Join our Newsletter — 33% off our NHI Course

What are the signs that termination access controls are failing?

The clearest signs are accounts that remain active after departure, remote access that stays open for days, shared passwords that continue working, and former staff still able to reach file shares or business apps. Another warning sign is when offboarding depends on manual follow-up instead of a standard workflow. If security cannot quickly confirm access removal, the termination process is not working reliably.

What failure looks like in termination controls

Termination access controls fail when revocation is not immediate, not comprehensive, or not tied to a verified workflow. The clearest operational signals are stale accounts, lingering remote access, reused shared credentials, and former employees still reaching business systems after separation. In practice, the issue is not just timing, but whether offboarding actually closes every path an ex-employee could use.

A reliable termination process should remove direct logins, remote access, application entitlements, and any shared or delegated access that the person could still use. If one of those paths remains open, the control has only partially worked. The strongest internal reference for this lifecycle problem is Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs, which covers offboarding, revocation, and visibility as linked lifecycle tasks.

Where this becomes especially visible is in systems that depend on manual follow-up. A termination process that relies on tickets, reminders, or separate team handoffs often leaves gaps between HR departure, IT disablement, and application deprovisioning. That delay is the sign to watch: if access removal cannot be confirmed quickly and consistently, the process is not operating as a control, only as an administrative intention.

Why terminated-user access stays dangerous after the badge is gone

Inactive or partially revoked access is risky because it extends the window in which a former staff member, or anyone who learned their credentials, can still authenticate and act as an insider. The threat is not limited to deliberate abuse. Forgotten access can also be reused by the person, inherited by a shared account, or exposed through remote access that was never disabled.

That is why termination failures often show up as both governance and security problems. Top 10 NHI Issues and Ultimate Guide to NHIs, Key Challenges and Risks both reinforce the same pattern: unmanaged access, weak visibility, and excessive permissions tend to persist together, which makes termination gaps harder to spot and more damaging when they are missed.

One useful benchmark from NHIMG research is that only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them. That statistic is a good reminder that “termination” must include every credentialed path, not just the human account most teams think of first.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Lifecycle Termination failures often leave credentials and access paths active after separation.
NHI-02 — Secure Provisioning and Deprovisioning Offboarding gaps are the core failure mode behind stale access and lingering accounts.
NHI-07 — Visibility and Inventory You cannot confirm termination succeeded without knowing where access still exists.
Recommendation — Revoke or rotate all credentials that survive user departure and verify the blast radius is closed. Automate deprovisioning so termination removes every access path in the same workflow. Maintain an inventory of accounts, credentials, and integrations that must be checked at offboarding.
CIS Controls v8 5 — Account Management Termination control failure is fundamentally a failure to disable accounts and remove access promptly.
6 — Access Control Management Lingering file share, VPN, or app access reflects incomplete access control enforcement.
8 — Audit Log Management Verification of offboarding depends on logs showing when access was removed and whether use continued.
Recommendation — Disable terminated accounts quickly and verify access removal across all connected systems. Remove entitlements and remote access paths as part of a documented termination workflow. Review audit logs for post-termination activity and alert on any continued access.
NIST CSF 2.0 PR.AC — Access Control Termination is an access control outcome: departing users must no longer be able to authenticate or use resources.
GV.OV — Oversight Manual follow-up failures indicate weak governance and accountability over offboarding controls.
DE.CM — Continuous Monitoring Detection of former users still accessing systems depends on ongoing monitoring of account activity.
Recommendation — Enforce rapid access revocation and confirm no residual authenticated sessions remain. Assign clear ownership for termination reviews and require evidence that access removal was completed. Monitor for post-termination logins and investigate any activity after the offboarding date.
NIST Zero Trust (SP 800-207) 5.1 — Policy Engine and Policy Administrator Termination should revoke authorization decisions at the policy layer, not only the user record.
Recommendation — Centralise revocation so policy changes immediately remove access across enforced resources.

Practitioner Guidance

What to verify: Confirm that termination removes access in the systems that actually matter, not just in the HR record or primary directory. A good control leaves an audit trail showing when access was disabled, who approved it, and which applications or remote paths were confirmed closed.

What to prioritise: Focus first on high-impact access paths such as remote access, privileged accounts, shared credentials, and any application where former staff can still reach sensitive data. If those remain open, the termination control is failing in a way that is immediately material.

Common mistake: Treating offboarding as complete once a user object is disabled. In real environments, that can leave business apps, file shares, VPN access, or shared passwords active long after departure.

Practitioner takeaway: The right question is not whether someone has left the organisation, but whether every route they could still use has been closed and verified. If you cannot prove that quickly, your termination control is not reliable enough.