are designing access infrastructure for a 5-story medical facility, modernizing a 150-resident gated community, or retrofitting a multi-building commercial campus, success depends on precise low-voltage schematics and policy segregation.
Partner With YesTechie Engineering
Our team of certified Ubiquiti integrators manages every phase of deployment, from high-capacity fiber backbones and electrical strike retrofits to automated database migration and custom UniFi Identity policy structuring.
If your facility is suffering from manual access bottlenecks or outdated legacy hardware, contact the YesTechie engineering team today to schedule an on-site technical layout consultation and build a secure, license-free access foundation.
Frequently Asked Questions (FAQ)
1. Do tenant users need full administrative access in UniFi Access to issue visitor passes?
No. With UniFi Identity, permanent tenant staff or residents are granted specific user-level permissions. They can issue QR codes, numeric PINs, and temporary passes for their assigned doors directly within the mobile app without seeing master system logs, hardware configurations, or other tenant profiles.
2. Can a visitor pass be restricted to specific times and dates?
Yes. The host can issue a One-Time Visit pass (which expires immediately after its first use) or a Recurring Visit pass with custom start and end times, specific valid days, or preset durations like 3 Days or 7 Days.
3. What hardware is required for visitors to scan QR passes or enter PIN codes?
Visitors scan mobile QR codes or enter PINs using UniFi Intercom stations or UniFi Access Reader G3 Pro units installed at building entrances, parking gates, and tenant suite doors.
4. How does the system handle gate access in areas with poor cellular service?
As demonstrated in our Malibu gated community project, we deploy outdoor enterprise wireless access points like the UniFi U7 Pro Outdoor directly at entry lanes. This creates a localized Wi-Fi field, allowing residents and guests to load their mobile app credentials or QR passes without relying on cellular data.
5. Can a single UniFi Gate Hub control two separate automated vehicle gates?
Natively, the Gate Hub controls one dry contact gate and one 12V side door. However, as engineered in our commercial gate project, adding an external industrial isolation relay (like a Schneider 12V DPDT relay) converts the 12V output into a secondary dry contact loop, allowing one hub to manage two independent gates safely.
6. How does YesTechie assist commercial property owners with UniFi Access migration?
YesTechie handles complete low-voltage architectural design, Cat6A cabling, long-distance fiber backbones, electric strike and magnetic lock integration, Gate Hub wiring, automated database import scripts, and custom policy provisioning.














