You get an incomplete picture of who can actually reach people, spaces, or assets. A recertification process that ignores badges and door permissions can certify a clean application profile while leaving the same person able to enter restricted facilities. The review looks effective, but the entitlement set is only half governed.
Why the Review Looks Complete but Isn’t
An access review only tells you the truth about the access it actually covers. If the process certifies application entitlements but omits badges, door access, or other physical permissions, it creates a false sense of closure: the digital layer may look clean while the person still has real-world reach to offices, labs, or assets.
The break is coverage, not intent. Recertification is supposed to answer one practical question, “Can this person still reach what they should not reach?” Once physical access sits outside the review scope, the answer becomes partial, and the control stops describing actual access risk.
Where the Governance Gap Shows Up
The gap becomes visible when teams assume identity review equals access review. In practice, badge systems, visitor rights, and facilities permissions often sit with a different owner, different workflow, and different evidence trail than application access, so the two worlds drift apart unless someone deliberately reconciles them. That is why a person can pass an entitlement review and still retain access to restricted spaces.
In governance terms, the entitlement set is fragmented. The reviewer may be certifying roles, groups, or application permissions while the real access decision also depends on physical controls, shared spaces, temporary badges, and vendor or contractor entry rights. Without a joined view, “approved” means only “approved in one system.”
This is where IAM and IGA Basics is useful, because the control problem is not just access administration but access governance across all material access paths. It also explains why Access Reviews and Certification Guide matters here: a certification campaign that excludes one access population cannot produce a reliable governance outcome.
What Good Looks Like in a Joined Review Model
A reliable process treats digital and physical access as parts of the same entitlement picture for the purpose of recertification. That does not always mean one tool, but it does mean one decision view: the reviewer should be able to see who has access, to what, under what basis, and which access types must be removed together when the business justification no longer holds.
Strong practice also distinguishes ownership. Facilities, IAM, and managers need a shared recertification model so badge permissions do not fall into a separate annual cleanup while application access is reviewed more frequently. The cadence can differ, but the governance outcome should not differ: if the access is no longer needed, it should be revoked wherever it exists.
For organizations with complex role structures, Role Mining and Role Design Guide helps when physical access is embedded in job roles or location-based privileges. If segregation of duties matters, Segregation of Duties (SoD) Guide adds the missing discipline for conflicting access combinations that span both systems and spaces.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews are part of account and entitlement governance across systems and facilities. |
| IA-2 — Identification and Authentication (Organizational Users) | The question concerns whether identity-based access is being reviewed completely. | |
| Recommendation — Review all active access paths and remove any account or badge access that no longer has a business need. Ensure organizational users are uniquely identified before certifying any of their access rights. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The issue is incomplete access governance when one access plane is omitted. |
| A.7.2 — Physical entry controls | Physical permissions are the missing half of the review scope described in the question. | |
| Recommendation — Define access control rules that cover both logical and physical access paths. Include badge and door permissions in access review scope where they affect protected areas. | ||
| CIS Controls v8 | CIS-5 — Account Management | The failure is incomplete account and access governance across multiple access systems. |
| Recommendation — Centralize account and access review so all active permissions are recertified and removed when unused. | ||
Practitioner Guidance
What to verify: Confirm that every recertification campaign has a defined scope that includes all material access paths, not just application entitlements. If physical access is managed elsewhere, require a reconciliation step before the review is closed.
What to measure: Track the percentage of users whose digital and physical access are reviewed together, plus the number of cases where badge or door access remains after related digital access has been removed. Those exceptions are often the clearest sign that governance is incomplete.
Common mistake: Treating “review completed” as proof of effective governance even when the review excludes an entire access plane. The process may be operationally successful and still security-ineffective.
Practitioner takeaway: If the review cannot answer whether a person can still enter a site, it has not fully answered whether that person still has access.