<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=7847562&amp;fmt=gif">
Home > Platform

What is physical access governance?

Physical access governance is the practice of managing physical access rights, such as keys and lock permissions, through the same identity-driven controls that govern digital access: rights derived from roles, granted through policy and approval, revoked automatically when identities change, and recorded in an audit trail. It closes the gap between identity and access management (IAM) systems, which govern who someone is and what they may do, and physical locking systems, which control which doors actually open. In short: your IAM decides, your locks enforce, and governance is the connected, auditable flow between the two.

Request a demo

Why the category exists

For decades, digital and physical access grew up as separate worlds with separate owners. IT built identity governance: joiner-mover-leaver processes, role models, approval workflows, recertification, audit trails. Facilities managed keys: issue registers, key cabinets, deposit forms, and a great deal of institutional memory.

That separation was tolerable when keys were purely mechanical and expectations were low. Three developments ended it:

  1. Digital locking systems matured. Technologies like iLOQ and ASSA ABLOY CLIQ made key rights programmable, which means they can be governed, if something feeds them the right decisions.
  2. Regulation caught up. The EU's NIS2 Directive requires appropriate policies for access to premises, and the CER Directive requires critical entities to secure their physical infrastructure. Physical access moved from a facilities detail to a board-level compliance topic.
  3. The threat model converged. Whoever enters a server room, switch room or relay house physically can compromise the digital systems inside. Separating the two governance worlds stopped making security sense.

Physical access governance is the discipline that reunites them.

What physical access governance consists of

In practice this is implemented as middleware, such as Key2XS, sitting between the IAM system and the locking system, translating identity decisions into key rights in near real-time.

How it differs from adjacent categories

Category What it does What it does not do
Key management software Registers which keys exist and who holds them Does not connect to identity: issuance and revocation remain manual decisions
Electronic access control (badges, PACS) Controls wired doors with badge readers, often in buildings Does not cover the key-operated estate: dispersed sites, cylinders, padlocks, technical spaces
IAM / identity governance Governs digital identities, roles and application access Stops at the digital boundary: no connection to physical keys
Physical access governance Applies IAM governance to key-based physical access Does not replace any of the above: it connects the IAM to the locking system

The categories are complementary. Most critical entities run all of them, and physical access governance is the layer that makes the key-operated part of the estate as governable as the badge-operated and digital parts.

Who needs it

Physical access governance matters most where physical access affects safety, continuity or compliance:

The common trigger is regulatory: organizations in scope of NIS2 or CER discover that their digital governance is mature while their physical access is still administered by hand, and that auditors have started asking about both.

A maturity model for physical access

  1. Stage 1: The register. Keys are tracked in a spreadsheet or paper register. Accuracy depends on discipline and decays continuously. Audits are reconstructions.
  2. Stage 2: Key management software. A dedicated system tracks keys and holders. The registration is better, but every grant and revocation is still a manual decision, disconnected from the identity lifecycle.
  3. Stage 3: Programmable locks. Digital locking (iLOQ, CLIQ) makes rights changeable without physical key retrieval. Revocation becomes possible in minutes, but someone still has to remember to do it.
  4. Stage 4: Governed. Middleware connects the IAM to the locking system. Rights derive from roles, lifecycle events propagate automatically, and the audit trail is produced as a byproduct of normal operation. Nobody has to remember anything.

Most organizations that feel physical access pain are at stage 2 or 3: they own capable systems on both sides and lack only the connection between them.

A buyer's checklist

When evaluating a physical access governance solution, ask:

  1. Does it connect to the IAM system we already run, with pre-built, maintained connectors?
  2. Does it work with our existing locking system without replacing locks, keys or the locking plan?
  3. How fast do lifecycle events propagate, and is revocation near real-time?
  4. Is the audit trail tamper-evident and does it link every right to an identity and a decision?
  5. Are the integrations certified by the vendors on both sides?
  6. What is the realistic implementation time, and does it require custom development?
  7. Does it handle external populations, such as contractors and agency staff, with automatic end dates?

Key2XS answers these by design: certified integrations on both sides (SailPoint Technology Alliance Partner, certified by ASSA ABLOY), pre-built connectors for SailPoint, Entra ID, Okta, One Identity and OpenText and for iLOQ and the ASSA ABLOY CLIQ ecosystem, near real-time propagation, a tamper-evident audit trail, and standard integrations live in under two hours.

Frequently asked questions

Physical access governance, defined and explained.

See physical access governance in practice

Get a guided walkthrough of how identity, policy and physical keys come together in one auditable flow.