Life safety and egress
This page is operator guidance, not legal advice and not a code substitute. An Authority Having Jurisdiction (AHJ), a fire-protection engineer, and counsel licensed where you operate must review the site. Codes are adopted locally. Buyer summary: Compliance. Binding rules: Terms of Service.
OpenApp grants and denies inbound cloud opens. It is not a lock manufacturer, not a listed access-control system (UL 294 / ULC-S319 / EN 13637), and not a fire-alarm control unit. Occupants must be able to exit without a phone, credential, app, or working internet.
Legal-use matrix (high level)
Section titled “Legal-use matrix (high level)”| Opening | OpenApp may |
|---|---|
| Vehicle gate with listed operator + photo-eyes; separate pedestrian exit | Pulse / schedule inbound. Entrapment stays on the operator listing. |
| Unit, hotel guest, or house door: mechanical inside always retracts the latch; OpenApp pulses the outside | Yes |
| Office or lobby: listed panic or lever inside + electric strike inbound | Yes |
| Maglock or motorized lock as the only hold on an egress leaf | No, unless a listed local special-locking system (not OpenApp) provides fire-alarm, power-fail, and local emergency-door release, and OpenApp cannot disable that lock |
| Fire-resistance-rated door | Do not hold-open via OpenApp; do not add unlisted hardware to the labeled assembly |
| Stair re-entry / elevator lobby special locking | Do not command these locks |
| Healthcare delayed / controlled egress | Out of scope |
| Locker / parcel compartment | Yes (not_applicable) |
Sectors that fit this envelope when classified door-by-door: private home, short-term rental, hotel guest rooms, apartment unit doors, parking gates with independent pedestrian egress. Office corridors, schools, hotel stairs, and campuses need a class on every leaf; many must not be electrically locked via OpenApp.
Opening classes
Section titled “Opening classes”Set life_safety_class on each virtual-access portal and on any standalone switchable device (Tasmota, MQTT relay, and similar) that is not listed as an opener of a portal. Dashboard door form, device form, and setup wizard. New access doors default to ingress only in the UI. Production open and toggle require class plus complete commissioning attestation (except not_applicable on lights and lockers). A door entity cannot use not_applicable. The entity page and device entities table keep Open and Toggle visible but disabled, with a tooltip and a Device settings link to classify and attest.
| Class | Meaning |
|---|---|
not_applicable | Light, locker, or other non-door |
ingress_only | Inbound grant only; independent exit exists |
vehicle_gate | Vehicle barrier; pedestrian escape is a separate listed opening |
means_of_egress | Leaf is (or may be) a required exit |
fire_door_assembly | Fire-resistance-rated doorset |
special_locking_listed_local | You attest a listed local controller / kit exists outside OpenApp |
Commissioning attestation
Section titled “Commissioning attestation”Before production opens on access classes, record:
- Independent mechanical exit, listed panic/lever, or hardwired request-to-exit was tested (OpenApp has no REX action)
- Power-fail behavior (
fail_safe,fail_secure, ormechanical_always— hardware sense) - Fire-door listing not altered (required for fire-door class)
- Vehicle-gate entrapment protection present (required for vehicle gates)
- OpenApp is not the fire-alarm interface
- Named installer
The server stamps who attested and when. Each save that stores attestation writes an audit event with the installer name you typed, the signed checkboxes, and the OpenApp user who saved. Dashboard save requires a complete attestation for access classes.
Prohibited configurations
Section titled “Prohibited configurations”- OpenApp as the sole electric lock on a means of egress or fire-door assembly
hold_closedorhold_openonmeans_of_egressorfire_door_assembly- PalGate hardware disable (
outputNDisabled) except on classifiedingress_onlyorvehicle_gate - Emergency lockdown as a building lock-in (it only denies inbound cloud credentials; it does not apply to egress or fire-door classes)
- Marketing or operating OpenApp as fire unlock, FACP door release, or UL / EN / NFPA certified
- Requiring a phone or the cloud to exit. OpenApp has no request-to-exit (REX) command; REX must be hardwired locally.
Emergency free egress only stops OpenApp from denying inbound opens. It is not fire-alarm release.
Hardware fail-safe (lock releases on power loss) is an installer choice. Stewardship that suspends device policies when an admin probe fails is not hardware fail-safe.
See Choosing access control architecture and Fallback, networks, and parallel path security.