Behavioral Anomaly Detection for Access Control
Pattern of Life builds a per-cardholder, per-door, per-peer-group baseline from your Gallagher event history, then flags activity that falls meaningfully outside it.
Pattern of Life is a User & Entity Behavior Analytics (UEBA) plugin for Gallagher Command Centre. It continuously ingests access events, learns each cardholder's normal patterns (which doors, which times, which days, which peer groups), and surfaces statistically meaningful deviations back into Command Centre as alarms or annotations. Designed for large city, state, and critical-infrastructure deployments where the event volume makes human review impossible.
The technical surface.
What it does, said plainly.
Multi-model anomaly scoring
Temporal models (time-of-day, day-of-week), spatial models (door affinity), and peer-group models (this person vs. their cohort) combine into a single anomaly score.
On-prem by default
Ships as a hardened Docker stack for Windows or Linux. Cardholder PII and event data never leaves the customer environment. Optional air-gapped operation.
Tunable sensitivity
Per-site, per-zone, and per-cohort thresholds. Quiet hours, drill windows, and known-good exceptions are first-class.
Operator-friendly explanations
Each alarm includes the why: 'card 22841 accessed door 14 at 04:12 - typical access window is 07:30-18:00, peer group never accesses outside business hours.'
How it's wired.
- 01Gallagher CC REST → event ingest service
- 02Time-series store (event history, per-cardholder rolling windows)
- 03Behavioral model pipeline (temporal, spatial, peer-group)
- 04Anomaly scorer → Gallagher CC alarm/annotation back-channel
- 05Operator UI for tuning, review, and feedback loop
Real customer scenarios.
Bring Pattern of Life into a deal.
Demo against your customer's actual workflow. Pricing the same day.
