Mobile Access Is Identity Infrastructure W/ Guest Host SecuriTEA's Xander Alexander
In this episode of The Inside Track, Phil Coppola sits down with Xander Alexander from SecuriTEA for a practical conversation about mobile access, identity, and the changing role of physical security in the enterprise.
Mobile access is often introduced as a convenience story. Tap your phone. Tap your watch. Open the door. But the bigger conversation is about identity, trust, and how physical security can align with the same security models already being used across IT and cybersecurity.
Phil and Xander explore why the traditional plastic badge is largely a possession-based model. A card can show that someone has something, but it does not necessarily prove they are the person authorized to use it. Mobile credentials create an opportunity to move beyond simple possession by connecting access to a validated user identity, a trusted device, and enterprise authentication methods such as single sign-on and multi-factor authentication.
The conversation also digs into one of the most important areas of mobile access security: provisioning. Once a credential is securely issued to a phone, it can be extremely strong. But how that credential gets to the right person matters. Invitation codes, email-based enrollment, SSO, MFA, automated provisioning, device trust, and lifecycle management all play a role in building a stronger credentialing model.
Phil and Xander also discuss the convergence of physical security, IT, OT, and cybersecurity, and why security teams can no longer afford to operate in silos. As threats evolve, access control leaders need to think differently about how credentials are issued, managed, revoked, and governed.
If your organization is evaluating mobile access, planning a migration away from physical cards, or trying to better align physical security with enterprise identity strategy, this episode offers a grounded look at the risks, misconceptions, and best practices that should shape the conversation.
Topics include:
Mobile credentials versus physical cards
Identity validation and device trust
Why possession is not the same as identity
Secure credential provisioning
SSO and MFA for physical access
Visitor badge and lost card risk
Automated provisioning and lifecycle management
Revocation and governance
Convergence between IT, OT, cyber, and physical security
Why mobile access is more than convenience