A plan view of a shared facility where the building and data hall are common to every tenant and only the cage and the cabinets inside it are restricted, with who can reach each layer

Cage or Rack-Level Restriction

Back to Data Center Management · Badge or Biometric Access · Access Logging · Visitor and Vendor Tracking · Service Offerings

This is in shared facilities, limiting access to your own footprint specifically. The reason it needs saying separately is that a colocation provider's security is genuinely good — and almost all of it protects the building, which you share with every other tenant, their staff, and their vendors.

1. Facility Access Is Not Equipment Access

The provider's perimeter, guards, mantraps and cameras keep out people who have no business in the building. They do not distinguish between you and the twelve other organisations who legitimately have business there, and whose contractors are in the hall today with a trolley.

Access therefore has to be thought of in layers, as the illustration above sets out, with each layer answering who can reach this:

Layer Controlled by Who is inside it
BuildingThe providerEvery tenant, their staff and their vendors
Data hallThe providerTenants with equipment in that hall, plus provider staff
Your cage or suiteYou, ideallyYour access list, plus remote hands
The cabinetYouYour access list

The two bottom rows are the ones you own, and they are the ones most often left to the provider's list or to a key in a drawer.

2. A Cage Has to Be a Boundary, Not a Suggestion

3. The Cabinet Lock Is Usually the Weak Link

Cabinets ship with locks, and that is roughly where the thinking stops. Two problems, both the shared-key problem from badge access wearing different clothes:

Electronic cabinet locks with per-person credentials and their own audit trail solve both, and are worth it for cabinets holding anything regulated. Where they are not justified, at minimum use unique keys, record who holds each, and treat the key register the way you treat the access list — including collecting them from leavers.

Side panels matter as well: adjacent cabinets with shared or removed side panels are one cabinet with two doors.

4. The Provider's Own Staff

This is not a suspicion, it is a design fact: remote hands exists so that somebody who does not work for you can physically touch your equipment at three in the morning. It is a genuinely useful service and it is also the broadest standing physical access anyone has to your estate.

5. Settle It in the Contract

Several of the controls above are not things you can install. They are things you must be entitled to, and the moment to establish that is before signing rather than during an incident.

6. It Applies in Your Own Building Too

The same argument holds in a server room you own, with the tenants replaced by your own colleagues. Everyone with a reason to enter the room does not necessarily have a reason to open every cabinet — particularly where one holds systems in scope for an audit and the others do not. A locked cabinet inside a controlled room is the cheapest way to make that distinction real.

How We Approach It

  1. Establish who can reach each layer today, including the provider's staff and every tenant's vendors, and write it out as the table above.
  2. Inspect the physical boundary: above the ceiling, below the floor, the mesh, the panel fixings, the side panels.
  3. Check the cabinet locks, including whether they are keyed alike, and who holds keys.
  4. Put your own reader and record at the cage, so your audit trail does not depend on a third party.
  5. Scope and log remote hands, and decide which cabinets it may open.
  6. Close the contractual gaps, including the complementary user entity controls the provider's report assumes you operate.

What You Get

The question that makes this concrete: if someone opened one of your cabinets last night, would you find out, and would anybody be able to tell you who it was?