Skip to main content
the-letter-A
Articles / Press

How to Audit Physical Access Across Multiple Locations

Who can enter your server room right now? If answering that takes three exports, two office managers, and a guess about whether an old badge still works, you have a reason to run a physical access audit.

The audit should answer a practical question: do current permissions still match current business need? At several locations, the answer can change quietly. A person transfers, a contractor gets extended, a project ends, and access that was once appropriate keeps working.

You don’t have to inspect every badge swipe to find the problem. Start with the people and credentials that are active, trace what they can open and when, then give each questionable permission an owner and a decision. Here is a way to do that without handing managers a 5,000-row spreadsheet.

Physical access audit dashboard showing permissions across multiple sites beside a door reader

What does a physical access audit actually review?

A physical access audit compares the people in your access control platform with a trusted employment or contractor source. It checks active credentials, access groups, doors, schedules, exceptions, and the administrators who can change those settings. It also tests whether a recorded permission matches what happens at the opening.

That last part matters. A clean cardholder list cannot tell you that a lobby is scheduled unlocked all weekend or that a warehouse door rarely latches. The permission review is the core of the audit, but a few targeted door and event checks show whether the system behaves the way the records imply.

Decide the scope before exporting data. Are you reviewing every site, a newly acquired region, or a set of sensitive openings? Which HR or identity system is the source of truth? Who will approve findings? A clear scope makes it possible to finish the review and show what changed.

How does a physical access audit find stale users?

Begin with the active identities in the access control system. Compare employee records with the current HR or enterprise identity roster. Compare contractors with their sponsor and approved end date. Investigate a former employee who remains active, a person with no current manager, a duplicate cardholder, or someone whose site no longer matches their job.

Don’t assume every mismatch is an error. A traveling employee may have a legitimate second location. A contractor may have a documented extension. The question is whether a current owner can explain the permission and show when it will be reviewed again. “Someone probably needs it” isn’t an approval.

If you use automated provisioning, this comparison is still useful. A connector can fail, an exception can bypass the normal flow, and old records can predate the integration. Our employee access lifecycle guide explains how routine changes should reach the system. The audit checks whether they actually did.

Why does a physical access audit check credentials separately?

One person can have several credentials: a physical card, a replacement card, a fob, and perhaps a mobile credential on a phone. Deactivating a user and revoking a credential are related actions, but your report should show both states. A lost badge that still works is a different finding from an active user with the wrong access group.

Look for two active cards where policy expects one, a replacement that left the old card valid, a mobile credential on a retired device, or a temporary credential with no end date. Check the platform’s actual status and test a sample at the door when the records are ambiguous.

This is also where a multi-site team benefits from a central view. You should be able to see the person’s credentials and site permissions together rather than calling each location to learn which badge they issued. If local systems can’t provide that view, document the limitation as part of the audit.

What should you look for in access groups?

A physical access audit should review group definitions before asking every manager to approve every cardholder. Most enterprise platforms grant door permissions through groups, levels, or roles. For each group, identify its purpose, doors, schedule, eligible population, membership approver, and owner. A group called “Warehouse Supervisors” should mean the same thing at the sites where it is used.

Names like “Special Access 3” are a warning. So are groups created for an old renovation, a former executive, or a department that no longer exists. Check whether they still have users, whether the doors still exist, and what might break if the group changes. Retire unused groups deliberately after confirming their dependencies.

Then compare each person’s current role and location with their memberships. Transfers often add access and fail to remove the old doors. A facilities employee who moves to Finance may still be in the maintenance group. The audit should find those inherited permissions and send them to the right owner for a decision.

How should cross-site and sensitive access be reviewed?

A physical access audit should make cross-site permissions visible. Central management makes it easy to give someone access across locations, but that convenience needs a rule. Does a regional manager need every site in their region? Does a traveling employee need permanent access to a second office? Should an IT technician enter every server room or request access for a specific visit? The answer depends on your operating model, but the current permissions should reflect an explicit answer.

Give sensitive openings a closer review. A server room, security office, cash room, lab, or high-value inventory area may need a named business owner, a narrower schedule, an expiration date, and a more frequent review. Ask who approved each person’s access and whether that reason still holds. Don’t assume a general employee access sign-off covers these doors.

Look at the schedule as well as the door. A warehouse supervisor may need the loading area during a shift, but 24-hour access could be broader than the job requires. Review holiday and weekend schedules too. A door that is scheduled unlocked ignores the badge permissions during that period, so include public and employee entrances in a targeted schedule check.

Who can change access, and does that authority still fit?

A physical access audit also needs a pass through administrator rights. A site administrator can grant permissions that a cardholder can only use. Review global and regional administrators, help desk roles, vendor support accounts, dormant accounts, and any shared logins. Confirm that each person still has the job and the right scope, and that the system logs changes.

Use individual accounts and multifactor authentication where the platform supports them. Limit vendor access to the support work it requires and review how it is enabled and removed. IT should also know how the access platform and any cloud connection reach the network. Alen’s approach avoids unnecessary open ports and firewall holes; a useful audit includes who owns that secure path and its support access.

Administrator review is not a separate cybersecurity exercise to leave for another year. If a former local manager can still create cards or change schedules, the door-permission report is only part of the picture.

How does a physical access audit handle contractors and exceptions?

Each contractor needs a sponsor who can say why the person still needs access. Confirm the company, approved site, schedule, access profile, start date, and end date. A long-running contractor with no sponsor or expiration is a data problem before it is an automation problem.

Look for temporary project access that became permanent after a move, renovation, inventory count, or special assignment. If the system can expire it automatically, use that ability. If it cannot, assign a review date to a person. An exception without an owner will be difficult to justify six months later.

Record the reason, approver, doors, schedule, and end or review date when granting unusual access. That small amount of discipline makes the next audit faster. It also helps the service team distinguish an intentional exception from a configuration mistake.

Should the audit include offboarding and door behavior?

Yes. A physical access audit should sample a few recent departures and trace the real sequence: when HR recorded the departure, when enterprise identity changed, when the team disabled the cardholder and each credential, and when the local controller received the update. If a site was offline, find out how the team handled the pending change. A policy that says “immediate removal” is only meaningful if the workflow can meet it.

Then review a sample of recurring forced-door, held-open, reader-offline, and controller-offline events. Repeated alarms may point to a closer, door hardware, a propped opening, or a bad configuration. The audit is not a full mechanical survey, but it should not declare an opening secure because the access list is tidy while the door never latches.

Video can help clarify a persistent alarm at a priority opening when the platforms are connected. Our access control and video guide covers that investigation workflow. In this audit, the question is whether the permission and the physical opening tell the same story.

What should a physical access audit ask managers to decide?

A manager needs a review they can act on, not a raw export. Give each reviewer only the people and groups they own, with the person’s current role, site, access group, sensitive doors, schedule, expiration, and last approval. Make the decision explicit:

  1. Keep: the access still fits the current job and has a clear owner.
  2. Remove: the person no longer needs it or the credential should be disabled.
  3. Modify: change the site, doors, schedule, or expiration.
  4. Investigate: the record is incomplete or conflicts with another source.

Security should define the physical access policy and approve restricted areas. A manager can confirm business need for their team. IT can resolve identity data and integration failures. Assign one owner to each finding and capture the date the change was verified. “Reviewed” should not mean that someone merely opened the file.

Keep evidence appropriate to company policy: scope, review date, reviewer, decisions, removed permissions, retained exceptions, and unresolved items. That shows what the organization did with the findings.

How often should you run a physical access audit?

Set a cadence based on risk and company policy. Administrator roles, sensitive doors, contractors, and temporary exceptions may need a shorter cycle than ordinary employee entrances. A new acquisition or major reorganization can also justify an extra review. The exact calendar is less important than a named owner and proof that decisions were completed.

Use the first audit to learn where the time goes. Different group names at every site slow the review. When HR and cardholder records do not match, fix the identifiers. Managers who repeatedly approve the same temporary access need a better approval or expiration rule. Our multi-site access control standardization guide covers the shared naming and operating rules that make the next review easier.

What happens after you find a problem?

A physical access audit should turn each finding into work with an owner and target date. Remove clearly unauthorized access promptly through the approved process. Ask a business owner to resolve uncertain permissions. Correct source data when the problem began in HR or identity. Redesign an oversized group when one permission keeps causing the same exceptions.

Look across sites for patterns. If ten offices retain access for former employees, the real issue may be the departure workflow. If an acquired region has entirely different group definitions, the organization needs a governance decision before mass changes. An audit earns its value when it fixes the cause as well as the individual record.

Close the loop by verifying the system change and, for a sample of high-risk doors, the actual behavior at the reader. Give the central team one documented service path for issues that span identity, network, controller, and door hardware. That is how the review becomes a repeatable process instead of an annual spreadsheet exercise.

Frequently asked questions

How do I find former employees who still have badge access?

Compare active cardholders and credentials with the current HR or enterprise identity roster. Investigate mismatches, then confirm both the person and every credential are disabled. Trace a sample of recent departures to test whether the normal process worked.

How often should badge access be reviewed?

Choose the cadence by risk and policy. Sensitive doors, administrators, contractors, and temporary access commonly need closer attention than standard employee entrances. Name a reviewer and track the decisions through verified changes.

Should managers approve physical access?

Managers can confirm a person’s business need. Security should own the door policy and restricted-area rules. A sensitive opening may have a separate business owner. Record who approved the exception and when it expires or returns for review.

Should temporary access expire automatically?

Use platform expiration when it supports the approved workflow. Otherwise give the permission a named owner and review date. Do not leave project access active simply because someone might need it again.

Does the audit include the actual doors?

The main review covers identities and permissions. Sample door schedules, recurring alarms, and physical behavior at priority openings as well. A correct access group does not compensate for an unlocked schedule or a door that fails to latch.

Get an answer you can trust

The next time someone asks who can enter the server room, your team should be able to answer with a current record, a reason, and an owner. Start with one sensitive area and one representative site. Prove the method, then extend it across the portfolio.

Alen Security can review your access groups, credentials, administration, and door behavior, then help your IT and Security teams turn the findings into a manageable plan. Schedule a physical access review conversation with Alen to see where to start.