A purely card-based, on-site process breaks down when organisations need to adjust for remote work, fluctuating occupancy, and reduced front-desk interaction. It slows issuance, revocation, and policy changes, and it makes it harder to respond to temporary use cases such as contractors or reopened shared spaces. The result is weaker operational agility and less consistent access governance.
Where a card-only process stops fitting the operating model
A card-centric access process assumes people are physically present, change requests are handled at a front desk, and access decisions can wait for manual workflow. That model becomes brittle once organisations need to support remote employees, hybrid occupancy, contractors, or short-lived access changes. The control problem is no longer just issuing a badge, it is keeping access aligned to who should enter, when, and under what conditions.
When the process stays tied to on-site administration, the access model drifts away from the actual operating model. A desk-based workflow can work for stable office populations, but it does not scale well to frequent onboarding, temporary visitors, location-based exceptions, or rapid revocation when a role changes. The gap is operational as much as physical, because access governance depends on timely decisions as much as on the badge itself.
That mismatch is why card-only governance often becomes a bottleneck. It creates delay in issuance and changes, encourages exception handling outside the formal process, and leaves teams with less reliable visibility into who can enter which space. A modern access model needs to support the same policy logic across permanent staff, contractors, and changing workplace patterns, rather than assuming every request can be resolved in person.
What breaks in issuance, revocation, and exception handling
The first failure point is lifecycle speed. If every change depends on an on-site handoff, credentials and access rights lag behind the business event that triggered them. That matters when someone starts remotely, moves teams, leaves the company, or needs temporary access to a reopened shared area. Delays turn a simple process into a queue, and queues are where access governance loses precision.
The second failure point is revocation discipline. Card-based processes are often strongest at initial issuance and weakest at rapid removal or adjustment. If the organisation still relies on physical presence, revoking access for a contractor, recovering from a lost card, or changing a temporary entitlement can require coordination that is too slow for the actual risk window. The longer the lag, the more likely access remains valid after it should have expired.
The third failure point is exception handling. Shared desks, hybrid schedules, and temporary projects generate cases that do not fit a fixed front-desk routine. When the process cannot absorb those exceptions cleanly, teams improvise, which usually means inconsistent approvals, undocumented workarounds, or local admin discretion. Over time, those workarounds become the real access model, even if the policy still describes something more controlled.
Why access governance becomes inconsistent at scale
Card-based administration is a poor fit for environments where access decisions need to be reviewed, re-scoped, or time-bounded across many people and locations. Consistency depends on whether the process can express policy clearly and execute it quickly. If that cannot happen, organisations end up with different treatment for permanent staff, contractors, and temporary users, which weakens governance even when no single control has technically failed.
The practical issue is not only convenience. Access governance requires the ability to answer basic questions reliably: who is allowed in, for how long, under what conditions, and who approved it. A purely on-site model makes those answers harder to maintain because the process is anchored to physical presence rather than administrative control. That creates friction for remote work and makes it harder to align workplace access with identity and role changes.
For teams running mixed office and remote operations, the better model is one that separates policy from location. The access rule should be able to follow the person, the project, or the time window, rather than depending on whether someone can visit a reception desk. Physical cards may still be part of the solution, but they should not be the mechanism that determines whether the access model is agile or governable.
Risk and Threat Considerations
A card-only process increases exposure when access changes are slow, manually handled, or easy to bypass through informal exceptions. The most common risk is not dramatic compromise, but stale access that persists longer than the business justification, especially for contractors, leavers, and temporary workspace arrangements.
Failure mechanism: Manual, on-site workflows create revocation lag, exception sprawl, and inconsistent approval paths, which weakens the organisation’s ability to keep access aligned to current need.
Impact: Stale or over-broad access can remain in place after a role change or engagement ends, increasing the chance of unauthorised entry, policy drift, and audit findings.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access issuance and revocation timing are central to the problem. |
| AC-6 — Least Privilege | Card-only processes often leave overly broad or stale access in place. | |
| Recommendation — Automate account and access lifecycle changes to reduce delay in granting and removing access. Limit access rights to the minimum required and time-bound exceptions tightly. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about whether access control remains governable under changed operating conditions. |
| A.5.16 — Identity management | Identity changes and role shifts drive the need for faster, better-governed access updates. | |
| Recommendation — Define access control rules that stay effective across remote, temporary, and hybrid use cases. Keep identity records and access assignments synchronized with current working arrangements. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The issue is operational access governance, including provisioning and revocation. |
| Recommendation — Centralise and standardise access provisioning, review, and revocation workflows. | ||
Practitioner Guidance
What to prioritise: Treat the access process as a governance workflow first and a badge workflow second. If changes cannot be issued, updated, or removed without a physical visit, the process is already too slow for hybrid operations.
What to verify: Check whether temporary access, contractor onboarding, and revocation can be completed within the time window your policy requires. If the formal process cannot meet that window, local workarounds are likely carrying hidden access risk.
Practitioner takeaway: The right test is not whether cards still work, but whether the access model can keep pace with how the organisation actually operates.
Related resources from NHI Mgmt Group
- What breaks when cloud access is still managed with proxy-based privileged access tools?
- What is the difference between role-based access and API key governance for NHI security?
- What breaks when agent access is managed in a separate governance process?
- What breaks when push-based MFA is the main control for privileged access?