From Identity to the Door: Entering Identity-Driven Physical Access

Share article

Physical access has traditionally been managed separately from digital identity. IT manages employees, accounts, groups and organisational roles, while security and facilities teams manage doors, credentials and access permissions. These systems often contain overlapping information about the same people, but they do not always work together. This creates administrative work and security risks, particularly when employees join, change roles or leave an organisation.

Key takeaways

Reading time: 4 minutes

  • Physical access should reflect who someone actually is in the organisation, their department, role, location, employment status and group membership, not a separate list an admin keeps in sync by hand.
  • Smart MasterKey sits between your organisational identity system and your existing door hardware, using enterprise SSO, MFA and SCIM so access updates automatically when someone joins, changes role or leaves.
  • Because access follows identity-based policies, permissions adjust the moment someone’s role or status changes. People gain access when they need it and lose it the moment they don’t need it, and none of your current physical infrastructure needs to be replaced.

Physical access should understand organisational identity

An employee’s physical access should reflect their role within the organisation. Department, role, location, employment status and group membership can provide the context needed to determine which buildings, floors, rooms or restricted areas someone should access.

In the traditional model, physical access becomes another user database that administrators must maintain. In an identity-driven model, physical access connects to the organisational information that already defines who a person is and what they are responsible for.

Where Smart MasterKey fits

Smart MasterKey sits between organisational identity and the underlying physical access infrastructure. It connects modern identity and access governance with existing physical security systems without requiring organisations to replace their current infrastructure.

Corporate identity remains responsible for digital identity and organisational information. The physical access system remains responsible for controlling doors and access points. Smart MasterKey connects these environments and applies the relevant physical access policies.

It’s time to get more from your building operations

Experience modern property management with Smart MasterKey. See how leading commercial real estate teams boost efficiency, streamline operations, and maximise performance using our platform.

Enterprise SSO and MFA

Single Sign-On, or SSO, allows users to authenticate using their existing corporate identity. Smart MasterKey supports any SAML or OIDC identity provider through a single integration. This allows organisations to retain their existing authentication environment instead of creating another isolated identity system.

Multi-Factor Authentication, or MFA, adds another layer of protection, particularly for administrators who can create users, change permissions or modify access policies. SSO and MFA protect access to the management environment, while physical credentials such as mobile credentials, PINs and RFID control access to the physical environment.

SCIM connects identity with the employee lifecycle

System for Cross-domain Identity Management, or SCIM, provides a standard way for identity systems and applications to exchange user lifecycle information. Smart MasterKey supports SCIM provisioning with Okta, Microsoft Entra ID, ADFS and other compatible identity providers and directories.

This connects physical access with the employee lifecycle. When an employee joins, their corporate identity can be provisioned into Smart MasterKey and physical access assigned according to organisational policies. When they change department, location or role, synchronised identity information can provide the foundation for updating their permissions. When they leave, their identity can be deprovisioned and their physical access and credentials revoked according to policy.

Identity-based access policies

Identity-driven access becomes particularly useful when organisations operate multiple buildings, departments and access zones. Physical permissions can connect to identities, roles and groups instead of being managed individually for every person.

A finance employee can receive access to finance areas, while an employee assigned to a specific office receives access to that building. A facility manager can manage access for the buildings they are responsible for, while a contractor can receive access to a specific location for a defined period. When an employee leaves, their physical access can be removed as part of the deprovisioning process.

Role-based administration also separates what someone can manage from where they can physically enter. A tenant administrator can manage their organisation’s users without controlling another tenant, while an ordinary employee can have physical access without receiving administrative permissions.

The direction of physical access

Physical access should reflect the same organisational reality as digital access. When someone joins, their physical access should be provisioned according to their role. When they change department or location, their access should change with them. When they leave, their physical access should be revoked.

Smart MasterKey connects corporate identity, access governance and physical access while allowing organisations to continue using their existing access-control infrastructure. The result is a physical access environment that responds to the organisation as it exists today, rather than relying on permissions created months or years ago.

Related Articles