Shared workstations compress multiple users, roles and actions into the same physical and logical environment, which makes it harder to prove who did what. If the organisation does not separate sessions and identities clearly, the audit trail becomes ambiguous and incident reconstruction gets much harder.
Why shared workstations make OT audit trails harder to trust
Shared workstations collapse multiple operators, shifts, and sometimes contractors into the same endpoint, so the workstation itself stops being a reliable proxy for a single accountable user. In OT, that matters because local HMI, engineering, and maintenance actions can all look similar unless sessions, badge-ins, and authentication events are tightly separated and time-aligned.
When the same console is reused across people and roles, the system often records “a workstation action” rather than a clearly attributable human action. That weakens the chain of custody for configuration changes, alarm acknowledgements, and emergency interventions, especially if operators can reuse browsers, cached credentials, or shared logins.
OT also tends to prioritise availability, so teams tolerate fast logon patterns, shared break-glass access, or loosely managed local accounts. Those choices can be operationally sensible, but they reduce evidentiary quality unless the organisation adds compensating controls such as individual session IDs, strict time synchronisation, and clear handoff procedures between users.
Where auditability breaks down in practice
The core problem is not just that several people touch the same device, but that the same device may mediate access to many different systems. If historians, HMIs, engineering tools, and remote support sessions all pass through one shared station, investigators must reconstruct intent from partial logs, which is much harder than reading a one-to-one user-to-action record.
This is why OT auditability degrades when shared access is combined with weak identity separation. A robust audit trail needs more than event timestamps, it needs a dependable mapping between user, session, asset, and action. Without that mapping, even good logs may fail to prove who approved a change, who issued a command, or whether an action was local, delegated, or remote.
Shared workstations also create a higher chance of credential residue, session carryover, and misattribution between shifts. If one user leaves a browser session open or an engineer steps in during an active login, the resulting activity can be technically recorded yet still be difficult to attribute with confidence.
What poor auditability changes for incident review and control evidence
Poor auditability slows root-cause analysis because investigators cannot quickly separate operator error, authorised maintenance, and suspicious use of a console. It also weakens compliance evidence, since many OT and critical-infrastructure controls depend on being able to demonstrate who performed what, when, and under which approval path.
For this reason, OT security guidance emphasises clear access paths, segmentation, and strong logging around human interactions with critical systems. NIST’s OT guide NIST SP 800-82 Rev 3, OT Security Guide and CISA’s industrial control resources CISA Industrial Control Systems both reflect the need for stronger visibility, controlled access, and defensible operations in industrial environments.
Where organisations rely on a shared workstation model, the practical question is whether the logs still support trustworthy attribution after a change, outage, or safety event. If they do not, the organisation may know that an action occurred, but not who should be held accountable or which other actions on the same console belong to the same incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Shared OT workstations need user-attributable logging for actions. |
| IA-2 — Identification and Authentication (Organizational Users) | Individual operator authentication preserves accountability on shared consoles. | |
| AC-6 — Least Privilege | Shared OT access becomes harder to audit when users retain more access than needed. | |
| Recommendation — Define log events so workstation actions can be tied to named users and sessions. Require unique user authentication before any shared workstation action. Limit each operator to the minimum privileges needed for the shift. | ||
| ISO/IEC 27001:2022 | A.8.15 — Logging | Auditability depends on logs that record actions on shared OT endpoints. |
| A.5.15 — Access control | Shared workstations are an access-control problem as much as an endpoint problem. | |
| Recommendation — Ensure OT logs capture operator identity, session and action detail. Separate access by user and role instead of relying on shared console use. | ||
Practitioner Guidance
What to prioritise: Treat attribution quality as a control objective, not a reporting afterthought. If a shared workstation is unavoidable, require individual authentication, per-user session switching, and time-synchronised logs that tie each action to a named operator rather than to the console itself.
What to verify: Confirm that the workstation, the application, and the downstream OT system all preserve user identity across the full path. The audit trail should survive shift changes, remote support, and emergency access without collapsing into a generic device log.
Common mistake: Teams often assume CCTV, badge records, or shift rosters can compensate for weak system logs. Those sources help, but they rarely provide enough precision to reconstruct exact technical actions unless the underlying session data is already clean.
Practitioner takeaway: Shared OT workstations are not automatically the problem; the real failure is when shared physical access is allowed to erase individual technical accountability. If you cannot reliably attribute actions after an incident, you do not yet have an audit trail, you have a shared activity record.
Related resources from NHI Mgmt Group
- Why do shared device keys increase operational risk in OT environments?
- Why do shared VPNs and jump boxes increase lateral movement risk in OT networks?
- Why do shared workstations and mixed devices increase identity risk in public safety environments?
- Why do shared IT and OT access paths increase operational risk?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org