Field Notes

Not All Building Data Is Highly Sensitive

Jul 27, 2026 / 5 min read

ClimaMind Editorial / Updated Jul 27, 2026 / reviewed for technical accuracy.

Building owner approving a controlled path from classified read-only BMS telemetry to commissioning evidence and energy optimization while restricted credentials and write authority remain protected

Building owners are often told that BMS data is too sensitive to share.

Sometimes that answer is justified. Credentials, network configurations, access-control records, life-safety systems, and control-write authorization can carry serious risk.

But a chiller power trend is not an administrator credential. A chilled-water temperature history is not a badge-access record. Read-only pump status is not permission to command the plant.

Treating every building data request as one undifferentiated security exception protects the owner from one category of risk while making it harder to see another: energy waste, control drift, poor commissioning, and plant performance that cannot be independently verified.

The better answer is controlled access based on the data, the purpose, and the consequence of misuse.

Locked data also locks owner value

The Coalition for Smarter Buildings states the market problem directly: "No more locked data, choices, value, or experiences in buildings."

Its point is not that every building system should be publicly accessible. C4SB advocates open technology, data, and standards so owners and operators can make informed decisions, gain visibility into performance, choose among vendors, and use new applications without rebuilding every integration from scratch.

The Interoperable Building Box makes that distinction concrete. Its proposed architecture runs a cloud-native software platform on a physical or virtual server inside the building. Authorized applications can exchange approved data through a consistent, open, and secure layer.

Open does not mean public.

It means the owner can authorize interoperability instead of remaining trapped between an opaque BMS, proprietary interfaces, and a blanket prohibition on using operating data.

Operating data is part of commissioning evidence

The strongest argument for controlled access is not AI. It is verification.

OpenBuildingControl was created by Lawrence Berkeley National Laboratory to make building control sequences easier to specify, deploy, and verify. Its workflow connects control logic, point lists, functional tests, and actual controller behavior.

For functional verification, OBC describes a commissioning agent exporting trended controller inputs, outputs, and setpoints to an archived CSV file. The verification tool can compare those time series with the digital control specification without receiving live access to the BMS.

That creates a practical question for the owner:

If a time-bounded, read-only export of approved trend points is prohibited, how will the building independently verify that its installed control sequence performs as specified?

OBC's Control Description Language has since become ANSI/ASHRAE Standard 231, a vendor-independent format intended to make control logic human- and machine-readable for specification, implementation, documentation, and simulation.

The direction is clear: the building industry is making control intent and performance more portable and verifiable, not less.

Cybersecurity still sets the boundary

This does not remove the need for a serious security review.

ASHRAE Standard 135 defines BACnet communication for monitoring and controlling building systems. ASHRAE Guideline 13-2024 addresses BAS architecture, documentation, interoperability, performance monitoring, and cybersecurity considerations.

ASHRAE has also identified lack of access to raw BMS data as a common barrier to building analytics, while stating that third-party access needs cybersecurity best practices.

NIST SP 800-82 Rev. 3 treats building automation as operational technology and recommends a risk-based assessment tailored to the site's security, business, safety, reliability, and operational requirements.

None of these sources says that all BMS data belongs in one universal classification.

The useful decision model is to assess the impact of disclosure, modification, or loss of availability for the specific information being requested. NIST FIPS 199 formalizes those three dimensions for federal information systems. It is not a universal building-data classification standard, but it is a useful discipline for asking the right questions.

Separate four different permissions

Many reviews become stuck because four requests are discussed as though they create the same risk:

  1. A one-time export of historical BMS trends.
  2. Continuous read-only access to an approved point list.
  3. Permission to write approved supervisory commands.
  4. Administrative or network access to the BMS environment.

They should be reviewed separately.

A first energy assessment may need only historical temperatures, equipment states, setpoints, flow, power, and weather data. It may not need occupant identities, access-control events, network maps, credentials, life-safety information, or any write authority.

If supervisory control is considered later, the owner can require a separate approval for the exact writable points, command priority, operating envelope, operator override, logging, fallback behavior, and emergency relinquish path.

That is a more secure decision than either unrestricted access or a permanent no.

Give IT a bounded request

The owner should not ask IT to "open the BMS." That request is too broad.

The owner can ask for a documented classification and access decision:

  • Identify the exact data fields and business purpose.
  • Rate the impact of disclosure, modification, and unavailability.
  • Exclude credentials, security systems, life-safety data, unnecessary occupancy context, and network administration.
  • Choose the narrowest access mode: archived export, outbound read-only feed, or approved on-premises processing.
  • Define identities, encryption, logging, retention, deletion, and automatic revocation.
  • Review control-write authority as a separate scope.
  • If controlled access is still denied, document the residual risk that these measures do not address.

This gives the security team something precise to secure and gives the owner a decision that can be challenged, improved, and audited.

Confidential does not mean unusable

Building telemetry may reasonably be classified as Confidential. Confidential data still supports approved business activity when the handling controls match the risk.

ClimaMind's public security model follows that separation. Site metadata, building telemetry, diagnostics, and customer configuration are treated as Confidential. Credentials, device identity material, BMS access details, and control-write authorization are treated as Restricted.

For an initial assessment, ClimaMind can work from an approved point list, a time-bounded historical export, or an on-premises path where the site's requirements call for it. Read-only analysis does not imply write permission, and write permission does not imply administrative access.

Building owners should not have to choose between cybersecurity and building performance.

They should require an architecture that protects what is restricted, controls what is confidential, and lets approved operating data create measurable value.

Source notes

Related field notes

Continue the thread.