Join our Newsletter — 33% off our NHI Course

How should IAM teams govern physical access across multiple sites?

IAM teams should treat physical access as part of the identity lifecycle, with central visibility, ownership and recertification across every facility. The key is to reconcile badge data with HR and role records, then review exceptions where access has been copied or inherited.

Why Physical Access Belongs in IAM Governance

Physical access becomes an identity problem as soon as badges, visitor credentials or facility entitlements determine who can enter a site and under what conditions. For multi-site organisations, the governance question is not just “who has a badge”, but whether every location is enforcing the same ownership, approval and review model, with a clean join between HR status, role assignment and facility access.

That makes physical access part of the same control plane as digital access. When a person changes role, leaves the company, transfers sites, or inherits access through a group move, the identity record should drive the facility entitlement outcome. Teams that treat each site as a separate local process usually lose consistency, which is why Identity Security Programme Guide is useful as a governance model for central ownership and shared decision-making.

At a practical level, the governing question is whether badge issuance, renewal and removal are tied to the same lifecycle discipline used for accounts and privileged access. If the answer is no, physical access often becomes a shadow entitlement: visible at the door, but not visible in the identity record, recertification workflow or exception process.

How to Run Multi-Site Access as One Lifecycle

Start by defining a single authority for policy, even if local facilities teams execute the mechanics. That authority should own the standards for request, approval, expiry, revocation and periodic review, so the sites do not drift into different practices for contractors, employees, visitors and shared spaces. Central ownership also makes it easier to compare badge data across locations and detect where entitlements have been copied or inherited without a fresh decision.

The control pattern is to reconcile three sources together: HR status, role or department records, and physical access grants. When those sources disagree, the mismatch deserves investigation before the access is assumed valid. This is especially important for moves between sites, because a person can legitimately need access to one facility but not another, even when the job title has not changed.

Lifecycle discipline works best when access is time-bound by default and exceptions are explicit. Temporary access for projects, vendors or short-term assignments should expire unless it is renewed through the same approval path. For teams building a broader access governance programme, lifecycle processes for managing identities provides a useful parallel for how provisioning, review and offboarding should operate as a repeatable process, not a one-off ticket.

Facilities data should also be structured enough to answer simple governance questions quickly: who has access, to which sites, at what level, and based on which approval. If that answer cannot be produced without manual email searches, the organisation cannot reliably prove least privilege or remove stale access.

What to Review, Exceptions to Chase, and Where Risk Accumulates

Multi-site environments accumulate risk when site-specific exceptions are left to local discretion. The common failure mode is inherited access, where membership in a regional group, inherited badge template or copied entitlement gives someone more physical access than their role justifies. Another is orphaned access after a transfer, exit or contract end, where the digital identity is updated but the badge remains active.

Review should therefore focus on exceptions first, not averages. Teams should look for duplicate badges, long-lived temporary access, cross-site access that no longer matches job function, and any facility privilege that cannot be traced back to a current owner. If the review process only validates active employees in a general sense, it will miss the highest-risk cases. The broader governance issue is the same one highlighted in Regulatory and Audit Perspectives: access must be reviewable, explainable and supported by evidence.

For organisations with many sites, the risk is not just unauthorized entry, but inconsistent enforcement. One location may revoke access promptly while another relies on badge expiry that is never checked, creating uneven control strength across the estate. That inconsistency is where audit findings, insider misuse and operational confusion tend to surface.

Risk and Threat Considerations

Physical access across multiple sites creates exposure when badge rights outlast the identity decision that justified them. The risk is strongest where local facilities teams can issue or extend access outside the central lifecycle, because copied, inherited or stale access can persist even after role changes, transfers or departures.

Failure mechanism: The control breaks when badge records, HR records and site-level exceptions drift apart, or when revocation depends on a local process that is not enforced consistently across facilities. That lets unauthorized or excessive access remain active without a clear owner to challenge it.

Impact: The result can be unauthorized site entry, insider misuse, poor auditability and a wider blast radius if one compromised or overprivileged identity can move across several locations unchecked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Badge and access lifecycle need controlled issuance, expiry, and revocation.
IA-2 — Identification and Authentication (Organizational Users) Multi-site physical access should tie entry rights to verified identity records.
AC-2 — Account Management Physical access needs provisioning, review, and removal governance across sites.
Recommendation — Enforce lifecycle rules for physical credentials and revoke stale access promptly. Bind facility access to verified identities before granting site entry rights. Review and remove facility access through a managed identity lifecycle process.
ISO/IEC 27001:2022 A.5.15 — Access control Physical access governance depends on formal access rules and consistent enforcement.
A.5.18 — Access rights Recertification and revocation are central to keeping badge rights aligned to need.
Recommendation — Define and enforce access rules for each site under one governance standard. Periodically recertify site access rights and remove any unneeded entitlement.
CIS Controls v8 CIS-5 — Account Management Multi-site badge governance depends on managing joiner-mover-leaver access changes.
Recommendation — Centralize joiner-mover-leaver updates so site access follows employment changes.
CSA Cloud Controls Matrix IAM — Identity and Access Management Cloud and enterprise IAM governance principles map directly to facility access control.
Recommendation — Apply IAM governance to physical access ownership, review, and revocation.

Practitioner Guidance

What to verify: Confirm that every site’s physical access list can be reconciled to a current identity record, a current business justification and a named approver. If you cannot produce that evidence quickly, the governance model is too fragmented to trust.

Decision rule: If access was copied, inherited or granted as a temporary exception, treat it as untrusted until it has been reapproved against the current role and site need. Do not wait for an annual review to catch a bad entitlement that is already operational.

What practitioners underestimate: The hard part is not issuing badges, but keeping the access model consistent as people move between sites, teams and employment states. Multi-site governance succeeds when revocation and recertification are designed as routine operations, not exceptional cleanup.

Practitioner takeaway: The safest model is a single identity-led approval and review process with local execution, because that is what prevents site-by-site drift from becoming permanent access debt.