For global enterprises, Aliro offers a path from vendor-controlled credentials to an access model the organization can govern.

An employee drives into a parking garage, enters a landlord’s lobby, crosses into her company’s offices, and reaches a restricted lab. Each door may belong to a different operator and run on a different access system. Today, that journey can require multiple badges, separate mobile credentials, and agreements to exchange sensitive keys among vendors.

For a global enterprise, this is more than an inconvenience. It is a governance problem. Who issues the credential? Who controls the keys that establish trust? Can the organization change a reader supplier without issuing a new identity to thousands of employees? Can it grant access through a partner’s building without handing that partner a shared secret?

For decades, the industry has treated the answer as a purchasing decision: choose the next proprietary credential and begin another migration. At GSX 2026, Safetrust co-founder Jason Hart argued for a more consequential question: What if the enterprise owned the trust model instead?

A credential should outlast a reader contract

Traditional access deployments often tie a credential, its data format, and its security model to a particular supplier. Even where a credential is technically secure, extending it across landlords, parking operators, and other systems can require custom integrations and difficult key-sharing arrangements. The result is familiar to security leaders: duplicated credentials, migration costs, and a roadmap constrained by someone else’s product decisions.

Hart offered a simple test for that dependency:

  • Do you own your credential keys?
  • Can you change reader vendors without replacing credentials?
  • Can you issue credentials without relying on one supplier?
  • Can you source mobile credentials from more than one provider?
  • Can you connect a new physical access control system without starting over?

If the answer to any of these is no, the next upgrade may recreate the lock-in you intended to leave behind. The cost can include reader changes, employee enrollment, integrations, and years of operational work.

Aliro 1.0, developed through the Connectivity Standards Alliance, establishes a common credential and reader protocol for interoperable access. It uses asymmetric cryptography to establish trust and supports NFC, Bluetooth LE, and Bluetooth LE with UWB for different entry experiences. The Alliance has also established a certification program and test suites. Certification is product-specific. Confirm which readers, wallets, and credentials have completed it before you treat a door as Aliro-capable. The Alliance comprises more than 220 participating companies, including access control vendors and major mobile platform providers. 

The leadership opportunity is to put the organization in charge of which credentials and readers it trusts. An enterprise can issue credentials under its own certificate authority and decide which readers and partner authorities it trusts. A landlord or parking operator can present its own credentials, and the enterprise can accept them at shared doors, without handing over private keys. Interoperability is cross-trust. It is not shared control.

The protocol also matters at the door: Aliro establishes a private channel and mutual authentication between credential and reader before access data is exchanged. For a security team, that makes reader trust and credential trust explicit parts of the design. It brings physical access closer to the certificate-based governance IT already uses for digital systems.

This changes what a badge means. It can become an organizational passport: one identity, issued under enterprise governance, that trusted systems can recognize across buildings and operators. Each operator still makes its own access decision. Interoperability does not mean that a credential automatically opens every door. Where the same physical credential also supports FIDO2, building entry and application authentication can sit in one identity program, with separate controls for each.

The transition is the strategy

The case for an open standard does not erase the installed base. A Fortune 1000 company may have thousands of readers across owned sites, leased offices, factories, and shared buildings. Some readers could gain Aliro support through an upgrade; others will need replacement. A legacy prox reader, for example, cannot read an Aliro credential simply because the enterprise issues one.

That is why a credible migration starts with coexistence. New credentials can support Aliro alongside the legacy technologies a site still needs. New reader purchases can be evaluated for both current requirements and a standards-based path forward. Hart demonstrated Safetrust’s migration card at GSX with Aliro and legacy credential capabilities on the same card, showing how an organization could begin issuance before every door has changed. The legacy capability works with the corresponding installed reader technology; Aliro itself requires an Aliro-capable reader.

For security leaders, the practical sequence is clear:

  1. Map the trust you have today. Identify who controls credential issuance, keys, reader configuration, and access policy across owned and third-party sites. Record where the same person carries multiple identities.
  2. Start where assurance matters most. Begin with server rooms, labs, and other critical openings, then restricted departments, general workspace, and the perimeter. Validate the specific legacy risks in your environment rather than assuming every installed system has the same exposure.
  3. Make interoperability a procurement requirement. Ask suppliers which products support Aliro, what certification applies, whether existing readers can be upgraded, and who will control credential and reader trust in the deployed design.
  4. Plan for years of mixed infrastructure. Move through discovery, lab validation, a site pilot, enrollment, and cutover before scaling. Define how Aliro and existing credentials will coexist, how partners will be authorized, and how issuance, renewal, and revocation will work at enterprise scale.

This is a phased infrastructure program, not a weekend badge swap. It also creates a decision leaders can make now: every new deployment can either extend a proprietary dependency or make the eventual transition easier.

The question for the next decade

Aliro is still early in its commercial rollout. Product availability, certification, wallet support, and upgrade options should be confirmed for each deployment. An open specification alone does not guarantee that every supplier will implement every capability or that every existing door can participate.

But the architectural direction is significant. The industry now has a common standard intended to let credentials, devices, and readers from multiple providers work together. For enterprises with global estates, that creates a chance to separate the identity they govern from the hardware they buy.

The comparison that matters is less about Aliro versus the credential already in your employees’ hands. It is about Aliro versus the next enterprise-wide migration. The strongest long-term access strategy gives the organization control of trust, room to choose its suppliers, and a migration path its operations can actually follow.

Based on Jason Hart’s GSX 2026 session on Aliro and enterprise credential migration.

Ready to take control of trust at the door? Walk through a migration plan built around the readers, credentials, and sites you already have.