Fail safe hardware unlocks when power is lost. Fail secure hardware stays locked when power is lost. Those two sentences are the whole vocabulary lesson — and almost none of the decision. The decision is about what should happen at one specific opening during the worst ten minutes of that building's year, and it is the single most common thing an electrified hardware line on a schedule fails to justify.
The terms describe one thing only: the locked state of the hardware when its power supply drops.
| Power ON | Power LOST | |
|---|---|---|
| Fail safe | Locked (energized to stay locked) | Unlocked |
| Fail secure | Unlocked only when signaled | Locked |
Fail safe lets people through when the lights go out — into shelter, into a stairwell, back into a floor. It also lets anyone through every time power flickers.
Fail secure keeps the opening protected during an outage. It also keeps out the people who may urgently need to get in — or keeps occupants from re-entering the building they just evacuated.
Same door. Opposite defaults. Both are routinely specified, and both are correct — for different contexts.
Part of the confusion is that the choice doesn't exist uniformly across product families:
That last point deserves its own sentence, because it is the most common misreading in the field: fail safe vs fail secure is about entry, not egress. Life-safety codes require free egress from the inside regardless of mode. A fail secure lock on an exit door does not trap anyone inside; the panic hardware or lever always works from the egress side. The mode only governs whether someone outside the door can get through it when power is gone.
The classic driver is re-entry. High-rise codes commonly require that occupants who enter a stairwell during an emergency can leave it again — onto a floor, not just at the ground level — so stairwell doors with electrified trim are typically fail safe: alarm or power loss unlocks them from the stair side. A stairwell full of smoke with locked doors on every level is the scenario the requirement exists to prevent.
The second driver is shelter. Doors where people outside may need to get in during an emergency — lobby entries in severe-weather regions, campus buildings that serve as refuge points — get specified fail safe so a power outage doesn't strand people outside.
The cost of fail safe is that security disappears exactly when the building is most chaotic. Every brownout is an unlocked door.
Almost everywhere the concern is what a power outage would otherwise open. Perimeter doors, stockrooms, server rooms, pharmacies, records rooms — anywhere an outage should not become an invitation. Fail secure is also the default answer where the owner's insurance or security policy assumes doors stay locked unattended.
The cost of fail secure is the mirror image: the person with a legitimate, urgent need to get in — a responder, a resident, an employee sheltering from weather — meets a locked door until someone restores power or arrives with a key. (Mechanical key override is not an optional nicety on fail secure openings; it is the contingency plan.)
Lori Greene posted a photo on iDigHardware that makes the point better than any paragraph: a panic device with fail safe lever trim — and a chain wrapped around the door. Her question: "Why is the lever trim fail safe? Why not fail secure?" The hardware was doing exactly what the schedule called for. Somebody in the field disagreed with the schedule strongly enough to reach for a chain.
In the comments, a contractor described a college dormitory whose lobby was specified fail secure — until a hurricane knocked out power during construction and students got locked out of an adjacent building. The team flipped the spec to fail safe so people could shelter. Two opposite specs on the same kind of door, both internally consistent, both wrong for the context that came next.
An internally consistent schedule line is not the same thing as a justified one. The mode arrives encoded as a suffix — a couple of characters in a seventeen-field part number — with no trace of why. Review processes that check "is this a valid, orderable configuration?" will pass a fail safe suffix that should have been fail secure every single time, because both are valid and both are orderable.
For every electrified opening on the schedule, the review question is not "is this configuration valid?" but "does the failure mode match the building's plan for this door?" Concretely:
Notice what kind of problem this is. Nobody bought bad hardware. The part number was valid, the configuration orderable, the installation correct. What failed was a piece of context — why this mode, at this door, in this building — that never traveled with the schedule line.
Most expensive Division 08 errors have this shape. The information existed at specification time, got compressed into a suffix, and the suffix outlived the reasoning. A senior estimator catches it by asking the same question Lori asked, reflexively, at every electrified opening. That reflex is exactly the kind of check that should run on every line of every schedule — which is what we build at Conversant: review that asks the expert's questions at estimating time, so the mismatch surfaces before fabrication instead of during the inspection walk, or worse, as a chain around a panic device.