Join our Newsletter — 33% off our NHI Course

Where does identity governance fail when IAM and PACS are run separately?

It fails at propagation. A termination, transfer, or contractor end date can close a login while leaving a badge active, or revoke a badge while digital access remains open. The gap is not abstract, it is the time and coordination needed to make one lifecycle event take effect everywhere it should.

Where identity governance breaks when IAM and PACS are split

identity governance fails when the control plane is not shared. IAM may process a leaver event, but unless that event reaches physical access controls, badge access can survive the digital deprovisioning step. The reverse is also true: a badge can be cancelled while login access remains active, creating an inconsistent lifecycle and a widened exposure window.

What propagation means in a split-lifecycle model

Propagation is the operational problem at the centre of this question. A single source of truth for identity status only matters if both systems consume it quickly, map it consistently, and enforce it without manual reconciliation. In a separate IAM and PACS setup, each system often has its own workflow, approval path, and timing, so governance becomes dependent on the slowest or least connected step.

That is why joiner, mover, and leaver controls become fragile when they are implemented as two independent programs rather than one coordinated lifecycle. The identity event is not the issue by itself; the failure is that the event does not reliably propagate to every access channel that the person can use.

Why coordination gaps matter more than policy gaps

Most organisations already have a policy that says access should end promptly. The practical failure is usually in entitlement mapping, event handling, and exception handling. If HR, IAM, and PACS do not share the same authoritative status and trigger logic, then one team can believe access has been removed while another system still permits entry.

That creates governance blind spots around contractors, temporary staff, and movers with residual access. It also complicates audit evidence, because a clean IAM record does not prove that physical access has been closed, and a closed badge record does not prove that logical access has been removed.

For a practical lifecycle view, see IAM and IGA Basics, which explains how provisioning, access review, and governance are supposed to fit together. The lifecycle angle is also developed in Joiner-Mover-Leaver (JML) Guide, where the leaver process must remove access consistently across every system.

Risk and Threat Considerations

Separate IAM and PACS programs create a real exposure window for insider misuse, stolen badge reuse, and delayed revocation after termination or role change. The risk increases when manual tickets, batch updates, or overnight syncs are used to bridge two systems that should be enforcing the same lifecycle outcome.

Failure mechanism: A status change is accepted in one control plane but not the other, so access remains valid in the lagging system until the next sync, exception review, or manual cleanup.

Impact: An individual may retain unauthorised building access, system access, or both, which can undermine segregation of duties, increase incident response complexity, and weaken audit confidence in joiner-mover-leaver controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Covers timely revocation and lifecycle control of authenticators when identity status changes.
AC-2 — Account Management Requires coordinated account lifecycle handling across systems when roles or employment change.
PE-2 — Physical Access Authorizations Addresses issuance and revocation of physical access permissions such as badges and facility entry.
Recommendation — Revoke authenticators promptly when a lifecycle event closes access. Synchronize account changes across IAM-connected systems and physical access lists. Tie physical access authorization changes to the same authoritative lifecycle event as digital access.
ISO/IEC 27001:2022 A.5.16 — Identity management Supports governance over identities and their authorized access across linked systems.
A.5.18 — Access rights Requires access rights to be provisioned, reviewed, and removed consistently.
Recommendation — Maintain one authoritative identity record that drives both logical and physical access. Ensure access rights are removed in every system when the identity lifecycle ends.

Practitioner Guidance

What to verify: Treat every termination, transfer, and contractor end date as a propagation test, not just a policy event. Verify that the same lifecycle event revokes the badge, the login, and any exceptions that extend either one.

Decision rule: If a control requires human follow-up to close either physical or logical access, treat the process as partially manual and therefore higher risk. If the systems cannot consume the same authoritative status in near real time, tighten the exception window and require explicit reconciliation evidence.

Practitioner takeaway: Identity governance fails here when organisations mistake a completed ticket for completed enforcement; the real control objective is synchronised revocation across every access path that the identity can use.