If you really step back and look at where most cybersecurity investment goes, it almost always comes back to one simple question: who actually has access to what? 

When you think about identity governance, centralized access controls, Privileged Access Management and Zero Trust, they are all really trying to answer that question in a way that holds up under scrutiny. Security teams have shifted toward validating identities, governing access and making sure permissions actually match what someone needs to do their job. 

Over time, that shift has fundamentally changed how organizations manage their digital identities. 

Joiner, Mover and Leaver processes that were once manual and scattered across systems have become automated workflows. Access reviews that used to take weeks are now structured governance processes. Privileged access that lived in spreadsheets is now vaulted and monitored. Even authentication has evolved from basic passwords to MFA, adaptive controls and increasingly passwordless approaches. 

So as organizations grew and matured on the digital side, they often did not account for the identities that have continued operating on their own: physical security. 

Badge systems, surveillance platforms, visitor management and access control systems have historically been managed separately from the identity programs that govern digital access. That separation was not necessarily intentional, it is simply how these disciplines evolved. Cybersecurity focused on protecting systems and data, while physical security focused on protecting people and facilities. Over time, both built their own tools, processes and governance models. 

Where this starts to break down is when you realize both sides are making access decisions about the same person. One system decides if someone can access a financial application, while another decides if they can walk into the building or a restricted area where that system lives. At the end of the day, the systems are different, but the identity behind the decision is exactly the same. 

  

The governance gap nobody talks about enough

If you look at where organizations have invested over the last decade, they have built pretty mature identity governance around applications, infrastructure, cloud and privileged accounts. Physical identities, though, are usually not part of that same model. 

The issue is not really that the technology does not exist, because in most cases it does. The bigger issue is how access is governed and whether physical security and cybersecurity are actually working from the same understanding. 

What this often creates is two teams managing access for the same individuals, but doing so in different systems, through different processes and with limited visibility into each other's decisions. 

A cybersecurity team can usually tell you every application and admin account someone has. If you ask physical security, they can tell you every building and restricted area that same person can enter. What neither side usually has is a complete picture across both. 

That gap does not always show up right away, but it becomes obvious during things like terminations, role changes or investigations. 

A manager might certify someone's application access without realizing that the same person still has badge access to a data center from a previous role. A physical security team might approve access to a restricted area without knowing what level of system access that person already holds. Each decision can make sense in isolation, but when viewed together, the risk becomes much clearer. 

The more disconnected these environments are, the harder it becomes to understand someone's full access footprint. 

And this is not just a challenge for organizations still building out their identity programs. Even in organizations with strong access governance on both sides, the gap tends to surface at the seam between the two programs rather than within either one individually. Two mature programs operating in parallel, without a shared lifecycle model or unified view of access, can still leave an individual with entitlements that neither team fully sees. The hygiene exists, but the connection between the two does not.  


 

Access is access

Organizations naturally tend to treat physical security and identity security as separate domains. Physical security is often aligned with facilities or corporate security, while identity lives within cybersecurity or IT. Because they evolved independently, each area developed its own processes, tools and governance structures. 

The problem is that attackers do not care about those boundaries. 

If someone is trying to get into your environment, they are not thinking in terms of departments. They are looking for the easiest path. 

That path could be a compromised password, an account that was never deprovisioned, an active badge for someone who left or admin access to a physical security system. In many cases, it is a combination of both physical and digital access that no single team sees. 

From a security standpoint, access is still access. It does not really matter how someone gets it, the question is whether they should have it in the first place. 

This is where Zero Trust starts to matter more than people realize. 

Organizations have spent years adopting the idea that trust should not be assumed and that access should be based on identity, context and risk. That thinking now applies across applications, endpoints, cloud and networks. There is no clear reason for that logic to stop at the physical boundary. 

If you require a verified identity and business justification to access a sensitive application, the same thinking should apply to entering a data center or restricted facility. 

Even though the environment changes, the identity does not. The organization still has to decide whether that access makes sense and whether it should continue. 

  

The question many organizations cannot answer completely

One of the simplest ways to validate an identity program's maturity is to ask: what happens when someone leaves the company? 

For mature identity practices, the answer on the digital side is usually clear. Automated processes kick in to disable accounts, remove access, revoke sessions and begin pulling back privileges across systems. What once required coordination across teams and spreadsheets is now handled through structured lifecycle workflows, with a focus on speed, consistency and auditability. 

When the same question is applied to physical access, the answer is often less consistent. 

Was the badge disabled at the same time as the accounts? Did both actions come from the same event? Was access removed from every location? Is there a single audit trail that shows when all forms of access were revoked? 

In a lot of cases, physical access is still handled separately, by a different team, on a different timeline. That does not mean anyone is doing their job wrong, but rather that there is a disconnect between processes that should be aligned. 

Similar issues apply during role changes. When someone moves into a new role, their application access is usually updated automatically, but their physical access often is not reviewed at the same time. This raises the question of whether they should still have access to their old office, lab or restricted area. 

Any change in role, location or responsibility can impact both physical and digital access, but most organizations only govern one side. The individual's identity has not changed, just the way they access things. 

That is where there is an opportunity to rethink how physical access fits into identity governance. 

The idea is not to replace existing physical security processes, it is to connect them to the same lifecycle events. If someone is terminated, both digital and physical access should be handled together. If their role changes, both should be reviewed. 

Technology can support this alignment, but it still comes down to teams agreeing on ownership and accountability. 

  

The privileged access problem that gets overlooked

When you look at this even closer, the connection between physical and digital identity becomes even more important when you consider privileged access. 

Cybersecurity teams have put in a lot of effort building strong controls around admin access because they understand the risk involved. Privileged Access Management programs exist for a reason. Accounts with elevated permissions are vaulted, monitored and tightly managed. 

The same level of care and scrutiny may not apply to physical security systems. 

Modern physical security platforms are not just passive tools. They have administrative capabilities that can directly impact an organization's security posture. If someone obtained admin access to a video system, they could disable monitoring, change retention settings or remove footage. A similar scenario applies to access control systems. Think about someone having admin rights in a platform that can allow them to modify badge permissions, grant access to restricted areas or unlock doors. 

From a cybersecurity perspective, that is clearly privileged access. 

However, in many organizations, these accounts are not managed with the same level of controls. They might be local accounts, shared credentials or outside standard review processes. Again, this is not due to oversight, but rather that these systems have historically been managed outside of IT's purview. A system being outside of IT's management does not mean it is not critical. 

If any individual can alter access permissions, disable monitoring or remove evidence, that has to be treated as a risk. Addressing it might mean enforcing individual accounts, requiring MFA, vaulting privileged credentials, monitoring privileged activity or applying just-in-time access where appropriate. 

Not every system needs the same controls, but the level of oversight should match the level of risk. 

  

Why identity is the connective tissue

The idea of bringing physical security and cybersecurity closer together is not new. Security leaders have been talking about convergence for years, and there has been a lot of focus on integration and visibility. 

But underneath all of that, the common thread is still identity. 

Identity is what both sides rely on to make access decisions. It answers who someone is, what they should be able to access and why. Whether it is an application or a building, the decision still comes back to the same person. 

The teams responsible for these decisions do not need to merge into a single function, but they do need to operate from a shared understanding of identity and lifecycle events. A termination should not stop at digital access. A role change should not be interpreted differently depending on the system. 

This does not require every decision to be made within a single platform, but it does require those decisions to be connected. That might involve data sharing, coordinated reviews or consistent approval processes. 

Once you start treating physical access like any other entitlement, the same governance questions apply. Who approved it? Why does it exist? Does it still make sense? Those are not just cybersecurity questions, they are fundamental access governance questions. 

  

The path forward

Closing this gap does not begin with purchasing another tool. It starts with defining ownership, identifying your source of identity truth and agreeing on lifecycle events. 

That means bringing together the teams that already play a role in access decisions. This is not a one-time project, it needs to become an ongoing operating model with shared accountability. 

A good place to start is understanding where physical access intersects with the employee lifecycle. How are badges issued? Who approves access? What happens during role changes? From there, it becomes easier to identify which types of physical access carry the most risk and should be more tightly governed. 

Termination is often the most straightforward place to start. Both digital and physical access should be removed from the same event, with clear evidence. Role changes are another key area, as access should be reviewed across both environments rather than updated in isolation. 

You can also expand access reviews to include physical entitlements. This gives managers a more complete view of what their employees can access. Administrative access to physical security systems should be evaluated based on its potential impact, making sure high-risk permissions are governed appropriately. 

The goal is not to force every process into a single system, but to make sure that access decisions are tied back to identity. 

The organizations that get this right will not necessarily be the ones with the most tools deployed. They will be the ones that understand access holistically, recognize it as a unified concept and build their security programs around that understanding. 

At the end of the day, identity is not just about systems. It is about any place where access is granted. 

And the more organizations start treating physical access the same way they treat digital access, the closer they get to closing one of the biggest gaps in security today.