
French administrations manage flows of agents, service providers, and users whose access rights vary according to the position, site, and mission. Since the gradual implementation of the NIS2 directive and the tightening of recommendations from the CNIL regarding access control to premises, IT departments in the public sector are facing dual pressure: to secure both logical and physical access while documenting each decision in an auditable manner.
Govioz positions itself in this niche by offering a platform that aims to unify these two dimensions.
Physical access and logical access: why administrations struggle to unify them
Most local authorities and public institutions still operate with siloed systems. The entry badge for premises is managed by a physical security provider, while IT authorizations depend on the HR reference framework and the Active Directory or LDAP directory.
This siloing creates blind spots. An agent transferred may retain their access badge to the old site for several weeks, and their application accounts remain active due to a lack of synchronization between the HR department and the IT department. By linking these two layers, a platform like Govioz seeks to automatically trigger the withdrawal of physical and logical access upon an agent’s departure.
The difficulty lies less in technology than in organization. Merging the reference frameworks requires that the human resources department, the IT department, and the security manager share a common vocabulary regarding access rights profiles.
Field feedback varies on this point: some local authorities report quick alignment, while others describe months of internal negotiation before stabilizing an exploitable role matrix. To delve deeper into best access practices with Govioz, one must first accept that the organizational foundation conditions technical success.

NIS2 Directive and access review: regulatory constraints for the public sector
The NIS2 directive extends its obligations to public entities operating services deemed critical, including certain local authorities and health establishments. Among the requirements, the formalization of a documented and auditable access review process occupies a central place.
The expected frequency is not uniform. Standard access (email, intranet, common business applications) calls for a quarterly review. Privileged access (administrator accounts, access to sensitive databases) requires a monthly or even continuous review, with complete traceability of decisions to maintain or withdraw access.
What traceability concretely implies
Each review cycle must produce a readable history: who validated the maintenance of access, on what date, and within what scope. In case of an audit, the administration must be able to provide this evidence without delay. Govioz offers integrated logging, but the quality of the audit depends on the rigor with which validators handle each request.
A tool that automates review reminders does not guarantee that the business manager actually examines the list of authorizations. The temptation to “validate everything in bulk” exists, and no platform can eliminate it without a clear managerial framework.
Passwordless authentication and biometrics: what the CNIL allows in administrations
Passwordless authentication, particularly via FIDO2 and WebAuthn standards, is beginning to appear in access projects within the European public sector. For agents working remotely or in user-facing roles, these protocols significantly reduce the risk of compromise through phishing.
The situation becomes more complicated when considering biometrics. The updated recommendations from the CNIL are clear on this subject:
- Non-biometric devices (badge, code, physical security key) should be favored in all cases.
- Any use of biometrics in an administration requires the completion of a mandatory data protection impact assessment (DPIA).
- The justification for using biometrics must be specific: it is not enough to invoke convenience or modernity of the device.
For a platform aiming to unify physical and logical access, this regulatory constraint weighs heavily. Integrating a fingerprint reader into a badge system connected to Govioz is technically feasible, but legally conditioned on demonstrating necessity that few administrations can produce.

Role matrix and the principle of least privilege applied to local authorities
The principle of least privilege consists of granting each agent only the rights strictly necessary for the performance of their duties. In a private company, implementation is already complex. In an administration, it faces specific peculiarities of the public sector.
Local agents frequently change missions without changing positions. An urban planning manager may temporarily be assigned to oversee public contracts, then return to their initial responsibilities. Each change of mission should trigger an update of authorizations, which requires a living link between the job description and the access reference framework.
Building an exploitable matrix
An effective role matrix for a local authority is based on a few principles:
- Start from actual business processes, not the formal organizational chart, which rarely reflects daily workflows.
- Define access profiles by mission (permit processing, budget management, civil status) rather than by grade or department.
- Provide for temporary profiles with an automatic expiration date for occasional missions or replacements.
- Document exceptions, as they will always exist, and submit them to a traceable hierarchical validation.
Govioz can serve as a technical support for this matrix, provided that the mapping work has been conducted in advance. Deploying the platform before stabilizing the profiles amounts to automating the existing disorder.
Access management in administrations remains a project where technology solves only part of the equation. Tools like Govioz bring structure and traceability, but the robustness of the system relies on internal governance and review discipline. The local authorities that make the most progress are those that treat the issue of authorizations as a general management topic, not as an isolated IT project.