Offboarding is complete only when a departing person’s physical and digital access paths have been identified, revoked and verified. A returned badge does not prove that mobile credentials, biometric enrollments, vehicle permissions, visitor-system accounts or remote administration rights have been removed. The process must follow the identity across every connected security system.
Build an authoritative trigger
Revocation should begin from a trusted personnel or contract event with an effective time and accountable owner. Human resources, procurement, facilities and security may hold different parts of the record, so the workflow needs one authoritative trigger and a method for urgent terminations. Role changes and extended leave also require review even when the person remains employed.
The request should identify the person, organization, sponsor, credential types, sites and systems in scope. Avoid using names alone; duplicate names and formatting differences can lead to missed records. Preserve identifiers that allow operators to find the same identity in the access-control system, visitor platform and mobile-credential service.
Revoke the credential and the entitlement
Disable active badges and mobile credentials, but also remove the access levels, groups and schedules that granted permission. Otherwise a replacement credential may inherit rights that should have ended. Biometric templates and identity documents should be handled according to retention and legal requirements rather than left indefinitely in an active population.
Collect physical badges where practical and record those that were not returned. Vehicle tags, keys, tokens and temporary passes need their own disposition. Contractors may have access through a shared employer relationship, so terminating one assignment should not accidentally remove or preserve access for unrelated personnel.
Verify across integrations and offline devices
Integrated systems may not update simultaneously. Confirm that revocation reached downstream controllers, wireless locks, elevators, parking systems and third-party services. Offline locks and cached mobile credentials deserve particular attention because a central status change may not take effect until synchronization.
Test high-risk cases by reviewing the credential status and recent transactions. Do not create a real unauthorized entry attempt unless the procedure is controlled. The verification record should show who performed each action, when it completed and which exceptions remain open.
Measure timeliness and completeness
Track the interval from the effective termination time to confirmed revocation. Separate routine delays from urgent failures, and investigate credentials that remain active beyond policy. Periodic reconciliation between personnel records and active access identities can identify orphaned accounts, expired contractors and duplicated credentials.
Access offboarding is a lifecycle control within Access Control & Identity, not a one-time badge task. Clear ownership, complete inventories and evidence-based closure reduce the window in which former access can be misused.
Include service identities and scheduled accounts assigned to the departing person. Shared administrative credentials should be rotated through a controlled process when exposure cannot be ruled out, while audit evidence is preserved.

Leave a Reply