Server policy
Person, group, facility, entry point, time, assurance, anti-passback, and two-person rules.
Every link is verified independently, from the mobile credential and gateway witness to the server decision, signed actuation, and physical passage observation.
MesaiGo does not conflate these outcomes. The decision, controller command, relay result, door contact, and turnstile sensor are bound to the same attempt while each retains its own audit meaning.
Person, group, facility, entry point, time, assurance, anti-passback, and two-person rules.
A time-bound, single-use final command bound to the relevant actuator.
Door contact, REX, turnstile direction, held-open, reverse passage, and tailgating events.
The policy and reason behind each allow or deny decision remain visible.
Online and bounded-offline behavior, clock drift, key expiry, and server unavailability are defined per profile. High Assurance does not fall back to Standard when required evidence is missing.
A signed, time-bound local policy package tied to the entry point.
Fire and emergency-egress circuits are managed independently of the MesaiGo cloud.
An explicit installation decision and change audit for each door type.
Together we can map controller, I/O, network, assurance, and life-safety boundaries.