Treat it as an unresolved offboarding event, not as a minor exception. Revoke the remaining access path immediately, rotate any shared credentials, verify session termination and capture the action in the evidence log so the termination is closed consistently across systems.
Why a Termination With Live Access Is an Offboarding Failure
When a terminated user still has live access, the organisation has not actually completed offboarding. The termination may be recorded in HR or a ticketing system, but the security state is still open until every surviving credential, session and entitlement is removed or neutralised. That is why the issue should be treated as an unresolved lifecycle event, not a clerical exception.
The practical question is whether any path still lets the former user act as if they were authorised. If the answer is yes, the system state is inconsistent and the exposure continues until access is revoked, sessions are invalidated and ownership of the closure is clear.
That is the same control problem addressed by Joiner-Mover-Leaver (JML) Guide, where leaver processing is only complete when the old access path is removed, not merely flagged for removal.
What Must Be Closed Before the Termination Is Considered Complete?
A complete response has three parts: revoke the remaining access path, invalidate anything that could still authenticate or continue a session, and confirm the change propagated across connected systems. If shared credentials exist, rotate them because the former user may still know or possess them even after formal departure.
This is why lifecycle and governance controls matter as much as the termination event itself. A user can be removed from one directory, but still hold a session token, a cached credential, an application-specific account or a shared secret in another environment. The closure standard should therefore be the absence of all usable access, not just the presence of a termination record.
The broader lifecycle and ownership model is covered well in NHI Lifecycle Management Guide, which treats offboarding, rotation and visibility as one operational chain, and in IAM and IGA Basics, which frames entitlement removal and governance as part of the same control loop.
A useful closure test is simple: if the former user could still sign in, use a shared key, or continue an active session after termination, the event is still open.
How Organisations Prove the Access Is Really Gone
Verification matters because deprovisioning is often asynchronous. Systems can lag, cached authorisations can persist, and downstream applications may not process the termination signal immediately. The organisation should therefore validate revocation, check session termination, and retain evidence that the removal was executed and confirmed.
That evidence should be operationally useful, not ceremonial. The log should show what access was removed, when shared credentials were rotated, what sessions were invalidated, and which systems confirmed the closure. Where access reviews are part of the process, they should end in actual removal, not only in sign-off.
That closure discipline aligns with the practice described in Access Reviews and Certification Guide, which emphasises closed-loop remediation, and with Workforce Identity Security Guide, where offboarding and session theft are treated as linked operational concerns.
Risk and Threat Considerations
A terminated user with live access creates avoidable exposure because former access is often trusted, overlooked and under-monitored. The risk increases sharply if the remaining path is privileged, shared, long-lived or able to reach production systems, since the actor may still be able to exfiltrate data, alter records or continue activity under a now-invalid employment status.
Failure mechanism: Offboarding is incomplete, so the person retains one or more working access paths after termination. That can happen through delayed deprovisioning, missed shared credentials, surviving sessions, unmanaged applications or access that was never tied cleanly to the joiner-mover-leaver process.
Impact: The organisation remains exposed to unauthorised use, insider-style abuse, credential reuse and audit failure until the last usable access path is removed and confirmed closed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Live access after termination is the core offboarding failure this question asks about. |
| NHI-07 — Long-Lived Secrets | Remaining shared credentials can keep a terminated user active after departure. | |
| Recommendation — Revoke all remaining access and confirm the NHI is fully offboarded. Rotate any surviving secrets and remove long-lived credentials from use. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Termination requires timely account disablement and removal of residual access paths. |
| IA-5 — Authenticator Management | Shared credentials and authenticators must be rotated or invalidated after termination. | |
| Recommendation — Disable accounts promptly and verify all associated access is removed. Rotate or revoke authenticators that could still grant access. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights must be removed when employment ends or no longer requires them. |
| Recommendation — Remove access rights immediately and record completion evidence. | ||
| CIS Controls v8 | CIS-5 — Account Management | This situation is an account lifecycle failure requiring rapid deprovisioning. |
| Recommendation — Automate deprovisioning and confirm no lingering accounts remain active. | ||
Practitioner Guidance
What to prioritise: Close the highest-impact access path first, especially any account, token or shared credential that can still reach production, finance, customer or administrative systems. If more than one path remains, treat the problem as a broader termination-control failure until all are cleared.
What to verify: Confirm three things before closing the ticket, the access path was revoked, any live session was terminated, and any shared secret or shared credential was rotated so the former user cannot continue to authenticate elsewhere.
Common mistake: Marking the HR event complete while the technical access remains live. That turns an offboarding issue into a latent access-control problem and often leaves the strongest exposure untouched.
Practitioner takeaway: A termination is not finished when the person leaves, it is finished when no surviving path can still act on their behalf and the closure is evidenced across the systems that matter.
Related resources from NHI Mgmt Group
- Who is accountable when a terminated user still has access?
- What should organisations do when nobody can explain why a user still has access?
- How should organisations handle emergency lockout when a user may still retain access across multiple connected systems?
- What should organisations do when a user disconnects an integration but provider-side access may still remain active?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org