Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What happens when user access is not terminated…
Governance, Ownership & Risk

What happens when user access is not terminated after a job change or termination?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Governance, Ownership & Risk

When access is not removed promptly after a role change or termination, dormant or orphaned access can persist in business and IT systems. That creates a clear control gap because former users may retain permissions that no longer match their duties. In practice, this weakens access governance, increases the chance of unauthorized activity, and complicates audit findings around completeness and timeliness.

Why delayed termination creates a control gap

When access is not terminated after a job change or departure, the real issue is not just stale records. The access path itself remains live, so the organisation can no longer rely on job status to reflect current authority. That breaks the assumption behind least privilege and makes access reviews less meaningful because entitlements no longer match the person’s active duties.

Over time, this usually shows up as dormant access, orphaned permissions, or accounts that still authenticate long after ownership has changed. A clean joiner-mover-leaver process should close that gap quickly, with offboarding and access change actions tied to the same lifecycle event rather than left to separate teams or manual follow-up.

Persistent access is especially problematic in shared business platforms, admin consoles, cloud services, and integrated systems where a single account can reach multiple data sets or operational actions. NHIMG’s NHI Lifecycle Management Guide covers the same lifecycle problem from an identity governance perspective, including provisioning, rotation, and offboarding discipline.

For a broader view of the failure mode, Ultimate Guide to NHIs, Key Challenges and Risks is useful because it explains how visibility gaps, unmanaged credentials, and excessive permissions combine into persistent exposure.

Why this matters for governance, audit, and operations

Unterminated access creates more than a hygiene issue. It weakens accountability because the organisation cannot confidently say who should still have access, who approved it, or whether the access is still necessary. That complicates audit evidence, especially when reviewers ask whether removal was timely, complete, and enforced across all connected systems.

The operational impact is also cumulative. The longer access stays in place, the more likely it is to be reused, forgotten, or inherited by another role transition. In environments with many systems, the gap often appears where provisioning is automated but deprovisioning still depends on manual tickets, exception handling, or delayed manager confirmation. NHIMG’s Top 10 NHI Issues is a useful companion because it frames lifecycle control, excessive permissions, and ownership as recurring governance failures rather than isolated events.

The same pattern is visible in real-world breach analysis. Coupang Signing Key Breach shows how unrevoked credentials after offboarding can become a direct exposure path, not just an administrative oversight. That makes deprovisioning speed a control objective in its own right, not a back-office cleanup task.

If the access path is tied to credentials, tokens, keys, or certificates, the same principle applies, the authority should end when the business relationship ends. Industry guidance such as the OWASP Non-Human Identity Top 10 reinforces this lifecycle view by treating rotation, revocation, and overprivilege as core security controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 5 — Account ManagementDirectly governs removal of stale user access after role change or termination.
CIS 6 — Access Control ManagementCovers least privilege and removal of unnecessary access paths after a role change.
Recommendation — Enforce timely account disablement and access revocation when employment status changes. Review and remove entitlements that no longer match current job duties.
NIST CSF 2.0PR.AA-05 — Asset Management and Access ControlSupports controlling and revoking access so permissions align with current authority.
GV.RM-02 — Risk Management StrategyLifecycle gaps create governance risk that should be measured and managed explicitly.
Recommendation — Align access permissions with current business need and remove stale access promptly. Set measurable expectations for access removal timeliness and exception handling.
NIST Zero Trust (SP 800-207)2.3 — Device and User Authentication and AuthorizationZero Trust depends on current authorization state, not legacy access left behind after departure.
Recommendation — Re-evaluate authorization continuously and revoke access when trust conditions change.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementStale access often persists through credentials, keys, tokens, or certificates left active after offboarding.
NHI-02 — Privilege and Entitlement ManagementExcess permissions left after a move or termination directly create unauthorized access risk.
NHI-03 — Lifecycle and OffboardingThe question is fundamentally about failing to end access when the lifecycle event occurs.
Recommendation — Revoke or rotate identity-enabling secrets immediately when ownership changes. Remove unused entitlements and enforce least privilege after every access change. Automate offboarding and access removal as part of the same lifecycle workflow.

Practitioner Guidance

What to verify: Check whether access removal is triggered automatically from the source-of-truth HR or workforce event, then propagated to every downstream system that can still authenticate the user. If revocation depends on manual tickets, treat that as a timing risk, not just a workflow preference.

Decision rule: If the user’s old access still reaches production data, admin functions, or shared secrets, prioritise revocation before lower-value cleanup work. If the account is only locally scoped and demonstrably harmless, the urgency is lower, but the closure still needs a documented owner and deadline.

What practitioners underestimate: Role changes can be as risky as terminations because old permissions often remain alongside the new role. The safest state is not “eventually removed”, it is “no longer usable after the authority to use it has ended”.

Practitioner takeaway: Treat access termination as a lifecycle control with measurable timeliness, not a courtesy step after HR closure, because stale access is still live authority until it is actually revoked.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org