Property, parking, and tenant can keep their own systems. The person at the door should not have to carry three cards.

An employee parks, walks the lobby, takes the elevator, and badges into a tenant floor. To that person it is one building. Behind the reader it is often three systems.

The property manager runs the lobby, turnstiles, and elevators. Parking is frequently a separate stand-alone system. The tenant runs the office suite. Each has its own policies, its own credentials, and no inherent reason to trust the others.

That is why people still carry two or three cards through a Class A tower. The problem is not that the backends are different. It’s that those independently managed environments were not designed to trust the same credential.

Why the usual fixes fail

Most buildings do not merge those systems. Property teams are risk averse. They do not want to inconvenience other tenants. Parking and the lobby stay separate because that is how they were purchased.

The other path is a key ceremony. Traditional symmetric-key credentials only work on a building reader if the tenant hands over its secret keys. Once those keys are shared, they are shared. If they are compromised, every party that holds them has a problem. Sharing secret keys introduces additional security and operational considerations, particularly when multiple independent organizations are involved. 

Workarounds fill the gap. Dual-technology cards. Extra mobile credentials. A tap that hides more than one identity. The journey looks simpler. The trust model is not.

What has to change is trust, not the access system

Aliro is a credential standard, not an access control system. Property, parking, and tenant can keep the platforms they already run. What changes is how a reader decides a credential is genuine and should be trusted.

Each organization keeps its own certificates. Aliro replaces the need to share symmetric secret keys with a certificate-based trust model. Public certificates can be used to establish trust between participating environments, while private keys are never shared.

The property reader can confirm that a tenant credential was issued by that tenant. The tenant credential can confirm it is talking to a real property reader. The property still decides who gets through shared space, when, and where, in its own access system. The tenant still issues and revokes credentials to its own people.

Interoperability is cross-trust. It is not shared control.

That boundary cuts both ways. Shared readers will trust tenants A, B, and C. Tenant B’s floor readers will not trust tenant A or C. Walking the wrong corridor does not open the wrong suite.

Trust does not eliminate independent policy 

Establishing trust between organizations does not mean giving up control. The property manager can continue defining access to shared areas through its existing access control system, while the tenant continues managing its own users, credentials, and tenant-controlled spaces.

The same principle applies as tenants move in and out. A new tenant establishes its own trust relationship with the property without requiring existing tenants to change their systems. When that relationship ends, it can be removed independently.

Adding another tenant means adding another trust relationship, not another shared access system.

The building does not have to be on Aliro first

Most multi-tenant sites will not replace every reader on the same day. Parking may still be prox. The lobby may still be on another legacy technology. The tenant may be ready for Aliro now.

The Safetrust Aliro Migration Card is built for that gap. One credential can work on the shared doors you do not own and on Aliro at the suite. The person at the door taps once. They do not need to know which technology opened which door.

When parking or common-area readers move later, the same card and the same mobile credential update in the field. That is not a second issuance project.

Start with the openings that already connect organizations: garage, lobby, elevator, amenities. Leave tenant floors on their own timeline. Modernize readers on the replacement cycle you already have.

What Aliro is changing

Aliro does not collapse three access systems into one. It removes the requirement that each system issue its own credential.

The employee gets one journey. Each organization keeps its keys, its policies, and its platform. Cards and mobile use the same trust framework. A tenant can update before the property is ready, and the property can change without collecting every badge in the building.

On September 30 we walked this model in Aliro in Multi-Tenant Buildings, sixth in the Safetrust Aliro series. Catherine Carducci, Daniel Bailin, and Will Holderness covered the certificate exchange, tenant policy on the credential, the Migration Card on shared doors, and what actually happens at move-in and move-out.

The session is available to watch now on demand.

Earlier sessions remain at https://youtube.com/@safetrustinc, and additional Aliro resources can be accessed at https://www.safetrust.com/aliro.