Walk into most enterprises and you will find a privileged-access program with real discipline: vaulted credentials, session recording, approval workflows, quarterly reviews. Then walk to the facilities office and ask who can open the network closet, the mechanical room, or the data hall. The answer usually lives in a different system, managed by a different team, reviewed on a different schedule, if it is reviewed at all.
This split is historical, not logical. Physical access to infrastructure is privileged access. A person in front of an unlocked rack does not need to defeat the PAM platform; consoles, management ports, and the ability to add or remove hardware are simply there. Conversely, digital privilege increasingly confers physical capability: the account that administers the badge platform or the building-management system can produce open doors, disabled cameras, and altered environmental controls without touching a lock.
Where the seams show
A few patterns recur in converged environments. Badge systems and their databases administered by a vendor whose remote access is not in any privileged-access inventory. Data-hall access lists that grow through exceptions, escort policies that quietly stop being enforced on night shifts, and departed contractors whose badges deactivate but whose VPN accounts do not, or the reverse. Camera and access-control servers that sit on flat networks a compromised workstation can reach. Mechanical spaces treated as low-security because they hold “no data,” even though they hold the switching that all the data crosses.
Each of these is unremarkable on its own. Chained, they are an attack path: digital compromise producing physical entry, or fifteen minutes of physical presence producing durable digital persistence.
One review, one owner, one model
The corrective is not a new platform. It is a decision to model privilege as one thing regardless of whether it is exercised through a keyboard or a door. Practically, that means a single inventory of who and what can affect critical systems, spanning admin accounts, service identities, badges, keys, and vendor site access. It means joint reviews where facilities and IT retire access together, so departures and contract ends close every path at once. It means the badge platform, camera estate, and building controls are treated as tier-one systems with the same segmentation, patching, and monitoring expectations as any other infrastructure that can stop the business.
Most organizations discover, the first time they build the combined inventory, that the two access worlds disagree about who still belongs. That disagreement is the finding. Attackers look for exactly the people and credentials that one system remembered and the other forgot.