Nedap Pace: designing clarity in distributed access control

Designing clarity in distributed access control

Client + context

Pace is a Physical Identity and Access Management platform built for enterprise organisations. 50k+ identities across multiple sites, all under distributed control. Four roles share responsibility: space captains, card managers, security managers and workspace managers. Each one owns a piece of the system. None owns the full picture.

Project + challenge

Each role works differently, decides differently, and defines "done" differently. The product had to serve all of them without adding cognitive load to any of them. The challenge wasn't simplifying workflows. It was designing clarity into a system where responsibility is distributed by design.

Role

Leading design at Pace, I created the shared design framework and led the design of these role-based workflows, working with product and engineering from early exploration through to implementation.

Results

Approvals that scale

Recurring access requests now resolve automatically through policies. Space captains handle the exceptions instead of processing every request by hand.

-50%

Access restored faster

One simple flow restores access 50% faster. What took a string of manual steps is now a single guided process, making sure business processes don't grind to a halt.

Design as a strategic position

At Pace and increasingly across Nedap, design now shapes the products. A shared framework of four principles carries the thinking for feature design, design reviews, engineering alignment and the guardrails for the team's AI tools.

Pace platform overview for distributed access control.

The design framework

I created a shared design framework for the product and team. Four principles became a decision lens for feature design, design reviews, and alignment with engineering. Printed and displayed at the Pace office and used as guardrails for AI tools.

Flow 1User role: Space Captain

ScalingDecisions

Space captains review access requests for their workspaces. As organisations scale, manual decisions become bottlenecks. The challenge: reduce repetitive approvals without losing governance.

Old access request design before scalable approval logic.
Problem

When manual decisions don’t scale

Space captains were responsible for reviewing every access request manually. At scale this meant high volumes, slow turnaround, inconsistent decisions, and cognitive overload.

Policy logic insight model for recurring access request patterns.
Insight

From manual review to policy logic

Analysis showed that most requests followed recurring patterns: same profile, same location, same time frame. Manual review added almost no value. The real opportunity wasn't faster approvals. It was eliminating the need for them.

Human DrivenPolicy logic made understandable for anyone, not just administrators.

New policy builder design with conditions and affected people preview.
Solution

Designing scalable approval logic

We introduced configurable policies that automatically approve or reject requests based on predefined conditions. Space captains moved from being manual decision-makers to policy designers and supervisors.

Considered ClarityComplex policy logic made visible: see exactly who's affected before the policy is live.

New dashboard balancing automated access decisions and manual control.
Result

Balancing automation and control

With policies in place, routine access runs automatically. Space captains monitor through a dashboard and step in only when needed. Recurring patterns surface automatically and can be converted into a policy directly from the dashboard.

Intentional SimplicityColour only appears when it carries meaning: red for overdue, yellow for visitors, blue for contractors. No colour means no action needed.

Flow 2User role: Card Manager

AccessRestored

In large enterprises, lost cards don't happen one at a time. They come in waves, often at peak moments. What looks like a simple action quickly becomes operational load. The challenge: reduce operational load at peak moments.

Old lost-card administration flow before access recovery redesign.
Problem

Changing a card condition is not a solution

Card managers could mark a card as lost and revoke access. This solves a system state, but does not resolve the situation: someone is standing in front of you, waiting to get back in. The old process required marking the card as lost, adding a new card to the person, and issuing the replacement card. At scale, this meant no immediate replacement, multiple manual steps, and increased operational load.

Insight model showing the shift from card administration to person-centred recovery.
Insight

Shifting from card to person

The existing flow was built around card administration. But the real situation starts with a person at a desk, without access. What mattered wasn't the card, it was restoring access as fast as possible.

Situational EmpathyA lost card is not a status. It is a situation that needs resolving.

New card manager dashboard designed around the access recovery flow.
Solution

Designing a recovery flow

The card manager dashboard was redesigned around the recovery flow, not around card data. Three labelled actions, each one keystroke away. Nothing on screen that doesn't help solve the next case.

Human DrivenDesigned for performance under pressure. Fast to scan, fast to act.

Final recovery flow for temporary and permanent replacement cards.
Result

Reducing operational load

Multiple manual steps become one guided process. The flow handles both temporary and permanent replacements. Card managers move faster at peak hours and the person at the desk keeps their access.

Considered ClarityThe temporary card sits next to the face it belongs to. 24 hours of validity is on the card, not buried in the interface.