They should connect lifecycle events from the authoritative HR source to badge issuance, badge modification, and badge revocation. Physical access must be governed with the same joiner, mover, and leaver logic used for applications so the person’s employment status and facility authority never diverge.
Why Extending JML to Physical Access Matters
Joiner-mover-leaver processes fail when they stop at application accounts. If HR status changes are not translated into badge issuance, badge updates, and badge revocation, a departed employee can still enter a building while their logical access is already closed, or a transferred employee can retain access to areas no longer needed. That gap creates a governance blind spot across security, safety, and audit.
Physical access is part of identity lifecycle control, not a separate facilities problem. Current guidance aligns with the same principle used for privileged access: entitlements should follow current need, be removed when need ends, and be reviewed on a defined schedule. The OWASP Non-Human Identity Top 10 reinforces this lifecycle discipline for machine access, while NIST controls around account and access management provide a useful analogue for badge governance. NHI Management Group’s Ultimate Guide to NHIs shows why lifecycle failures become security failures once credentials or access paths are left active beyond their intended use.
In practice, many security teams discover physical access drift only after an audit, a termination review, or an incident investigation rather than through intentional lifecycle control.
How to Operationalise Physical JML
Effective physical JML starts with the authoritative HR system as the trigger source and the badge or physical access control system as the downstream enforcement point. The goal is to make facility access react to the same employment events that govern application access, so a joiner gets only the sites and zones required, a mover is adjusted quickly, and a leaver is revoked without delay.
A practical implementation usually includes:
- Automated badge issuance for joiners only after identity proofing, manager approval, and role validation are complete.
- Immediate badge re-scoping for movers when job function, location, or reporting line changes.
- Timed revocation for leavers, including badge disablement, turn-in tracking, and last-entry logging.
- Exception handling for contractors, visitors, and shared spaces, with expiry dates and sponsor ownership.
- Periodic reconciliation between HR records, physical access logs, and active badge assignments.
This is also where identity governance should connect to broader access policy. NIST SP 800-53 Rev. 5 supports the idea that access authorisation must be controlled, reviewed, and removed when no longer needed, and that principle applies just as strongly to doors as it does to systems. For organisations managing both human and machine lifecycle risk, the same operational logic appears in 52 NHI Breaches Analysis, where stale access paths repeatedly turn into real-world exposure.
Where this guidance breaks down is in multi-site environments with outsourced facilities teams and disconnected badge systems, because revocation latency and inconsistent local procedures create access gaps that HR alone cannot close.
Common Variations and Edge Cases
Tighter badge control often increases operational overhead, requiring organisations to balance security precision against workforce friction and facility uptime. That tradeoff is most visible in environments with contractors, temporary staff, emergency responders, and shared workspaces, where strict automation can be too rigid if the business does not support clean exceptions.
Best practice is evolving, and there is no universal standard for every physical access scenario. Some organisations use just-in-time badge provisioning for visitors or short-term workers, while others rely on pre-approved access profiles tied to location and time windows. The right model depends on how quickly HR events are published, how many sites are involved, and whether facilities, security, and IT share a single identity workflow.
Two common edge cases deserve special handling. First, movers who change teams but stay in the same building may need reduced rather than fully replaced access, so the system must support rapid entitlement reshaping instead of a full reissue. Second, leavers with retained visitor access, gym access, or after-hours access can bypass the normal offboarding path unless every badge use case is explicitly inventoried. The Ultimate Guide to NHIs - Key Challenges and Risks is a useful reminder that unmanaged access paths tend to persist when ownership is unclear.
Physical JML is strongest when access rights are short-lived, reviewed, and tied to a named owner. It weakens when badge exceptions become permanent and no one is accountable for closing them.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Physical access must be provisioned and removed with lifecycle events. |
| NIST SP 800-63 | Identity proofing and lifecycle assurance support trustworthy badge issuance. | |
| NIST Zero Trust (SP 800-207) | Zero Trust principles support continuous, least-privilege access decisions. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | Lifecycle control is central to preventing stale access paths. |
| NIST AI RMF | Governance and accountability apply to automated access workflows. |
Tie badge issuance and revocation to HR events and verify access changes at each lifecycle step.
Related resources from NHI Mgmt Group
- How can organisations use access profiles in joiner-mover-leaver workflows?
- How should organisations automate joiner mover leaver access changes?
- How should teams govern Jira access through joiner-mover-leaver workflows?
- How should organisations manage joiner-mover-leaver processes across employees and contractors?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org