In physical access, identity is only half the answer


In physical access, identity is only half the answer

Physical access is moving from the door to the person, from what a key opens to who someone is, drawn from an HR or identity system. Knowing who someone is is not the same as knowing whether they should still open a given door. Keys and identity are two different records, and most sites keep only one of them well. The questions below separate what identity settles from what it does not.

Is identity enough for physical access?

No. Identity tells you who a person is, not whether they should still be able to open a given door. Physical access needs both. It needs the identity that establishes who someone is, and a check at the door that confirms the access is still correct.

What does identity actually get right?

The “who”. Drawn from HR and identity systems, identity has made that far cleaner than it used to be: one record per person, checked against a source, kept current as people join and move between roles. Because that record travels across every system a person touches, it clears a whole class of old errors, the account that outlived the person and the leaver still on the list. Access can start from a reliable answer to who is asking. The mistake is reading a clean answer to “who” as a clean answer to “what they can still open.” One record says who a person is. The other says what a particular key or card still opens, and that one changes every time a lock is rekeyed, a card is reissued, or a key goes unreturned.

Why doesn’t a door know who you are?

Because a door was never built to. It reads the key or card in front of it and opens, and it goes on opening until that credential is changed or collected. Identity lives upstream, in the systems that decide who should get what; the door only ever sees the credential. And an identity system, built to answer who a person is across every system they touch, was never meant to know that one cylinder in one door was last opened by a key issued for a job that ended in March. That knowledge sits in the physical world, in the key, the lock and the record of who holds it, and it does not refresh itself when a directory changes.

A wall-mounted card reader beside a door on a slate-grey wall, its indicator glowing green with no one present.
The door reads the credential, not the person, and opens either way.

Who carries the change from identity to the door?

Someone has to. When a person changes role or leaves, the identity system can know within the hour. The card still has to be turned off and the key still has to be collected, and that is a separate act by a separate person: a facilities lead who hears a contract has ended, an administrator acting on a leaver flag. Where that handoff is quick and written down, access stays correct. Where it waits on someone remembering, the door keeps its own version of the truth, and the directory and the door drift apart. At one site, one person knows every key. Across many sites the change has to pass through different teams on different systems, none of whom owns the door at the far end, and every handoff is a place it can stall.

Where does access drift, and how would you see it?

In the gap between the record of who someone is and the reality of what their key still opens. A person can be perfectly identified and still hold access that should have ended months ago, the identity record right while the access is wrong. You can measure your own exposure without any new system. Take one regulated room, and compare who is authorised for it on paper with who currently holds a working key or card to it. The difference is access that has outlived its reason. One site fits in your head. A dozen sites, several access systems, and years of joiners and leavers do not, which is where a complete record of who holds which key and what it opens matters most.

What breaks when only identity is checked?

Two failures recur. An outside contractor keeps a working key to a plant room long after the job ends, and nothing flags it, because their identity record was closed cleanly and the door was never told. An auditor asks for everyone who can enter a regulated room, and the list from the identity system is short by exactly the people holding physical keys it never tracked. Nobody did anything wrong, and the identity side was tidy. The identity system did its job; the door was just never part of the same record. The gap shows only from the door, and only if someone looks.

The door was never the hard part

Identity has made the first half of physical access easier than it has ever been. Knowing who someone is is close to solved. Knowing whether they should still open the door in front of them, today, for a reason that still holds, is the half that is not, and it is the half worth building toward. The shift from doors to identity is real. The next step is not choosing between the door and the identity. It is keeping the two in one honest picture, so that who a person is and what they can open do not fall out of step.

Common questions about physical access and identity


Subscribe Now