← Back to the NeuroDesk Blog

How Do You Remove Door Access When an Employee Leaves?

Moose Salloum, Principal Advisor|October 8, 2026|6 min read
TL;DR
  • →Remove access from the system, not just from the employee's key ring. A card, phone pass and code can be separate credentials.
  • →Follow an authorized departure process with a clear effective time and an accountable administrator.
  • →Check individual permissions, group memberships, other sites and any administrative rights.
  • →Confirm the affected equipment received the change. Treat offline doors as unresolved until their behaviour is verified.
  • →Preserve the appropriate access record and handle physical keys or shared codes separately. Do not erase useful history just to tidy the user list.

An employee returns their card on the last day. The card goes in a drawer, their email account is closed, and everyone assumes the building access is handled. Their phone pass or a shared door code may still work.

To remove door access properly, follow the person's permissions across credentials, doors and locations, apply the approved change, and verify it reached the equipment. Collecting an object is part of the process. It is not the same as confirming that the system will refuse access.

Start with an approved person and time

The manager or other authorized owner should identify the correct person, the effective time and the sites involved. This avoids revoking the wrong account when names are similar or removing access before an agreed final shift ends.

Use a process that respects employment decisions and confidentiality. A technician needs the approved instruction and necessary identifiers, not the personal reasons for a departure. Decide who can authorize an urgent change and how they reach the administrator outside normal office hours.

Give one person responsibility for closing the access task. Email, payroll and building access may belong to different teams. A single departure checklist can show which owner confirmed each action without assuming that one system automatically controls all the others.

List every credential and permission

A credential is the thing the door system accepts as proof of permission, such as a card, phone pass or personal code. A person can have more than one. Check both assigned credentials and the rules that allow those credentials to open doors.

Review individual door permissions, membership in groups such as Staff or Managers, temporary access and other locations. If the departing person could also administer the system or remotely open doors for visitors, review that privilege separately. Removing routine entry access does not necessarily remove administrative control.

Shared credentials need their own decision. A shared code cannot reliably distinguish the departing employee from everyone else who knows it. Rotate it through an approved process where needed, tell the remaining authorized users securely, and consider whether named credentials would make future changes easier.

  • Cards and fobs assigned to the person.
  • Phone or watch passes and app based door access.
  • Personal codes, shared codes and temporary visitor permissions.
  • Door groups, schedules and access at other sites.
  • Administrator or door attendant privileges and physical keys.

Use revocation, not a cosmetic account change

Changing a display name or deleting an app from a returned phone is not reliable proof of revocation. Use the method documented for the installed access platform. Suspension, permission removal, credential removal and account deletion may have different effects.

This matters especially with mobile credentials. Manufacturer guidance for one supported phone pass system distinguishes unbinding the current device from suspending the pass. The former can leave the same user able to activate it again. That is a reason to check the exact operation, not a claim that all mobile passes behave alike.

If access is connected to a central employee directory, verify the connection is active and covers the relevant sites and services. Record whether the removal completed or is still being processed. Automation is helpful when its result is checked; an integration logo is not evidence that this departure reached this door.

Do not delete records indiscriminately to make the user list look clean. Follow the business's approved retention and privacy policy, preserve necessary access history, and limit who can read it.

Verify the doors received the change

Check the status of the affected door equipment. A powered controller, the device making access decisions, may operate from permissions already stored locally when its network connection is unavailable. A change made in the management screen may therefore need further confirmation at an offline site.

Use the platform's available status and event records, then perform an authorized credential test where practical and appropriate. A returned credential can help confirm denial, but do not use someone else's private phone or request their personal account password. Ask the installer how to verify credentials that cannot safely be presented.

Document unresolved locations explicitly. If a door cannot be verified, tell the responsible manager and follow the approved security contingency. Do not alter emergency exit hardware or improvise a lock change to finish a software checklist.

Close the task when the access change is verified, not when the card lands in a drawer.

Keep the evidence useful and private

A completion record should name the authorized request, effective time, affected sites, actions taken, verification and any remaining exception. It should not contain the old access code, account password or unnecessary employment details.

Physical keys remain a separate issue even when the electronic system shows no permissions. Record their return or the required follow up with the building's responsible person. Likewise, a door scheduled to stand unlocked is not made secure by revoking one credential.

Use the next routine review to remove stale access and confirm who owns the process. We recommend checking this while everyone is available, rather than discovering during a departure that only a former installer can administer the doors.

Plan the next step with NeuroDesk

NeuroDesk includes security cameras and access control in its business technology planning. Bring a list of doors, credential types and the people authorized to approve access changes. We can review the installed system and define an offboarding check that fits it.

See our business security and access planning for the relevant scope.

Sources and technical scope

The technical references below describe particular equipment and software. Features and limits must be checked against the installed model and configuration; they are not promises for every system.

See more NeuroDesk guides in Google.

Add NeuroDesk as a preferred source so Google can show you more of our practical technology articles.

Add NeuroDesk on Google

Connect the systems around your business and remove repetitive operating steps.

Explore the service →

Talk to a specialist.

Book a call to walk through the problem, or email us if you would rather start there.

Book a callEmail NeuroDesk
Read Next
Commercial Automation
How Long Should Your Business Keep Security Camera Footage?
October 8, 2026 · 6 min read
Commercial Automation
What Should You Receive When a Business Network Installation Is Finished?
October 8, 2026 · 6 min read
Commercial Automation
Where Should Business Cameras Go If You Need to See Who Entered?
October 8, 2026 · 7 min read

Frequently Asked Questions

Is collecting a key card enough to remove door access?

No. The person may also have a phone credential, personal code, another card or access at another site. Revoke the relevant permissions and credentials in the installed system, then verify the change. Handle physical keys and shared codes through their separate procedures.

Will disabling a work email account remove door access?

Only if the identity integration is configured to do that and the change reaches the relevant system. Standalone door permissions may remain. Confirm the integration's scope and check the door access record rather than treating an email shutdown as proof.

Is removing a phone from a pass the same as revoking it?

Not necessarily. Some systems distinguish unbinding a device from suspending the credential. Unbinding can allow the same user to activate the pass on another device. Use the documented revocation method and verify the person's remaining access.

What if a door controller is offline during offboarding?

Do not claim access is removed at that door until the outcome is known. Powered equipment may be using permissions stored locally. Escalate through the approved site security process, restore communication where appropriate and verify the updated behaviour without compromising safe exit.