New Envoy Research: 44% of High-Security Workplaces Can’t Say Who Was in Their Building Yesterday
SAN FRANCISCO, Sept. 22, 2026
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
New Envoy Research: 44% of High-Security Workplaces Can’t Say Who Was in Their Building Yesterday
PR Newswire
SAN FRANCISCO, Sept. 22, 2026
Across two separate 2026 studies, Envoy finds a structural blind spot: security teams feel protected, but their systems can’t prove it – and most have already been breached
SAN FRANCISCO, Sept. 22, 2026 /PRNewswire/ — Envoy today released “The State of Physical Security & Compliance,” a new, comprehensive research report revealing that most organizations have no single, persistent identity for the visitors and contractors moving through their buildings — and that most have already experienced a real physical security incident despite high confidence in their programs.

The findings draw on two separate 2026 studies that interviewed 782 enterprise compliance leaders and 294 leaders at frontier AI labs, defense-tech firms, and biotech/medical R&D sites – the organizations with the most to protect.
The research shows a wide gap between confidence and coverage. 44% of leaders at high-security workplaces say they cannot confidently state who was in their building yesterday. 79% report at least one unauthorized or unverified person in a workspace where they shouldn’t be in the past year. Across both studies, 71–72% give contractors no single identity that follows them across locations. And despite that exposure, 62% say they’re confident they’d pass a compliance audit today with no preparation.
The confidence is real. The coverage is not.
The numbers tell a consistent story across both studies:
- 44% of leaders at high-security workplaces can’t confidently say who was in their building yesterday
- 79% report at least one unauthorized or unverified person in a workspace where they shouldn’t be in the past year
- 71-72% give contractors no single identity that follows them across locations
- Yet 62% are very confident they’d pass a compliance audit today with zero preparation
That confidence gap holds even as security programs mature. In the sensitive-workplace study, 58% of leaders believe their program would stop an unauthorized person from entering, yet only 52% have badge control on sensitive doors and just 47% escort visitors at all times. In the separate enterprise compliance study, audit confidence peaks at single-site organizations (71% very confident), but drops to 58% the moment a second site enters the picture — the exact point where identity stops following a person from building to building.
No industry has solved it
The gap widens further by industry. Healthcare organizations give contractors a single identity across sites only 22% of the time; manufacturing, 26%. Financial services (31%) and technology (30%) fare modestly better, but no industry clears even one in three. Scale doesn’t fix it either: even organizations with 20+ sites still fail to give most contractors a persistent identity, at just 32%.
The stakes: what’s actually on the line
For leaders protecting the most sensitive work in the country, the exposure is direct:
- AI models and training data top the list of intellectual property they fear losing (18%), narrowly ahead of client data (17%) and proprietary research (16%)
- 39% have personally seen a visitor or contractor reach a restricted area
- 28% have seen someone view or photograph work-in-progress on whiteboards, screens, or prototypes
- 67% are concerned about intentional insider exposure and 66% about unsupervised contractors — the exact threats current controls handle worst
“In our facilities, we’re not just protecting a building but protecting technology that has national security implications,” says Tim Carr, Senior Security Manager at Attalon, one of more than 16,000 workplaces that use Envoy to support security and compliance. “Knowing exactly who’s on-site at any given moment, and being able to prove it after the fact, isn’t a compliance checkbox for us, it’s core to how we operate. This research confirms what we see every day: confidence in a security program means nothing if you can’t actually account for who came through the door.”
To read “The State of Physical Security & Compliance” in its entirety, visit envoy.com.
Want to dig deeper into the findings? Join Envoy on October 7 for a live webinar as they unpack the research and what it means for physical security and compliance.

About Envoy
Envoy protects the places the world relies on most by unifying people, spaces, and communications in one secure, integrated workplace and security management platform and ecosystem. More than 16,000 workplaces around the world trust Envoy to run secure, compliant, and connected operations across every location.
From manufacturing sites and data centers to life sciences labs, healthcare facilities, and corporate headquarters, Envoy unifies visitor management, risk assessment, mailroom management, digital signage software, resource booking, and emergency management into one integrated platform.
With deep integrations across access control, identity, compliance screening, and collaboration tools — including LenelS2, Brivo, Genetec, Honeywell, Cisco Meraki, Okta, Microsoft Azure, Microsoft Teams, Slack, ServiceNow, DocuSign, Avigilon Alta, and Descartes Visual Compliance — Envoy helps organizations reduce risk, stay audit-ready, and operate with clarity at scale.
Learn more at envoy.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-envoy-research-44-of-high-security-workplaces-cant-say-who-was-in-their-building-yesterday-302885878.html
SOURCE Envoy

