What survives the audit


An auditor is sitting across from you. Not the fire inspector and not the insurer. The one who decides whether your site still meets the standard it is held to. She has one question, and she will ask it in a dozen forms until she is satisfied. Show me who could open the door that matters most on your site, when they could open it, under which rule, and who signed it off. Then show me how that changed over the last eighteen months.

In the first issue I argued that identity is settled. Okta and Workday took that ground a decade ago, and the access industry was never in the room. The argument has moved on, and this is where it has moved. Not to who someone is. To what survives the audit.

A serious access system has to do two things the auditor cares about, and they pull in different directions. It has to keep the right access in place while nothing visible is happening. No incident, no alarm, nobody watching. The contractor’s access ends when her contract ends, whether or not anyone remembers. And it has to leave evidence that still makes sense eighteen months later, when the people who made the decisions have moved on and the record is all that is left.

Neither of those lives in identity. Identity knows who the contractor is. It does not know which three keys are still in her drawer, which doors they open, or that one of them should have come back in March. It does not hold the rule. It does not hold the proof.

Your day is made of small movements. Someone joins, someone shifts between buildings, someone leaves, a contractor needs a key for a week, a manager approves an exception over the phone because the rule is inconvenient at four in the afternoon. Each one is minor. None of them feels like the thing an auditor will fix on. The auditor’s day is the opposite. She is not interested in the thousand small movements. She is interested in the one that should not have happened, or the one you cannot prove was meant to.

This is the layer the industry keeps walking past. Identity says who someone is. The layer underneath says what should have happened, and then proves what did. Schedules, zones, time limits, the rule that says this role opens these doors in these hours and no others. The record of who held which key, who signed for it, and when it came back. The HR system does not carry it. The lock cannot keep it. This is the layer that holds the rule and keeps the proof, and the only place the auditor’s question can actually be answered.

There is a comfortable answer to all of this, and it is the wrong one. It is a better cylinder. A smarter lock, a mechatronic core, a digital key you can switch off from a screen. Useful hardware, all of it. But a serious site is not made safe by a cleverer lock on the door. It is made safe by the layer that knew the door should open to three people last March, can show exactly those three held the keys, and records the day the fourth was taken off the list. KRITIS is not a hardware problem. It never was.

This is the part of the system that stays invisible while the work goes well, and the only part that matters the moment someone asks you to prove it.

None of the daily work disappears. Keys move, people leave, approvals get made on the spot. The right layer does not stop any of that. It records it, holds it against the rule, and keeps the answer ready for the day it is asked for. The cylinder does what it is told. The audit asks who told it, and why.


Subscribe to portier Letters