Category definition

What is physical access governance?

Physical access governance extends identity governance to the keys and locks that protect physical assets: substations, pumping stations, cabinets, depots. Rights derive from the identity, pass through the same approvals and lifecycle as digital access, and produce the same evidence.

12 min readUpdated July 2026
In one sentence

Manage physical keys and lock permissions through identity-driven controls: rights derived from roles, revoked with the identity lifecycle, evidenced automatically.

Why the category exists
Origins

Why the category exists

For decades, digital and physical access grew up as separate worlds with separate owners. IT built identity governance: joiner, mover and leaver processes, role models, approval workflows, recertification, audit trails. Facilities managed keys: issue registers, key cabinets, deposit forms, and a great deal of institutional memory.

That separation was tolerable while keys were purely mechanical and expectations were low. Three developments ended it.

IT: identity governance Facilities: key management
Locks became programmable
iLOQ, ASSA ABLOY CLIQ: access rights that can be governed
Regulation caught up
NIS2 and CER in force, October 2024
The threat model converged
Whoever enters the switch room owns the systems inside
Physical access governance
Physical access governance is the discipline that reunites the two worlds.
The distinction

Authentication is not governance

A lock authenticates a key. A reader authenticates a badge. Both answer one question: is this credential valid at this door, right now? Neither knows whether the person holding it should still have it.

Governance answers the questions that come before and after. Access control enforces. Governance decides and evidences. An organisation can have excellent locks and no governance at all, and most do.

CYLINDER KEY Anna, contractor Valid at this door, now.
  • 1
    Is this key valid at this door, right now?The only question a cylinder can answer.
  • 2
    Should this person hold this right?Derived from role, contract and lifecycle state.
  • 3
    Who approved it, against which policy?Recorded in the same IGA that approves digital access.
  • 4
    When does it end?With the contract, the role change, or the leaver event.
  • 5
    Can we prove all of it later?Every grant, change and revocation, traceable to an identity.

The lock is right. Anna's key is valid. Nobody has asked whether it should be.

Anatomy

What physical access governance consists of

Four capabilities, implemented as middleware between the IAM system and the locking system, translating identity decisions into access rights in near real time.

Identity-driven provisioning

Access rights derive from who someone is and which roles they hold in the IAM system, not from who happened to ask at the desk.

Policy and approval

Which role opens which doors is defined once, as policy. Exceptions pass through approval instead of around it, in your own IGA.

Lifecycle enforcement

Joiners receive access with their role, movers lose the old and gain the new, and leavers lose everything in the same movement that disables their accounts. Contract end dates end physical access too.

Audit and evidence

Every grant, change and revocation is logged, tamper-evident, and traceable to an identity and a decision, so compliance questions are answered from the system.

The principle

One identity, two worlds

A person has one identity. Their digital access is derived from it: role, department, contract dates, lifecycle state. Their physical access should be derived from the same identity, not from a second record kept by facilities, a key register, or a badge system with its own copy of who works here.

When the identity changes, both worlds should change in the same movement. A contract that ends on Friday ends the VPN and the substation key on Friday.

DIGITAL ACCESS PHYSICAL ACCESS VPNActiveEmail and filesActiveSCADA consoleActive Substation 12ActiveCabinet 4, tracksideActiveDepot gateActive Anna de Vries Contractor, field maintenance Contract active
One event. Six revocations. Same movement.
Adjacent categories

How it differs

The categories are complementary. Most critical entities run several of them. Physical access governance is the layer that makes the key-operated estate as governable as the badge-operated and digital parts. Hover a row.

Category
Digital applications
Badge-controlled doors
Key-operated sites, offline
IAM / identity governance
Governs
No reach
No reach
Electronic access control (PACS)
No reach
Enforces
No reach
PIAM (physical identity and access management)
Syncs from
Governs
No reach
Key management software
No reach
No reach
Registers
Physical access governance
Connects to
Connects to
Governs

Hover a category to see what it does and where it stops.

Governs or enforcesPartial: registers or syncsConnects toNo reach
The badge estate and the rest

Where PIAM stops

PIAM was built for the badge estate: office buildings, wired doors, a reader on every entrance. It does that well, and physical access governance connects to it. Two things sit outside its reach.

The estate is the wrong shape. A utility's risk lives in substations, cabinets and pumping stations, thousands of sites with no reader and no network, where a key is the entire security model.

The decision has to come from one place. Physical access governance does not keep its own copy of the identity. It makes the IAM the source of every decision and treats the lock as one more system that carries it out.

IAM / IGAone identity
PIAM: reader-controlled estate
Head office, depots, control rooms
Physical access governance
connects to
Substations, cabinets, pumping stations
no reader, no network, a key
PIAM covers the circle. Physical access governance connects to it, and reaches the sites outside it from the same identity.
Mechanics

Offline assets

Most operational sites are offline by design. Keys and cylinders stay disconnected for resilience, and governance has to work there anyway. With programmable keys, it does.

Rights travel with the key and are refreshed when the key is used. Revocation is therefore near real time, not instantaneous: the window is closed by periodic blacklist checks the customer configures, and a shorter interval costs battery. The audit trail is collected when keys and cylinders sync. The site never needs connectivity.

1Control plane, online

The decision

A role changes, a contract ends, an approval lands in the IGA. The right is granted or withdrawn in the control plane.

2Key, on use

The key carries it

The next time the key is used it picks up its updated rights. Revocation propagates the same way, and through a scheduled blacklist check.

3Cylinder, offline

The lock enforces it

The cylinder never needs a network. It checks the rights the key presents, and the blacklist it holds, and opens or refuses.

4Control plane, on sync

Evidence comes back

Every open, refusal and update is collected when keys and cylinders sync, and linked to the identity and the decision that caused it.

More oftenLess often

A design choice the customer makes per estate, not a limitation to hide.

Exposure window after a revocation
Battery life of the key
Industries

Who needs it

Physical access governance matters most where physical access affects safety, continuity or compliance. The common trigger is regulatory: organisations in scope of NIS2 or CER discover that their digital governance is mature while their physical access is still administered by hand, and that auditors have started asking about both.

Self-assessment

The governance gap

Most critical entities today run mature identity governance on the digital side and capable locking technology on the physical side. What is missing is the connection between them: the point where an identity decision becomes an access right, automatically and with evidence. That is the governance gap, and it is narrower than most organisations think.

Pick the stage that looks like yours.

Joiner
Mover
Leaver
Audit

Stage 1. The register is only as good as the discipline behind it, and discipline decays continuously.

Stage 2. Better registration, same decisions. Every grant and revocation still originates outside the identity lifecycle. Most organisations are here or at stage 3.

Stage 3. Capable systems on both sides, and nothing connecting them. This is the governance gap, and it is one integration wide.

Stage 4. Governed. Nobody has to remember anything.

The thesis

The identity control plane

Over the last decade the IAM system became the control plane for digital access: one place where lifecycle, policy, certification and audit are defined, and every application is an enforcement point. Physical access is the last domain still outside it.

Physical access governance extends the control plane. The same joiner, mover and leaver events, the same approval flows, the same recertification campaigns and the same audit trail now reach the substation door. The lock becomes what an application already is: something that enforces a decision it did not make. Approvals stay in your IGA. No decision originates anywhere else.

Identity control plane: lifecycle, policy, certification, audit SaaS apps enforcement point VPN and network enforcement point SCADA and OT enforcement point Cylinders and padlocks enforcement point Cabinets and gates enforcement point Offline sites via the key

Identity decides.

Who may hold access is derived from the identity in the IAM you already run.

Policy governs.

The same approvals, segregation rules and certification cycles that govern digital access.

Technology executes.

Keys and cylinders carry out what was decided. They enforce. They never decide.

Evaluation

A buyer's checklist

When evaluating a physical access governance solution, ask these. Tick what a vendor can show you, not what they tell you.

0 of 8 shown

Key2XS answers these by design: certified integrations on both sides, pre-built connectors for SailPoint, Entra ID, Okta, One Identity and OpenText and for iLOQ and the ASSA ABLOY CLIQ ecosystem, approvals that stay in your IGA, near real-time propagation with configurable blacklist checks, a tamper-evident audit trail, and standard integrations live in under two hours.

Frequently asked questions

Physical access governance, defined and explained.

See physical access governance in practice

A 30-minute walkthrough of how identity, policy and physical access come together in one auditable system.