BlogEvaluation guide

How to Evaluate GPU-Pod Physical Access, Badge Control, and Visitor Logs

An ISSM’s checklist for deciding whether a secured building actually provides a defensible physical boundary around an on-prem GPU pod.

Consider a hypothetical pilot walkthrough: the GPU pod sits behind a locked server-room door. The facilities manager demonstrates the badge reader. Everyone initially marks physical security “covered.”

Then the evaluator asks who else can open that door. The answer includes cleaners, landlord technicians, and a maintenance contractor using a shared credential. Visitor records live at reception, but nobody records which visitors enter the server room. Badge events disappear before the planned evidence review.

The building has security. The pod’s physical access boundary remains unproven.

For a CUI/ITAR pilot, evaluate who can reach the hardware, under what authorization, and with what evidence afterward. Physical protection supports a defined CUI boundary; a locked room alone does not establish that boundary or resolve export-control obligations.

1. Draw the boundary people can actually cross

Ask the ISSM, facilities owner, and pod operator to mark the physical perimeter on a floor plan. Identify the room or cage, racks, service entrances, emergency exits, and any shared pathways.

Then walk the route from the street to the hardware. Test the explanation against reality:

  • Does a building badge also unlock the pod room?
  • Can adjacent tenants or general maintenance staff reach exposed equipment?
  • Are rack doors locked where the room is shared?
  • Who controls spare keys, mechanical overrides, and emergency access?
  • Can someone enter through an unmonitored service door?

Record each access point, its control, its owner, and the evidence it produces. A lobby visitor desk is not proof that access to the pod is controlled.

Use Pacific Intelligent Technologies, Inc.’s CMMC evaluation context to frame the discussion, not as evidence that a particular deployment is certified or compliant.

2. Evaluate badge permissions, not just badge readers

A working reader proves a door can accept credentials. It does not prove the right people hold them.

Request a dated export of authorized badge holders for the pod perimeter. Reconcile it with approved roles, employment or contractor status, access hours, and expiration dates. Include facilities personnel and emergency responders where applicable.

Look for named credentials rather than shared badges. Ask who approves additions, who periodically reviews access, and how departures or role changes trigger revocation. Inspect a recent revocation record and verify that the credential stopped working at every relevant door.

Also examine lost-badge handling, temporary credentials, tailgating prevention, and the distinction between denied attempts and successful entries.

For ITAR-related work, counsel should determine applicable authorization and access restrictions, including any nationality-related considerations. Neither possession of a badge nor a generic background check establishes export authorization.

3. Make visitor and remote-hands access reconstructable

Visitor logs should connect a person to a purpose, sponsor, authorized area, and visit window. Ask whether records distinguish entering the building from entering the pod room.

A useful sample includes identity verification, badge issuance and return, check-in and checkout, escort assignment, and the work authorization associated with the visit. Collect only the personal information needed under the organization’s policy.

Escort rules need operational detail:

  • Who may escort, and how is that authority approved?
  • Must the escort remain with the visitor throughout the visit?
  • What happens during shift changes or an interrupted service task?
  • Who stops work when a visitor exceeds the approved scope?

Remote hands means a person touching equipment on-site, even when instructions arrive remotely. Inspect how that person’s entry and physical task are authorized, supervised, and closed out. A support ticket should not silently become permission to open every rack.

Physical entry authorization is separate from logical administrator access; neither substitutes for the other.

4. Test retention and tamper evidence together

Ask for a sample evidence chain: an approved maintenance visit, its visitor record, relevant badge events, escort confirmation, and any rack-opening or tamper inspection record.

Can the evaluator reconstruct who entered, what they were permitted to touch, and when they left?

Confirm:

  • Retention: The documented period covers applicable requirements and the buyer’s investigation and assessment needs.
  • Retrieval: Records remain exportable after vendor changes, staff turnover, or subscription expiration.
  • Integrity: Permissions restrict alteration or deletion, with changes traceable.
  • Correlation: Door names, badge identities, timestamps, and time zones are understandable across records.

There is no universal retention period to invent for this checklist. Have the ISSM and counsel establish the applicable requirement and verify actual system settings against it.

Tamper-evident seals, rack sensors, or documented inspections can supplement access controls. Evaluate identifiers, baseline photographs where permitted, inspection frequency, and response ownership. A broken seal is useful only if someone detects, records, and investigates it. Review Pacific’s security information alongside deployment-specific evidence.

5. Turn findings into a pilot decision

Produce a short decision record: perimeter diagram, access roster, visitor sample, retention settings, unresolved exceptions, and named owners.

Separate “demonstrated,” “not demonstrated,” and “requires remediation.” For material gaps, specify whether the pilot must exclude CUI or controlled technical data until the ISSM and counsel approve proceeding. Do not convert “building security exists” into a green check.

Bring that record to a 30-minute evaluation discussion with Pacific Intelligent Technologies, Inc.. Use the Pacific platform overview for deployment context; keep the acceptance decision tied to your actual site.

FAQ

Does a locked server room make a pod CMMC-scoped?

No. Scope follows the assessed environment and how CUI is handled. Physical controls are one part of that evaluation. Start with Pacific’s CMMC context.

Can reception logs replace pod-door records?

Not when they cannot establish access to the protected area. Evaluate whether the combined records reconstruct entry at the relevant perimeter.

Are cameras or tamper seals enough?

No. They supplement authorization, access control, and response procedures. Compare Pacific’s security information with evidence from the proposed room or cage.

Continue on the mothership

This satellite stops at the playbook. Transactions, specs, and comparisons live on pacificmachines.com. If the next step is a human, book 30 minutes with Harper.

Book 30 min