Client confidentiality
I'm not naming the organisation, and I give no detail about the physical security configuration, site layout, credential scheme or access-control topology. Those are exactly the details that should not be public.
Where the engineering actually is
Not in the interface. It was in reconciling an access-control database designed for hardware with an employee directory designed for HR, and producing something coherent when the two disagree — which they do, constantly, because people join, leave, lose badges and get temporary credentials.