Someone left in March. Yet their badge may still open the back door tonight. Access control offboarding is the part most teams get wrong, because a departure rarely closes every door at once. The email account gets disabled fast. The laptop gets wiped. The login gets revoked. Still, the physical badge often sits on a separate system. The login to a forgotten app often lingers too. So the person is gone, but the access is not. Below is why that gap forms, how wide it really is, and how to close it before it costs you.
Why Access Control Offboarding Breaks Down
Access control offboarding breaks down for boring, human reasons. The IT side usually moves quickly when someone departs. However, the badge sits on a different system, and facilities often owns it instead of IT. So disabling it depends on a handoff between two teams. When that handoff slips, the credential keeps working. As a result, an orphaned badge can open a door at 9 p.m. on a Saturday. It maps to a name no longer on payroll. The same thing happens to logins. A VPN profile, a SaaS seat, or a shared password lingers. No one owned the task of turning it off. The gap is quiet, so it stays open for weeks.
Orphaned Accounts and Badges Pile Up Fast
The numbers are blunt. According to Security Magazine, only 34 percent of organizations revoke system access on the day an employee leaves. For half of all companies, it takes three days or longer. That window is exactly when orphaned accounts pile up. Beyond Identity surveyed more than 1,000 people on this question. It found that roughly 25 percent of former workers can still reach a past employer’s accounts. Worse, 24 percent admitted they kept a password on purpose. So this is not a rare edge case. Instead, it is the default outcome when no one closes the loop. These are not hypotheticals. They are forgotten doors with real names attached.
Physical and Logical Access Are the Same Risk Now
A badge used to be a building problem. A login used to be an IT problem. Today they are the same problem. Modern access control runs on the network. Therefore an orphaned badge is both a physical entry point and a live account inside your walls. A former worker with that credential can open a door or pivot deeper. CISA, the federal cyber agency, is direct about this in its insider threat guidance. When someone separates, the plan should revoke system access and disable the badge together. It should not handle them on two different timelines.
The Standard Already Tells You What to Do
You do not have to invent a process. NIST SP 800-53, the federal control catalog, spells it out in control AC-2, Account Management. It tells organizations to align account management with personnel termination and transfer processes. In plain terms, the moment HR marks someone as gone, the access should follow. The same control points to least privilege and timely removal of accounts that are no longer needed. So the badge and the login are not separate chores. Rather, they are two ends of one identity lifecycle. Both should open and close on the same trigger.
Insider Threat Carries a Real Price Tag
This gap is expensive, not just untidy. Verizon, in its 2024 Data Breach Investigations Report, found that internal actors were tied to a large share of breaches. Privilege misuse also remained a leading pattern. The cost follows. IBM, in its 2024 Cost of a Data Breach report, put the average malicious insider attack at 4.99 million dollars. That was the highest of any attack vector it measured. A former worker with a working badge is the cheapest version of that threat to prevent. After all, the fix is a checklist item, while the breach is a headline.
How to Close Every Door at Exit
Good access control offboarding is a routine, not a scramble. First, build one list that maps every credential a person holds, both badges and accounts. Next, tie that list to the HR exit trigger, so one event starts every revocation. Then disable the badge and the login on the same day. Do not wait until facilities gets around to it. After that, sweep for orphaned accounts on a schedule, because shared logins and old SaaS seats hide well. Finally, log each closure, so you can prove a door is shut rather than assume it. By contrast, a process that only kills the email leaves the riskiest doors open.
Here is the honest summary. If you cannot name who closed the badge and the login for this year’s departures, some are still working. The good news is that this is fixable. Better still, it costs far less than the breach it prevents.
Source 1 Solutions builds this discipline into one managed program. That includes designing and installing access control. It brings badges and logins under the same governance. It also converges physical and IT security, so a departure closes both at once. As a result, offboarding becomes a clean, provable event instead of a gap you hope no one finds.
Do not wait for an orphaned badge to find the door first. Talk to Source 1 Solutions and make every exit close every door. Reach the team at /contact-us/ or call +1 (727) 538-4114. Then turn offboarding into access you can prove is shut.