By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SaviyntPublished June 11, 2025

TL;DR: The University of Ottawa says it unified physical and digital access control in one identity system, adding RBAC, lifecycle management, and direct integration between Genetec and Saviynt to streamline campus access and governance. The practical lesson is that physical security becomes an identity lifecycle problem once badges, roles, and approvals share the same control plane.


At a glance

What this is: The University of Ottawa describes a single identity system that ties campus physical access and digital access together, with RBAC and lifecycle management as the core governance change.

Why it matters: For IAM and IGA teams, the case shows how mixed physical and digital access can expose lifecycle, approval, and role-design gaps that standard IT-only models miss.

👉 Read Saviynt's case study on unified physical and digital access control at the University of Ottawa


Context

The core governance issue here is not simply campus convenience. It is the collapse of two access domains that are usually managed separately: physical entry and digital entitlement. In identity terms, the University of Ottawa is describing a single lifecycle and authorization model for people whose access spans buildings, systems, and services, which makes the use case relevant to IAM, IGA, and campus security teams.

That matters because mixed access environments often fail at the seams. Badge issuance, role changes, request approvals, and offboarding can be handled in different systems with different owners, which creates delays, duplicate records, and stale access. The article frames a typical modernisation pattern for higher education, but the governance lessons apply well beyond campus operations.


Key questions

Q: How should security teams govern physical and digital access through one identity model?

A: Start by mapping badges, facility rights, contractor credentials, and application entitlements to a single identity record. Then apply the same joiner-mover-leaver, certification, and revocation processes across both domains so access can be approved, reviewed, and removed consistently rather than through separate physical and digital evidence chains.

Q: Why does RBAC matter in physical access control?

A: RBAC matters because it replaces ad hoc, door-by-door permissions with governed roles that can be reviewed, approved, and revoked consistently. In mixed environments, that consistency reduces manual effort and helps ensure that a job change changes every relevant access path at the same time.

Q: Why does physical access become risky when it is managed separately from IAM?

A: Because physical access can outlive the employment record if revocation is not tied to the same source of truth. A terminated employee may still hold a badge, and role changes may not remove old entitlements. Separate management creates drift, weak evidence, and unnecessary insider risk.

Q: Who should own mixed physical and digital access governance?

A: Ownership should sit with identity governance, physical security, and business process owners together, because no single team sees the full lifecycle. If the systems share a control plane, accountability must also be shared across provisioning, review, and revocation decisions.


Technical breakdown

RBAC for physical access and digital identity

Role-based access control assigns permissions through defined roles rather than per-user exceptions. In this case, RBAC is extended beyond application entitlements into campus access control, which is unusual because physical access is often managed as door-by-door exception handling. The technical value is consistency: when a person changes jobs or student status, the role can drive both building access and system access from the same identity record. That reduces manual updates, but it only works if role definitions are precise and governance is strong.

Practical implication: model physical access as part of the same role design and certification process used for IT entitlements.

Identity lifecycle management across campus systems

Lifecycle management means joiner, mover, and leaver processes govern access from onboarding through role change and removal. The article shows this being applied across both card credentials and digital identity, which is where many programmes break down because physical access is often left outside the core IAM workflow. Direct data synchronisation matters here, because lifecycle events must propagate reliably to every connected system. If the workflows are not aligned, access persists after job changes or departures even when the identity record looks current.

Practical implication: make physical access revocation and updates part of the same offboarding and mover workflow as digital access.

API-driven identity data exchange between systems

The integration described relies on a direct database connection between the physical security platform and the IGA system, plus an internal API gateway linking identity data to badge credentials, group memberships, and photographs. This is an architecture pattern, not just a feature. The important security point is that each data element becomes an access-control input, so the integrity of the interfaces matters as much as the policy logic. If the gateway or synchronisation jobs fail, the identity record and the physical access state can drift apart.

Practical implication: treat identity interfaces as governance-critical controls and monitor synchronisation failures like any other access-control defect.


NHI Mgmt Group analysis

Physical access is now an identity lifecycle problem, not a facilities-only problem. Once badges, buildings, meal plans, and digital entitlements sit in one control flow, the access decision becomes inseparable from joiner, mover, and leaver governance. That changes ownership, review cadence, and audit evidence requirements for IAM and physical security teams alike. The implication is that campuses and enterprises need one lifecycle model for all identity-bound access, not parallel systems with different truth sources.

RBAC becomes materially more valuable when it governs both doors and systems. Physical access has historically been handled through exceptions, local approvals, and manual door lists, which creates inconsistent governance. Applying role structure to campus access reduces that entropy, but only if role engineering is maintained and not allowed to sprawl into poorly governed bundles. The practitioner lesson is that role design is now a cross-domain control, not just an application governance exercise.

Identity data integration creates a governance dependency that many programmes underweight. When card credentials, photographs, memberships, and entitlement requests depend on API-driven synchronisation, the control surface shifts to data quality, routing logic, and system trust. This is not a customization story, it is a control integrity story. The concept here is cross-domain entitlement drift: access remains technically provisioned in one system after the governance state changed in another. Practitioners should treat that drift as a measurable security condition.

Higher education is exposing a broader enterprise pattern for mixed identity estates. The article is framed as a campus modernization story, but the same model is emerging anywhere physical access, IT access, and role-based approvals converge. That includes healthcare, manufacturing, and research environments where a single person or contractor may need credentials across multiple domains. The practical conclusion is that governance teams must stop classifying physical access as separate from IAM because audit and risk outcomes already do not.

From our research:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
  • Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which shows how quickly governance confidence drops outside human IAM.
  • For the broader lifecycle and governance angle, NHI Lifecycle Management Guide is the next step for teams formalising joiner-mover-leaver controls across identity types.

What this signals

Cross-domain entitlement drift: when physical access, card functions, and digital entitlements are updated in different systems, governance state and real-world access inevitably diverge. That drift is what identity teams should prepare to measure, because the risk is not only delay but mismatch between what policy says and what people can actually use.

The campus pattern here is a reminder that lifecycle governance now has to span every identity-bound control point, not just applications. Teams that already struggle with access review quality should expect the same failure mode when physical access is brought into scope unless the authoritative source, approval path, and revocation path are aligned.

For practitioners working from policy to implementation, the useful next lens is NIST Cybersecurity Framework 2.0 paired with the CIS Controls v8, because both help connect access governance to measurable control outcomes rather than isolated administration tasks.


For practitioners

  • Map physical access into the same lifecycle workflow Include badge issuance, card revocation, and mover events in the same joiner-mover-leaver process used for digital access so the access state changes together across systems.
  • Engineer roles across buildings and applications Define RBAC so that campus roles drive both physical zones and IT entitlements, with exceptions limited to sensitive areas that truly need bespoke approval.
  • Monitor synchronisation as a control, not an IT task Track API gateway failures, stale interface jobs, and rejected entitlement requests as governance incidents because they can create access drift between systems.
  • Certify mixed-access identities together Run access reviews that cover building access, card functions, and application entitlements in one review cycle so reviewers see the full exposure picture.

Key takeaways

  • This case shows that physical access and digital identity are now one governance problem when roles, approvals, and lifecycle events are shared.
  • The practical risk is access drift between systems, especially when card credentials and IT entitlements are not revoked or updated together.
  • The control that matters most is a single lifecycle and role model that spans physical security, IAM, and audit evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4The article centers on managed access permissions and role-based governance.
NIST SP 800-53 Rev 5AC-2Account management applies to lifecycle changes across badge and digital access.
CIS Controls v8CIS-5 , Account ManagementAccount management is the clearest control family for shared identity lifecycle governance.
NIST Zero Trust (SP 800-207)Zero trust reinforces continuous verification across mixed access domains.
OWASP Non-Human Identity Top 10NHI-03Lifecycle and access governance issues map to non-human style entitlement drift risks.

Map physical and digital access to PR.AC-4 and verify approvals, revocation, and role assignment are aligned.


Key terms

  • Cross-domain entitlement drift: A mismatch between what one system says a person can access and what another system still allows. In mixed physical and digital environments, it appears when badge systems, IAM platforms, and approval workflows update at different speeds or under different ownership.
  • Role-Based Access Control: A model that grants permissions by assigning identities to predefined roles. It works well when jobs are stable and access patterns are predictable, but it becomes brittle when exceptions pile up. In practice, role design must stay small enough to audit and broad enough to avoid endless custom variants.
  • Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.
  • Identity Control Plane: An identity control plane is the governance layer that decides who or what can access systems and under what conditions. In practice, it coordinates authentication, authorization, privilege review, and lifecycle management across human and machine identities so access policy is enforced consistently across environments.

What's in the full article

Saviynt's full case study covers the operational detail this post intentionally leaves for the source:

  • The data model used to connect card credentials, photographs, group memberships, and access requests across systems
  • The implementation sequence for integrating Genetec with the IGA platform and the internal API gateway
  • The approval-routing logic that maps entitlement requests to the right supervisor using metadata
  • The team structure and partner support model that made the rollout possible

👉 The full Saviynt case study covers the integration approach, workflow design, and rollout details behind the campus identity model.

Deepen your knowledge

NHI governance, machine identity security, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org