Identity-driven provisioning
Access rights derive from who someone is and which roles they hold in the IAM system, not from who happened to ask at the desk.
Physical access governance extends identity governance to the keys and locks that protect physical assets: substations, pumping stations, cabinets, depots. Rights derive from the identity, pass through the same approvals and lifecycle as digital access, and produce the same evidence.
On cylinders, padlocks, cabinets and gates, including fully offline sites.
Manage physical keys and lock permissions through identity-driven controls: rights derived from roles, revoked with the identity lifecycle, evidenced automatically.
For decades, digital and physical access grew up as separate worlds with separate owners. IT built identity governance: joiner, mover and leaver processes, role models, approval workflows, recertification, audit trails. Facilities managed keys: issue registers, key cabinets, deposit forms, and a great deal of institutional memory.
That separation was tolerable while keys were purely mechanical and expectations were low. Three developments ended it.
A lock authenticates a key. A reader authenticates a badge. Both answer one question: is this credential valid at this door, right now? Neither knows whether the person holding it should still have it.
Governance answers the questions that come before and after. Access control enforces. Governance decides and evidences. An organisation can have excellent locks and no governance at all, and most do.
The lock is right. Anna's key is valid. Nobody has asked whether it should be.
Four capabilities, implemented as middleware between the IAM system and the locking system, translating identity decisions into access rights in near real time.
Access rights derive from who someone is and which roles they hold in the IAM system, not from who happened to ask at the desk.
Which role opens which doors is defined once, as policy. Exceptions pass through approval instead of around it, in your own IGA.
Joiners receive access with their role, movers lose the old and gain the new, and leavers lose everything in the same movement that disables their accounts. Contract end dates end physical access too.
Every grant, change and revocation is logged, tamper-evident, and traceable to an identity and a decision, so compliance questions are answered from the system.
A person has one identity. Their digital access is derived from it: role, department, contract dates, lifecycle state. Their physical access should be derived from the same identity, not from a second record kept by facilities, a key register, or a badge system with its own copy of who works here.
When the identity changes, both worlds should change in the same movement. A contract that ends on Friday ends the VPN and the substation key on Friday.
The categories are complementary. Most critical entities run several of them. Physical access governance is the layer that makes the key-operated estate as governable as the badge-operated and digital parts. Hover a row.
Hover a category to see what it does and where it stops.
PIAM was built for the badge estate: office buildings, wired doors, a reader on every entrance. It does that well, and physical access governance connects to it. Two things sit outside its reach.
The estate is the wrong shape. A utility's risk lives in substations, cabinets and pumping stations, thousands of sites with no reader and no network, where a key is the entire security model.
The decision has to come from one place. Physical access governance does not keep its own copy of the identity. It makes the IAM the source of every decision and treats the lock as one more system that carries it out.
Most operational sites are offline by design. Keys and cylinders stay disconnected for resilience, and governance has to work there anyway. With programmable keys, it does.
Rights travel with the key and are refreshed when the key is used. Revocation is therefore near real time, not instantaneous: the window is closed by periodic blacklist checks the customer configures, and a shorter interval costs battery. The audit trail is collected when keys and cylinders sync. The site never needs connectivity.
A role changes, a contract ends, an approval lands in the IGA. The right is granted or withdrawn in the control plane.
The next time the key is used it picks up its updated rights. Revocation propagates the same way, and through a scheduled blacklist check.
The cylinder never needs a network. It checks the rights the key presents, and the blacklist it holds, and opens or refuses.
Every open, refusal and update is collected when keys and cylinders sync, and linked to the identity and the decision that caused it.
A design choice the customer makes per estate, not a limitation to hide.
Physical access governance matters most where physical access affects safety, continuity or compliance. The common trigger is regulatory: organisations in scope of NIS2 or CER discover that their digital governance is mature while their physical access is still administered by hand, and that auditors have started asking about both.
Most critical entities today run mature identity governance on the digital side and capable locking technology on the physical side. What is missing is the connection between them: the point where an identity decision becomes an access right, automatically and with evidence. That is the governance gap, and it is narrower than most organisations think.
Pick the stage that looks like yours.
Stage 1. The register is only as good as the discipline behind it, and discipline decays continuously.
Stage 2. Better registration, same decisions. Every grant and revocation still originates outside the identity lifecycle. Most organisations are here or at stage 3.
Stage 3. Capable systems on both sides, and nothing connecting them. This is the governance gap, and it is one integration wide.
Stage 4. Governed. Nobody has to remember anything.
Over the last decade the IAM system became the control plane for digital access: one place where lifecycle, policy, certification and audit are defined, and every application is an enforcement point. Physical access is the last domain still outside it.
Physical access governance extends the control plane. The same joiner, mover and leaver events, the same approval flows, the same recertification campaigns and the same audit trail now reach the substation door. The lock becomes what an application already is: something that enforces a decision it did not make. Approvals stay in your IGA. No decision originates anywhere else.
Who may hold access is derived from the identity in the IAM you already run.
The same approvals, segregation rules and certification cycles that govern digital access.
Keys and cylinders carry out what was decided. They enforce. They never decide.
KuppingerCole Analysts, Rising Star report on Key2XS, September 2026“Physical Access Governance extends identity governance to the offline, mechanical, and electronic key systems protecting critical field assets such as substations, pumping stations, and bridges.”
“Physical Access Governance is likely to grow steadily in the next two to three years, tracking the pace at which the CER Directive and NIS2 are transposed into national law and enforced.”
Market segment: Physical Access Governance
Read the analyst recognitionWhen evaluating a physical access governance solution, ask these. Tick what a vendor can show you, not what they tell you.
Key2XS answers these by design: certified integrations on both sides, pre-built connectors for SailPoint, Entra ID, Okta, One Identity and OpenText and for iLOQ and the ASSA ABLOY CLIQ ecosystem, approvals that stay in your IGA, near real-time propagation with configurable blacklist checks, a tamper-evident audit trail, and standard integrations live in under two hours.
Physical access governance, defined and explained.
Managing physical keys and lock permissions through identity-driven controls: rights derived from roles, revoked automatically with the identity lifecycle, and evidenced in an audit trail linked to the identity.
Access control enforces access at the door, whether by badge, key or code. Governance decides and proves who should have that access in the first place, based on identity, role and policy, and withdraws it when the reason ends.
PIAM manages badge holders for reader-controlled doors and keeps its own identity records, synchronised from HR or IAM. Physical access governance connects to PIAM and to the IAM, makes the IAM the source of every physical right, and reaches the key-operated, offline estate that badges never covered.
Yes. Rights travel with programmable keys and are refreshed when the key is used. Revocation is enforced at the next use and by periodic blacklist checks, and the audit trail is collected when keys and cylinders sync. The site needs no connectivity.
Both directives require governed, demonstrable control over physical access to premises and infrastructure. Neither prescribes a specific technology, but manual key administration cannot produce the evidence they ask for.
No. Physical access governance is a middleware layer. It connects the IAM system and the digital locking system you already run.
Key2XS is a physical access governance platform: a governance control plane connecting IAM systems (SailPoint, Microsoft Entra ID, Okta, One Identity, OpenText) to electronic key systems (iLOQ, ASSA ABLOY CLIQ), vendor-neutral in any combination.
A 30-minute walkthrough of how identity, policy and physical access come together in one auditable system.