July 16, 2026
Extending SailPoint Identity Governance to Physical Access: One Framework for Every Access Point
More than 3,100 enterprises run identity governance on SailPoint. They have invested in identity lifecycle workflows, access certification programs, governance policies, compliance reporting, and role-based access controls. They can answer, in minutes, who has access to SAP, who approved it, and when it was last reviewed.
Ask the same questions about the data center door, and the answer usually lives in a badge system nobody has certified in years.
This guide covers how SailPoint customers extend the governance program they already have – certifications, reviews, lifecycle policy – to physical access, using the certified Alert Enterprise Guardian for SailPoint integration.
01
SailPoint Identity Governance Stops at the Digital Perimeter
A mature SailPoint identity governance program governs applications, cloud infrastructure, and enterprise systems with real discipline: policy-driven provisioning, scheduled certifications, separation-of-duties checks, and defensible audit evidence.
Those controls stop where the building begins. Consider the questions each side can answer:
- Who has access to Salesforce? Answered from SailPoint in minutes. Who can enter the executive floor? Answered by exporting badge records and asking around.
- Who approved SAP access? In the audit trail. Who approved building access? In an email thread, if it survives.
- When was application access last certified? Last quarter's campaign. When was badge access last certified? For most organizations, the honest answer is never.
Badge systems were never built for governance; they enforce decisions at the door. So physical access is provisioned at a front desk, reviewed when something goes wrong, and revoked on a timeline nobody audits. As identity programs mature, this inconsistency becomes harder to justify: the same identity, the same risk, and two entirely different standards of control.
What governance actually requires – certification, separation of duties, attestation – is covered in our guide to identity governance. This post covers extending those disciplines past the digital perimeter.
02
Unified Identity Governance, Briefly
Unified identity governance is the practice of governing both digital and physical access through a single identity-centric framework. Traditional identity governance covers applications, SaaS platforms, cloud environments, databases, and enterprise systems. Unified identity governance extends the same lifecycle controls, policies, certifications, and compliance processes to corporate facilities, data centers, restricted areas, employee badges, mobile credentials, and visitor access.
For SailPoint customers, the appeal is straightforward: the governance investment already made extends to access it previously could not see.
03
The Layer That Makes It Possible: PIAM
Physical Identity and Access Management (PIAM) is the discipline that brings physical access under identity governance. It manages physical identities, credentials, and facility access through the same lifecycle and policy processes used for digital access, provisioning, deprovisioning, role-based control, certification, and reporting.
The distinction that matters: a physical access control system (PACS) answers “can this badge open this door?” while PIAM answers “should this person have access, who approved it, and is it still appropriate?”
04
The Physical Gap in Certification and Review
Access Certification That Includes Every Door
An access certification campaign that covers Salesforce entitlements but not data center badge access certifies half the risk. With physical entitlements visible inside SailPoint, managers and area owners certify facility access in the same campaign as application access, with a single evidence trail behind both.
Just as important, revocations execute automatically. When a reviewer decertifies badge access, the credential is adjusted at the PACS layer without a ticket to the security office – closing the loop that manual physical reviews leave open.
User Access Reviews Beyond Applications
User access reviews exist to catch access that has outlived its justification, and physical access outlives its justification more often than digital. The contractor whose engagement ended a quarter ago still holds an active badge. The employee who transferred departments keeps access to the previous unit. The vendor technician retains data center access from a project that closed last year.
Bringing physical entitlements into SailPoint access reviews surfaces exactly this class of risk and puts it in front of the manager or area owner, who has the context to judge it.
Access Recertification on a Continuous Cadence
High-sensitivity areas like data centers, laboratories, and executive floors warrant access recertification on a shorter cycle than the annual campaign. The integration supports recertification scheduled by area sensitivity, role, or compliance framework, with attestation evidence generated in real time and available before any audit requests it.
Separation of Duties Across Both Domains
Some access conflicts only become visible when both domains are in view: the finance employee with payment system access who also holds unsupervised access to the records vault, or the contractor who can approve their own facility access. Policy rules spanning digital and physical access catch these conflicts at the moment of request, before they become audit findings.
05
How the SailPoint Integration Works
Guardian connects SailPoint to the physical access control systems a facility already runs. SailPoint remains the system of record for identity; Guardian translates governance decisions into the badge and door layer, across PACS from multiple vendors.
The SailPoint integration works with SailPoint Identity Security Cloud and IdentityIQ. Access requests, approvals, and certifications flow through the SailPoint interfaces teams already use, so there is no new console to learn and no parallel approval chain. In practice:
- Physical access provisioning and revocation tied to SailPoint identity lifecycle events
- Physical entitlements visible in SailPoint certification campaigns and access reviews
- Separation-of-duties policies enforced across digital and physical access
- One audit trail covering every access decision in both domains
06
What Extending Governance Delivers
Stronger Security
Governance gaps between domains close. Least-privilege is enforced consistently across every access point, and the lingering physical access that manual processes accumulate disappears.
Improved Compliance
Regulators and auditors increasingly expect governance evidence across all forms of access. Audit preparation draws on one evidence base instead of four systems, and certification records cover the facility alongside the application.
Greater Operational Efficiency
Automated provisioning, deprovisioning, and certifications replace the manual reconciliation between HR, IT, and the badge office. Work that previously required tickets and follow-up now executes through policy.
Better Visibility
One view of who has access to what, applications and facilities, employees and contractors, supports faster investigations, better decisions, and unified access management across the enterprise.
07
Where to Start
Three practical first steps for SailPoint customers:
- Standardize physical access policies first. The identity governance framework enforces the policies you define - approval workflows, badge issuance, revocation protocols. So define them before automating them.
- Start with the highest-sensitivity areas. Run one certification campaign that includes physical access to the data center or the pharmacy. The stale access it flags will make the internal case for expanding the program.
- Expand from certification to lifecycle. Once reviews cover physical access, tie provisioning and revocation to the same SailPoint lifecycle events closing the gap at both ends.
09
Frequently Asked Questions
Can SailPoint govern physical access natively?
No. SailPoint governs digital access. Physical access is brought under SailPoint governance through certified integrations such as Alert Enterprise Guardian for SailPoint.
What does a physical access certification include?
The facilities, restricted areas, and credentials each identity holds, presented for review alongside application entitlements, with automated revocation of anything decertified.
Does this replace our access control system?
No. Guardian governs across the PACS a facility already runs. PACS enforces at the door; governance happens in the layer above.
Which SailPoint products does the integration support?
SailPoint Identity Security Cloud and IdentityIQ.
How is this different from a custom integration?
Certified status means the SailPoint integration is tested and validated by SailPoint, published in the Connector Directory, and maintained against current releases. Organizations avoid building and supporting a one-off integration themselves.