Responsibility should sit with the teams that control employment status and facility access together, typically HR and the office or security function. Temporary staff and contractors need access that expires on their last day, and their badges or keys should be collected during offboarding. Clear ownership prevents access from lingering after a role ends.
Why accountability has to span both employment and facility control
Accountability should follow the two control points that make offboarding effective: the team that knows when the person’s work ends, and the team that can physically disable entry. If those responsibilities are split ambiguously, badges, keys, and escort requirements can outlive the assignment, which leaves a simple but real access gap after a temporary engagement ends.
The practical issue is not whether HR or security “owns” offboarding in the abstract, it is whether the organisation can prove that the last day of work and the last day of access are the same event. For temporary staff, the answer should be yes by default, with exceptions handled explicitly rather than informally.
What a clean offboarding handoff looks like
A good process starts before the worker leaves. HR or the staffing owner confirms the end date, while the office, facilities, or security function confirms what physical access exists, such as badges, proximity cards, keys, visitor passes, locker access, and after-hours permissions. That information then drives collection, deactivation, and final sign-off.
For organisations that also manage digital access in the same process, the same principle applies: access should be time-bound, reviewed against the role, and removed on the last day without waiting for a manual reminder. NHIMG’s Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is useful here because it shows how lifecycle ownership, expiry, and offboarding work when access must end cleanly rather than linger.
Where organisations need a practical reference for the lifecycle angle, the broader Ultimate Guide to NHIs and the NHI Lifecycle Management Guide both reinforce the same operational lesson: ownership, expiry, and revocation have to be coordinated or access will outlive the business need.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 6 — Access Control Management | Directly governs revoking access when staff leave and limiting facility access paths. |
| Recommendation — Remove temporary staff access promptly and verify all physical access paths are revoked at offboarding. | ||
| NIST CSF 2.0 | PR.AA — Identity and Access Management | Supports accountable access removal when employment ends and privileges should cease. |
| GV.RM — Risk Management Strategy | Requires defined accountability so offboarding control gaps do not persist as unmanaged risk. | |
| Recommendation — Assign clear owners for access revocation and confirm termination events trigger removal. Document ownership for offboarding and ensure revocation responsibilities are explicitly assigned. | ||
Practitioner Guidance
What to verify: The offboarding record should show who approved the end date, who collected or disabled the badge or key, and when that happened. If the process cannot produce a timestamped handoff, treat it as incomplete.
Decision rule: If employment status changes first, use that event to trigger facility revocation immediately, not as a later clean-up task. If the person is a contractor or temp with recurring access, require explicit renewal rather than assuming continuation.
What good looks like: The access list for temporary staff is short, dated, and owned by a named team, with no reliance on memory or informal messages. Revocation is automatic where possible, and collection of physical credentials is confirmed before departure is closed out.
Practitioner takeaway: The safest model is dual accountability, HR confirms the person is leaving, and facilities or security confirms the door is closed, so no one assumes the other team handled revocation.
Related resources from NHI Mgmt Group
- Who should be accountable for enforcing access policies across students, staff, and visiting users in education?
- What do healthcare security teams get wrong when they rely on manual processes for temporary staff and third-party access?
- Who should be accountable for revoking temporary group access when a project ends?
- What should organisations do when business users are building AI copilots with access to internal systems?