By NHI Mgmt Group Editorial TeamBased on WorkOS: “Duality AI: Building Reality-Grade Digital Twins for AI and Robotics” (December 1, 2025)

TL;DR: Duality AI’s Falcon uses high-fidelity digital twins to generate synthetic data and validate robotics and embodied AI safely, while the article also argues that enterprise auth, scoped permissions, and auditability still need a separate governance layer according to WorkOS. That split matters because simulation expands testing capacity, but it does not answer who can launch, modify, or export the resulting data and outputs.


At a glance

What this is: This is an analysis of how high-fidelity digital twins help AI and robotics teams test safely, while leaving identity and access governance as a separate requirement.

Why it matters: IAM, PAM, and NHI teams need to treat simulation platforms as governed enterprise systems, because the right to run, modify, or extract outputs is an access problem, not a modelling problem.


Context

Digital twins are virtual environments that mirror physical systems closely enough to support realistic testing, data generation, and behaviour validation. In this article, the primary governance gap is not simulation fidelity, but the identity layer around simulation workflows, output access, and enterprise sharing.

WorkOS frames the problem as one of access control above the simulation stack. As AI and robotics teams expose dashboards, scenario builders, and synthetic datasets to more users, the question shifts from whether the model works in simulation to who can operate, inspect, or export that simulation safely.


Key questions

Q: How should teams govern access to digital twin simulation platforms?

A: Treat the simulator as a governed platform, not a standalone engineering tool. Separate permissions for scenario creation, execution, export, and deployment. Use enterprise identity for all humans, then apply role-scoped access, audit logging, and lifecycle offboarding so access follows business responsibility rather than project convenience.

Q: Why do digital twin workflows need identity controls beyond model validation?

A: Because validation answers whether the system behaves correctly, while identity controls answer who may operate the system and handle its outputs. Once synthetic data, scenario design, and simulation dashboards are shared across teams, the security problem becomes authorisation, auditability, and lifecycle control, not just technical correctness.

Q: What breaks when simulation outputs are shared without scoped permissions?

A: Teams lose the ability to separate view, modify, launch, and export rights. That usually leads to either over-permissioned access or bottlenecks where every request needs manual approval. Scoped permissions preserve collaboration while keeping simulation artefacts under traceable, role-specific control.

Q: What should organisations do immediately when digital twins become cross-team assets?

A: Put the platform under the same identity governance as other enterprise systems. That means provisioning through the corporate identity stack, logging exports, reviewing entitlements regularly, and removing access when contractors, auditors, or partner teams no longer need it.


Technical breakdown

Why simulation fidelity does not solve access control

High-fidelity digital twins reproduce sensors, physics, object dynamics, and environment behaviour so teams can test embodied AI without physical risk. That solves a technical validation problem, but not a governance problem. Once simulation outputs become business assets, the system needs identity controls for launch rights, dataset visibility, and modification scope. Otherwise, the same environment that improves model quality can become a broad access surface for internal teams, contractors, or external reviewers. The important point is that simulation realism and authorization depth are separate layers, not substitutes for each other.

Practical implication: treat digital-twin platforms as governed production-adjacent systems, not as unowned test sandboxes.

Enterprise auth for simulation platforms

The article points to SSO, directory sync, multifactor authentication, role-based permissions, resource-scoped permissions, and auditability as the control layer around simulation. That matters because simulation users are not a single role: operators may launch scenarios, data scientists may inspect synthetic data, and auditors may need read-only access. Without granular entitlement design, teams either over-share simulation assets or block the workflows that make the platform useful. In practice, the auth layer has to express both organisational identity and task-specific scope across human users and, where relevant, automated workflows that touch simulation outputs.

Practical implication: model simulation access by role and resource, not by a single platform-wide entitlement.

Why synthetic data still needs lifecycle governance

Synthetic data reduces dependence on dangerous or expensive physical testing, but it still travels through enterprise processes. It may be downloaded, versioned, reviewed, redistributed, or used to train downstream models. That means the data lifecycle extends beyond generation into access review, retention, export control, and offboarding. The governance gap is not the data itself but the assumption that non-production data is automatically low risk. Once synthetic outputs influence real product decisions or external customer workflows, they need the same identity-aware oversight as other sensitive assets.

Practical implication: apply lifecycle controls to synthetic data the moment it becomes shareable or decision-relevant.


NHI Mgmt Group analysis

Digital-twin fidelity creates a governance illusion if identity is treated as an afterthought. The article is right to separate simulation capability from access control. High-fidelity environments can be technically accurate while still being operationally under-governed if launch rights, export rights, and review rights are not explicitly modelled. For identity teams, the lesson is simple: realism in the twin does not imply control in the enterprise.

Simulation platforms are becoming enterprise systems, not just engineering tools. Once multiple teams, contractors, and auditors can reach the same environment, the platform inherits the same identity problems as any internal SaaS. That means authentication, entitlement design, provisioning, and audit trails matter as much as simulation throughput. The practical conclusion is that platform ownership must include identity governance from day one.

Role-scoped access is the decisive control boundary for digital twins. The core security question is no longer whether the twin is accurate, but whether the organisation can limit who may create, modify, observe, and export simulation outputs. That boundary determines whether the system supports controlled experimentation or becomes a shared data lake with a simulation front end. Practitioners should design access around resource scope, not around broad platform membership.

Named concept: digital twin governance layer. This article shows why simulation and identity should be managed as distinct layers in the stack. The twin produces the environment and outputs, while the governance layer determines who can touch them, under what conditions, and with what evidence. Practitioners should treat that separation as a core architectural principle for AI and robotics programmes.

Identity governance now follows the output, not just the workload. As synthetic data and simulation artefacts move into product development, compliance review, and external collaboration, the access model has to extend with them. The field implication is that machine learning and robotics governance will increasingly depend on auditability of artefact access, not only on accuracy of model training.

What this signals

Digital twin governance layer: simulation programmes now need a distinct control plane for who can create, inspect, and export outputs. The model may be technical, but the risk is operational, because the moment synthetic data becomes shareable it behaves like any other governed enterprise asset.

Identity teams should expect robotics and embodied AI platforms to be pulled into standard access review, provisioning, and audit workflows. That shift matters because the security question moves from whether the simulation is accurate to whether the organisation can prove who touched the resulting data and when.


For practitioners

  • Define simulation access roles Separate operators, model developers, reviewers, and export approvers so each role receives only the simulation actions needed for its task.
  • Scope permissions to simulation resources Tie entitlements to specific twins, scenarios, datasets, and output folders instead of granting broad platform-wide access.
  • Require audited output export Log every download, share, and handoff of synthetic data or simulation artefacts so downstream use is traceable.
  • Integrate enterprise identity providers Use SSO and directory sync so onboarding, offboarding, and access changes follow corporate identity policy rather than local platform accounts.

Key takeaways

  • Digital twins improve testing realism for AI and robotics, but they do not replace enterprise identity controls around access, export, and audit.
  • The governance boundary sits above the simulation layer, where scoped permissions and lifecycle oversight determine who can use the environment and its outputs.
  • Practical security design should treat synthetic data and simulation workflows as governed assets once they cross team or organisational boundaries.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article is fundamentally about governing who can access simulation platforms and outputs.
Recommendation — Use IAM controls to scope who can launch, modify, and export simulation assets.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsScoped permissions are the core control boundary discussed around digital-twin workflows.
Recommendation — Apply PR.AA-05 to constrain simulation access by role, resource, and task.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast privilege is needed to stop broad access across simulation dashboards and artefacts.
AU-2 — Event LoggingAuditability is explicitly required for simulation launch, modification, and export actions.
Recommendation — Enforce AC-6 so users only receive the simulation permissions their role requires. Log simulation actions so export and modification activity remains attributable.

Key terms

  • Digital Twin Governance Layer: The governance layer is the identity, access, and audit control plane that sits above a digital twin environment. It determines who may create, view, modify, launch, or export simulation assets, and it turns simulation from an engineering tool into an enterprise-managed service.
  • Synthetic Data Lifecycle: Synthetic data lifecycle is the set of controls that govern generated data after it leaves the simulator. It includes access, retention, sharing, review, and deletion, because simulated outputs can still become sensitive business artefacts once they are used across teams or in downstream products.
  • Resource-scoped Permissions: Resource-scoped permissions restrict access to specific simulation environments, datasets, scenarios, or output folders rather than the platform as a whole. This reduces over-permissioning and makes it possible to separate operators, developers, reviewers, and export approvers cleanly.
  • Enterprise Identity Provider Integration: Enterprise identity provider integration connects a platform to corporate authentication, provisioning, and deprovisioning systems. For simulation platforms, it ensures access follows organisational policy instead of local accounts, which is essential when multiple teams and external reviewers use the same environment.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org