Employee offboarding is a crucial element many businesses overlook. When an employee leaves, most organizations remember to collect a laptop and disable email. Physical access can be less consistent. A card may be returned without being deactivated. An alarm code may still work. A former manager may continue receiving security alerts. A contractor may keep a garage remote long after the work is complete.
These gaps are rarely intentional. They happen because human resources, operations, property management and security administration each assume someone else is handling part of the process.
A physical-security offboarding checklist creates one clear process for removing every form of property access. It should apply not only to employees, but also to contractors, cleaners, temporary workers, service providers, residents and commercial tenants when their access is no longer required.
| Quick answer: A physical-security offboarding process should remove building credentials, alarm permissions, keys, parking access, mobile credentials and security-system access associated with the departing person. The organization should document the removal, recover issued property and review shared credentials that may still be known to that person. |
What is physical-security offboarding?
Physical-security offboarding is the documented removal or reassignment of every credential that allows someone to enter, unlock, arm, disarm or manage a property.
The process should identify the person, the property, the credentials they hold, the exact time access should end and the person responsible for completing each action. It should also record that the work was completed.
What types of access need to be removed?
Access cards, fobs and mobile credentials
Returning a physical card or fob does not automatically remove its permissions from the system. The credential should be disabled so it cannot be used if it was copied, misplaced or returned to circulation without proper reassignment.
Mobile credentials should also be removed. These are digital credentials stored on a phone or mobile device and used in place of a card or fob.
Keys, remotes and parking credentials
Mechanical keys, gate remotes, parking tags and elevator permissions should be included in the same checklist. Keys are easy to overlook because they may have been issued years earlier or copied outside the formal process.
Alarm codes and arming permissions
Individual alarm codes should be removed when a person leaves. If the organization uses a shared code, consider changing it when someone with knowledge of that code no longer requires access.
Individual codes improve accountability because the event history can show which user armed or disarmed the system. Shared codes make that harder to determine.
Security applications and administrative access
Some employees and property managers can view cameras, receive alerts or administer access-control users from an application. Removing the building credential does not necessarily remove this administrative access.
The offboarding checklist should identify every security application the person used and whether they had basic viewing access or broader administrative permissions.
Intercoms, visitor systems and emergency lists
Former personnel may remain in intercom directories, visitor-approval systems, monitoring contact lists and emergency escalation plans. These records should be updated so current representatives receive calls and make decisions.
Why physical access is often overlooked
- Human resources assumes building access is controlled by IT or facilities
- Property management is informed after the employee or tenant has already left
- Shared credentials make individual removal difficult
- Contractor end dates are not recorded
- Returned cards are stored without being disabled
- Employees change roles but keep their previous access levels
- Different properties maintain separate user lists
- No one owns the complete offboarding checklist
The solution is not necessarily more technology. It is a clearer handoff between the people responsible for employment, operations and the building.
Offboarding in warehouses and logistics facilities
Warehouses often have a mixture of permanent employees, temporary labour, drivers, maintenance providers and third-party contractors. Turnover may be higher than in a traditional office, and access needs can vary by shift and job function.
The offboarding process should cover employee entrances, shipping offices, loading areas, inventory cages, gates and any restricted storage zones. Driver or carrier access should be managed separately from employee permissions when the operational need is different.
Temporary credentials should have a clear owner and, where the system supports it, an expiration date. A temporary worker who was expected for two weeks should not remain active months later because no one reviewed the user list.
Offboarding in condominiums
Condominium access changes involve more than employees. Residents move, tenants change, property-management companies are replaced and contractors complete projects.
A condominium offboarding process may need to address suite residents, parking garages, storage areas, amenities, elevators, rooftops, mechanical rooms and management offices. The corporation should be clear about which common-area credentials it controls and which access responsibilities belong to individual owners or residents.
When a property-management company or superintendent changes, administrative permissions, monitoring contacts and emergency call lists should be reviewed along with physical fobs and keys.
Offboarding in retail and commercial properties
Retail and multi-tenant properties may have store employees, tenant managers, cleaners, delivery personnel and property contractors using different entrances. Seasonal staffing and tenant turnover can create a large number of credentials over time.
Property managers should distinguish common-property access from tenant-controlled access. When a tenant leaves, shared loading areas, service corridors, parking access and master permissions should be reviewed. Vacant units should also be secured as part of the turnover process.
Offboarding in other commercial businesses
Office and service businesses should consider more than the main entrance. Former employees may have access to records rooms, storage areas, executive offices, parking facilities or after-hours alarm functions.
Role changes should trigger a review too. An employee who moves departments may no longer need access to their previous work area even though they remain with the organization.
A step-by-step physical-security offboarding process
Step 1: Identify every assigned credential
Maintain a record of cards, fobs, keys, remotes, alarm codes, mobile credentials and security applications. If credentials are not inventoried when they are issued, they are much harder to remove later.
Step 2: Establish the exact removal time
Access should end at the time established by the organization. The timing may differ for a planned retirement, a tenant move or an urgent termination. The process should make clear who authorizes the removal and who performs it.
Step 3: Disable electronic credentials
Disable cards, fobs, mobile credentials and individual alarm codes. Do this even when the physical item has been returned.
Step 4: Recover physical property
Collect keys, parking tags, gate remotes, identification badges and company devices used to access security applications. Record items that were not returned so the organization can decide whether further action is required.
Step 5: Review shared credentials
Determine whether shared alarm codes, lockbox combinations or other common credentials were known to the departing person. Change them when appropriate and notify current authorized users through a secure process.
Step 6: Remove remote and administrative permissions
Remove access to camera applications, alarm-management platforms, access-control administration and alert notifications. Confirm that the person is no longer able to add users, unlock doors or view the property remotely.
Step 7: Update contacts and directories
Remove the person from monitoring contacts, after-hours call lists, intercom directories, visitor approvals and emergency plans. Replace them with a current representative where required.
Step 8: Document completion
Record which actions were completed, when they were completed and who completed them. This closes the loop between human resources, operations, property management and security administration.
How HR, operations and property management can work together
A reliable process needs one owner and clear responsibilities. The owner does not have to complete every task, but they should confirm that all required tasks are assigned and closed.
- Use one standard notification form for departures and role changes
- Include contractors, temporary workers and tenant changes
- Set deadlines for routine and urgent access removal
- Prefer individual credentials over shared codes
- Create a defined process for unreturned keys or devices
- Audit active users at a frequency that reflects turnover
- Review access whenever an employee changes roles
Physical-security offboarding checklist
- Disable access cards and fobs
- Remove mobile credentials
- Recover keys, parking tags and gate remotes
- Remove alarm codes and arming permissions
- Remove camera viewing and security application access
- Remove administrator permissions
- Update monitoring and emergency contacts
- Remove intercom and visitor-management permissions
- Review shared codes and combinations
- Document the completed removal
Planned departures and urgent terminations require different timing
The same checklist can support different departure situations, but the timing and coordination may change.
Planned departures
For a retirement, contract completion or scheduled tenant move, the organization can confirm issued credentials in advance, arrange the return of physical items and schedule access to end at an agreed time. Advance planning also gives managers time to assign replacement contacts and administrative responsibilities.
Urgent or sensitive terminations
An urgent termination may require access to be removed at a precise time while human resources, management and security administration coordinate their actions. The process should be prepared before the meeting begins so cards, codes, remote permissions and contact lists are handled consistently.
The security system does not determine the organization’s employment process. It supports the access decision made by authorized management. Only the people who need to coordinate the removal should receive sensitive information.
Preventing access creep when people change roles
Access creep occurs when a person receives new permissions but keeps access from earlier roles. Over several job changes, an employee may accumulate entry to areas that are no longer connected to their responsibilities.
A promotion does not always mean the person should retain every previous permission. A warehouse employee moving into an office role may no longer need inventory-cage access. A property manager assigned to a new portfolio may no longer need administrative access to a former building.
Role changes should trigger a review of current access, not simply the addition of new access. Using defined access groups can make this easier. An access group is a standard set of doors and schedules assigned to a role, such as warehouse supervisor, cleaner or property manager.
Managing temporary workers, contractors and vendors
Temporary access is often more difficult to control because the person is not part of the normal employee offboarding process. Every temporary credential should have a sponsor within the organization. That sponsor is responsible for confirming why access is needed and when it should end.
Where the system supports expiration dates, a credential can be configured to stop working automatically after the approved period. This reduces the chance that a two-week construction credential remains active for months. Automatic expiration does not replace review, because project dates and responsibilities may change.
- Issue individual credentials instead of sharing a general contractor card
- Limit access to the doors and times required for the work
- Record the company, project and internal sponsor
- Set an expected end date
- Recover physical keys and remotes when work is complete
- Review active contractor credentials during regular audits
A responsibility workflow for reliable offboarding
The following workflow can be adapted to a warehouse, condominium, retail property or commercial office:
- Human resources, management or property administration starts the request and confirms the authorized removal time.
- The manager identifies the person’s role, locations and known physical credentials.
- Security administration disables cards, fobs, alarm codes, mobile credentials and system permissions.
- Facilities or property management collects keys, parking devices, remotes and other issued property.
- The monitoring contact list, intercom directory and emergency procedures are updated where required.
- One assigned owner confirms that every action is complete and records any item that could not be recovered.
The exact job titles may differ between organizations. What matters is that one person confirms completion instead of assuming several departments completed their own portions.
How to audit an existing access-control user list
Begin by exporting or reviewing the active credential list. Compare it with current employees, residents, tenants, contractors and property representatives. Investigate unfamiliar names, credentials with no assigned owner and users who have not used the system for an extended period.
Do not disable unfamiliar credentials without checking their purpose. Some may belong to emergency, service or operational roles. The goal is to confirm ownership and need, then document the decision to retain, modify or remove each questionable credential.
Summary
Physical-security offboarding protects employees, residents, inventory, restricted areas and the integrity of the organization’s access records. It also prevents former staff, contractors, residents or tenants from retaining permissions simply because no one completed the final step.
The strongest process is clear, repeatable and shared across the departments responsible for people and property. Technology can support that process, but responsibility must still be assigned.
Frequently asked questions
Should a returned access card still be disabled?
Yes. Returning the physical credential does not confirm that its permissions have been removed from the system. Disabling it prevents future use and keeps the user record accurate.
Who should remove employee building access?
The organization should assign clear responsibility to human resources, facilities, operations, property management or security administration. The key requirement is a documented handoff so the task is not assumed or overlooked.
Should access be reviewed when an employee changes roles?
Yes. Permissions should match current responsibilities. Role changes can leave employees with access they no longer require even though they still work for the organization.
How should contractor access be managed?
Contractors should receive only the access required for their work. Credentials should have a defined owner and, where possible, an expiration date. Active contractor permissions should be reviewed regularly.
How often should access-control users be audited?
The right frequency depends on staff, tenant and contractor turnover. High-turnover facilities should review users more often. Every organization should also complete a review after major staffing, tenant or operational changes.
Do you know how many active credentials are in your system?
| SecurU can assess your access-control procedures, active credentials, restricted areas and offboarding process. An on-site security audit can identify outdated permissions and improve how access is assigned and removed. Request an On-Site Security Assessment |


Commercial Security System Maintenance: What Ontario Businesses Should Inspect Before Winter