Insights

Access control is worth what the review of its rights is worth

Badges are issued in minutes and withdrawn rarely. After three years the list of authorised people no longer describes the organisation it is meant to protect.

Badge reader at the entrance to a restricted area — editorial context image, unrelated to any site protected by the group.

An access control system is judged on its ability to refuse entry to those who have no right to it. It performs that faithfully: it applies the list it was given. The useful question therefore concerns that list, and the date it was last verified.

How a list drifts

Granting a right answers an immediate need and is done quickly. A contractor works three weeks in a plant room, a member of staff changes department, someone covers for an absent colleague. Each of those situations produces an authorisation that is legitimate at the moment it is granted.

Withdrawal answers no immediate need. Nobody is inconvenienced by a right that persists. It appears in no procedure, it triggers no alert, and it outlives the departure of the person who requested it as surely as that of the person who granted it.

Three years are enough for a significant share of a site’s authorisations to correspond to nobody identifiable, or to people who no longer work there.

The four events that must trigger a withdrawal

The departure of an employee, which is handled in most organisations. The end of a contractor’s assignment, which is handled considerably less often. An internal transfer, where the new right is added to the old instead of replacing it. And the end of a temporary cover, which by its nature carries no end date in the system.

Tying each of those events to an automatic withdrawal assumes the access control system holds an end date. Entering that date at the point of granting takes seconds; reconstructing it two years later takes an investigation.

The periodic review

The review consists of presenting the person accountable for each zone with the list of people who have access to it, and asking them to approve it line by line. It runs twice a year on sensitive zones and once a year on the rest.

Its value does not lie in the rights it withdraws, which are few in a well-kept organisation. It lies in what it makes visible: a zone nobody claims accountability for, a contractor with no live contract, a door the list protects while it is propped open during the day.

What the log has to make possible

An access log exists to answer a question asked after the fact: who entered this room between these two times? It answers only if three conditions hold. The retention period exceeds the usual delay in discovering an incident, which is counted in weeks rather than days. The timestamp is reliable, which assumes verified synchronisation. And consultation is itself logged, failing which the audit facility is not audited.

What to require

A mandatory end date on every temporary authorisation. Withdrawal tied to the four events, written into the procedure rather than left to initiative. A periodic review whose minutes are signed by the person accountable for the zone. And an annual test: ask the system for the list of people with access to the most sensitive zone on the site, and check that every name on it can be justified.

Consultations · Pre-qualifications · Partnerships

Let’s discuss your project.

Describe your priority, its operating context and the intended outcome. We will route the enquiry to the right person.