Sixty-five terms we use every day, explained the way we would explain them to a customer.
Each entry stands on its own: you should not have to read the one above it to understand the one you came for.
Identification and credentials
RFID (Radio-Frequency Identification)
Technology that identifies an object or a person at a distance using radio waves, without contact and without needing the credential to be in view. An RFID system is a tag (the label or the card), a reader, and software that interprets the code it reads. It is used for access control, asset inventory and traceability in production.
NFC (Near Field Communication)
A subset of RFID that works at very short range, typically under four centimetres, at 13.56 MHz. It is the technology in smartphones and contactless payment cards: the short range is a security measure, not a limitation.
Low frequency (125 kHz)
The first generation of RFID cards. Cheap and forgiving, but the code can be copied with a duplicator costing a few euros: not advisable for any application where security matters.
High frequency (13.56 MHz)
The current standard for access control. It supports encryption and mutual authentication between card and reader, so the card does not simply announce a number: it proves it knows a key.
Mifare Classic
A very widespread and cryptographically obsolete family of RFID chips: the weaknesses in the Crypto1 algorithm have been public since 2008 and cloning a card is within anyone’s reach. It should be replaced, not built on.
Mifare DESFire EV2 / EV3
The secure generation: 128-bit AES encryption, mutual authentication, and several independent applications on the same credential. It is the standard we recommend for new installations.
UHF (Ultra High Frequency)
Long-range RFID, from a few metres up to about ten. It is used for vehicle access and for asset inventory, where the point is to read many tags at once while walking through a room.
Card
The physical carrier of an identity: a PVC card, a key fob, a wristband or a sticker. The difference between a cheap card and a good one is not the printing but the chip inside it.
Barcode and QR
Optical identification: it requires the code to be visible and framed. It costs almost nothing and is irreplaceable where the credential is paper or shown on a screen — an entry ticket, a temporary visitor badge.
Biometrics
Recognition based on a physical characteristic: fingerprint, face, iris, hand geometry. In Italy its use for time and attendance is heavily restricted by the Garante, the Italian data protection authority; for access to sensitive areas it is possible, but it requires a documented impact assessment.
Gates and devices
Tripod turnstile
The most common gate: three rotating arms that let one person through at a time. Cheap, compact, and it does not stop anyone climbing over. Suited to offices and companies that need to count and regulate rather than physically prevent.
Full-height turnstile
A structure that reaches the ceiling and cannot be climbed. Used where the gate is isolated or unstaffed: industrial perimeters, plants, depots.
Speed gate
Glass wings that open for an authorised passage. High throughput, an appearance suited to corporate receptions, and available in a wheelchair-accessible version. It is the usual choice for headquarters lobbies.
Anti-passback
A rule that stops the same card entering twice in a row without having exited first. It prevents passing a card to a colleague and keeps the roll call trustworthy in an emergency.
Tailgating
An unauthorised person entering immediately behind an authorised one. It is the most common weakness in access control systems, and it is countered with the geometry of the gate or with dedicated sensors, not with software.
Reader
The device that reads the card and talks to the controller. Its quality comes down to three things: which card technologies it supports, which protocol it uses to talk to the controller, and whether it is protected against tampering.
Wiegand
The legacy communication protocol between reader and controller, dating from the 1980s. It is neither encrypted nor authenticated: anyone with physical access to the cabling can intercept and replay the codes. Still extremely widespread, for compatibility.
OSDP (Open Supervised Device Protocol)
The successor to Wiegand: two-way communication, AES-128 encryption in the Secure Channel profile, and supervision of reader status. It is the standard to ask for in any new installation.
Attendance, sites and assets
Time and attendance
Recording entry and exit times for workforce management and payroll. In Italy the data may be processed for contractual purposes, but it cannot be used for remote monitoring of work activity under Article 4 of the Italian Workers’ Statute (Law No. 300/1970).
Digital construction site card
The identification card required by Article 3 of Italian Law 198/2025, carrying an electronically readable unique code — QR, RFID or NFC — and interoperable with the Sistema Informativo per l’Inclusione Sociale e Lavorativa (SIISL), the national information system for social and labour inclusion. It replaces the paper badge with an identifier that can be verified in real time.
DURC
Documento Unico di Regolarità Contributiva, the single certificate of contribution compliance: it certifies that a company is up to date with its contributions to INPS (social security), INAIL (workplace accident insurance) and, for construction firms, the Casse Edili. In site access control systems its expiry date can be an automatic condition of entry.
Asset inventory
Periodic stocktaking of an organisation’s durable assets. For Italian local authorities it is mandatory and must be updated annually (Article 230(7) of the Italian Consolidated Law on Local Authorities, Legislative Decree 267/2000). With UHF RFID labels a room is counted by walking through it, rather than by reading one label at a time.
Facility management
Integrated management of a building’s spaces, systems and services: planned maintenance, on-request work, room and desk booking, floor plans.
Smart locker
An electronically managed compartment cabinet where opening is authorised by the same identity that governs access. Used for keys, personal protective equipment, tools, shared devices and handovers between shifts.
Cloud, security and compliance
SaaS (Software as a Service)
Software used through the browser and paid for by subscription, with no local installation. The supplier runs the infrastructure, the updates and the backups; the customer avoids the upfront investment but depends on the supplier’s continuity — which is why it matters to know where the data is and how it is recovered.
ACN qualification
Recognition by the Italian National Cybersecurity Agency certifying that cloud services intended for Italian public administration meet its security requirements. In the cases covered by the qualified-cloud rules, a service without the qualification cannot be procured by a public body.
ISO/IEC 27001
The international standard for information security management systems. It does not certify that a product is secure: it certifies that the organisation has a documented system for managing risk, and that a third party audits it periodically.
ISO/IEC 27017 and 27018
Extensions of 27001 for cloud services (27017) and for the protection of personal data in the cloud (27018). These are the controls that matter to anyone entrusting employee or citizen data to a supplier.
ISO/IEC 20000-1
The standard for IT service management systems: it defines how service levels, incidents, changes and capacity are managed. It is the standard that concerns the quality of the support, not of the product.
NIS2
Directive (EU) 2022/2555, transposed in Italy by Italian Legislative Decree 138/2024, imposing security measures and incident notification duties on a wide range of public and private bodies. Physical access control is one of the measures it explicitly requires.
Cyber Resilience Act
Regulation (EU) 2024/2847, the European regulation on cybersecurity requirements for products with digital elements: anyone who places a connected device on the market must keep it secure throughout its lifecycle. The reporting obligations start on 11 September 2026 and the remaining obligations on 11 December 2027.
GDPR
Regulation (EU) 2016/679 on the protection of personal data. In access control it comes down to three questions you have to be able to answer: for what purpose do you collect the data, how long do you keep it, and who can see it.
DPIA (data protection impact assessment)
The assessment to be carried out before processing that is likely to result in a high risk to people’s rights. It is required, for example, for biometric systems and for systematic monitoring of publicly accessible areas.
AI Act
Regulation (EU) 2024/1689 on artificial intelligence. It classifies systems by risk level; those used for workforce management fall under Annex III as high-risk, with the obligations applying from 2 December 2027.
AI literacy
The duty set out in Article 4 of the AI Act: anyone who provides or deploys artificial intelligence systems must take measures to support AI literacy among the staff who operate them. Regulation (EU) 2026/1744 rewrote the article and made explicit that it does not require guaranteeing a set level of competence: the measures are calibrated to role, experience and context rather than identical for everyone. It remains an obligation, not a recommendation.
Audit trail
A verifiable record of the relevant events, actions and decisions in a digital process: who did what, when and to which record. It exists to reconstruct a fact after it happened, which is also why it has to be protected from the very people it might describe.
Privacy by design
The principle that data protection is considered from the design stage of a system and not added after release. It is set out in Article 25 of the GDPR, but the most persuasive argument stays economic: as a design constraint it costs a fraction of what it costs as a rebuild.
Security by design
An approach that builds security requirements into the design, development, configuration and operation of a system rather than laying them on top at the end. In an AI system it covers permissions, input protection, environment segregation and escalation paths.
Artificial intelligence and data
Large language model (LLM)
A model trained on enormous quantities of text, able to produce answers in natural language. It does not “know” things: it estimates the most probable continuation of a text, and that is precisely why it can be wrong with confidence.
RAG (Retrieval-Augmented Generation)
A technique that retrieves the relevant documents and hands them to a language model as context before it answers. It does two things: it makes the model answer from your documents instead of from its generic training, and it makes it possible to cite the source of every statement.
Chunking
Splitting a document into blocks small enough to be retrieved precisely and large enough to keep their meaning. It is the choice that determines the quality of a RAG system more than any other: a badly cut block produces a wrong answer even with the best model.
Embedding
A numerical representation of a text that captures its meaning, so that similar texts have nearby representations. It is the mechanism that allows searching by sense instead of by exact words.
Vector database
A store specialised in holding embeddings and quickly finding the ones closest to a question. It is the warehouse a RAG system rests on.
Hallucination
A plausible but false answer produced by a language model. It is reduced by anchoring answers to verifiable documents and showing the source; it is not eliminated, which is why every output should be treated as a suggestion.
Computer vision
The set of techniques that let a system recognise objects, people or conditions in images and video. In our own projects we use it to recognise litter in beach imagery collected in the field.
Anomaly detection
Automatic identification of values that depart from the normal behaviour of a data series. On an environmental sensor it is what distinguishes a failing probe from a real event.
MLOps
The set of practices for putting machine learning models into production and keeping them there: versioning, monitoring performance over time, retraining. It is the part that decides whether a model is still useful after six months.
TRL (Technology Readiness Level)
A scale from 1 to 9 used by European programmes to measure the maturity of a technology. TRL 6 means a prototype demonstrated in a relevant environment: it works in the field, it is not yet a product.
LLMOps
The practices that keep an application built on language models running: versions, prompts and configurations, quality monitoring, compute-cost control, security and updates. It is to a language model what MLOps is to a machine learning model, with one practical difference: here the supplier underneath changes too, and it changes without warning.
Knowledge base
An organised store of documents, procedures and know-how that can feed internal search, a support service or an AI system with verifiable sources. Building it is the easy part: the hard part is keeping it current, because an old knowledge base gives confident answers about how things worked two years ago.
Data curation
Selecting, cleaning, classifying, organising and maintaining data so that it is fit for reliable use. It is usually the least interesting line in the budget of an AI project, and the one that determines its outcome.
Synthetic dataset
Data generated artificially to reproduce useful characteristics of real data, typically where the real data is confidential or insufficient. It still has to be assessed for quality, privacy and re-identification risk: synthetic does not automatically mean anonymous.
Human-in-the-loop
A design in which a person reviews, validates or can correct the output of an AI system before it produces a relevant effect. There is only one test of whether it is real rather than nominal: the reviewer has the information, the time and the authority to say no.
Algorithmic auditing
A structured review of the quality, robustness, traceability, limitations and possible bias of an algorithmic or AI system. It supports technical and organisational governance; it is not a legal certification unless a specific engagement expressly says so.
Connected operations
IoT (Internet of Things)
A network of connected devices and sensors that collect, transmit or receive data from environments, assets and processes. The interesting question is almost never which sensor: it is what happens to the data after it arrives, and who acts on it.
Traceability
The ability to follow and reconstruct the path of an asset, an event, a document or an operation through consistent data and records. It is what turns “we think that is what happened” into “at 14:32, with this card”.
Predictive maintenance
Using historical and field data to estimate anomalies or the need for intervention before a significant failure or degradation. It does not eliminate failures: it changes which failures take you by surprise. Its effectiveness depends on data quality, continuity and coverage before it depends on the model.
Digital twin
A digital representation of an asset, a process or an environment, used to observe its condition, simulate scenarios and support decisions. It is worth exactly as much as the telemetry feeding it.
Environment and measurement
WQI (Water Quality Index)
A composite index that summarises several chemical and physical parameters in a single number from 0 to 100. Its job is to make communicable to anyone a state that would otherwise require reading twenty separate values.
Turbidity
A measure of how far suspended particulate makes water opaque. It is one of the most informative parameters because it reacts quickly to discharges, heavy rain and disturbance of the seabed.
COD and BOD
Chemical and biochemical oxygen demand: they measure how much organic matter is in the water. They are the central parameters for monitoring treatment-plant discharges and normally require laboratory analysis.
Life cycle assessment (LCA)
A method for calculating the environmental impact of a product or service across its whole life, from raw material extraction to disposal. It is the basis of environmental product declarations.
EPD (environmental product declaration)
A document verified by a third party stating the environmental impact of a product on the basis of a life cycle assessment. It is becoming a requirement in public tenders and in supplying large buyers.
Green IT
A technology approach that accounts for the efficiency of infrastructure, software, devices and the digital lifecycle in order to limit waste and impact. It is about the boring decisions — how many years a device stays in service, how oversized a platform is, how many copies of an archive really exist — more than the visible ones.
Società Benefit (Italian benefit corporation)
A company form introduced in Italy by Article 1(376)–(384) of Law No. 208/2015: alongside profit, the company pursues common-benefit purposes written into its articles of association, appoints an impact officer and publishes an impact report every year. It is not a certification: it is a binding commitment written into the articles of association.
Missing a term? Tell us and we will add it.

