For decades, digital and physical access grew up as separate worlds with separate owners. IT built identity governance: joiner-mover-leaver processes, role models, approval workflows, recertification, audit trails. Facilities managed keys: issue registers, key cabinets, deposit forms, and a great deal of institutional memory.
That separation was tolerable when keys were purely mechanical and expectations were low. Three developments ended it:
Physical access governance is the discipline that reunites them.
In practice this is implemented as middleware, such as Key2XS, sitting between the IAM system and the locking system, translating identity decisions into key rights in near real-time.
| Category | What it does | What it does not do |
|---|---|---|
| Key management software | Registers which keys exist and who holds them | Does not connect to identity: issuance and revocation remain manual decisions |
| Electronic access control (badges, PACS) | Controls wired doors with badge readers, often in buildings | Does not cover the key-operated estate: dispersed sites, cylinders, padlocks, technical spaces |
| IAM / identity governance | Governs digital identities, roles and application access | Stops at the digital boundary: no connection to physical keys |
| Physical access governance | Applies IAM governance to key-based physical access | Does not replace any of the above: it connects the IAM to the locking system |
The categories are complementary. Most critical entities run all of them, and physical access governance is the layer that makes the key-operated part of the estate as governable as the badge-operated and digital parts.
Physical access governance matters most where physical access affects safety, continuity or compliance:
The common trigger is regulatory: organizations in scope of NIS2 or CER discover that their digital governance is mature while their physical access is still administered by hand, and that auditors have started asking about both.
Most organizations that feel physical access pain are at stage 2 or 3: they own capable systems on both sides and lack only the connection between them.
When evaluating a physical access governance solution, ask:
Key2XS answers these by design: certified integrations on both sides (SailPoint Technology Alliance Partner, certified by ASSA ABLOY), pre-built connectors for SailPoint, Entra ID, Okta, One Identity and OpenText and for iLOQ and the ASSA ABLOY CLIQ ecosystem, near real-time propagation, a tamper-evident audit trail, and standard integrations live in under two hours.