Join our Newsletter — 33% off our NHI Course
Home Glossary NHI Lifecycle Management Termination Process
NHI Lifecycle Management

Termination Process

← Back to Glossary
By NHI Mgmt Group Updated September 19, 2026 Domain: NHI Lifecycle Management

The termination process is the formal sequence used to end employment and remove access at the same time. It should connect HR, IT, security, and business owners so no account, password, or remote connection is left behind. Weak termination handling creates a gap where ex-employees can still reach sensitive systems.

What the termination process actually covers

The termination process is not just a payroll or HR event, it is an access-removal control that closes the employee lifecycle at the same moment the employment relationship ends. Its job is to make sure accounts, sessions, credentials, remote access, badges, and business approvals are removed or transferred quickly enough that the former worker cannot continue to act for the organisation.

That sequence matters because termination is where ownership breaks down most often: HR may know the departure date, IT may own the account, security may own the policy, and the business may own the application. A complete process ties those parties together so the offboarding action is coordinated rather than assumed.

For identity lifecycle context, see NHI Lifecycle Management Guide and the broader lifecycle processes for managing NHIs, which explain why removal, rotation, and deprovisioning must be treated as one control.

Why termination failures create security exposure

The security problem is stale access. If any account, token, VPN path, mailbox rule, shared credential, or remote connection survives termination, the organisation has a live path that no longer has a valid business owner. That gap can be used accidentally, by a disgruntled former worker, or by an attacker who has obtained old credentials.

This is why termination should be understood as a control point in the access lifecycle, not a paperwork step. It is the moment when entitlement, authentication material, and remote reach must be brought to zero or reassigned with clear ownership.

That risk is easy to underestimate because many organisations believe an employee leaving automatically means access is gone. In practice, identity sprawl, third-party tooling, and overlooked service access often leave partial exposure behind.

A useful external reference for this control model is NIST Cybersecurity Framework 2.0, especially where governance and protection functions require timely access revocation, and NIST SP 800-53 Rev 5 Security and Privacy Controls, which aligns termination with access control and account management discipline.

How a sound termination process should work

A reliable process starts before the final day and ends only when access inventory is verified. The practical sequence is: identify every system the person can reach, decide what must be disabled immediately versus transferred, revoke remote and privileged access, recover organisation-owned assets, and confirm that no residual access path remains.

Where credentials are involved, removal is often not enough. Shared secrets, API keys, certificates, and signing material may need rotation or replacement because they can outlive the person who used them. That is especially important when the departing worker had access to automation, infrastructure, or privileged service paths.

The most useful view is to treat termination as a cross-functional control with three outcomes: access is removed, ownership is reassigned, and evidence of completion is retained. If any of those is missing, the process is incomplete.

For broader lifecycle and offboarding examples, Top 10 NHI Issues is a strong companion reference, and the Coupang Signing Key Breach illustrates how missed offboarding of signing material can turn a departure into material exposure.

Common termination gaps and what they leave behind

The most common failure is partial revocation. Organisations disable the primary account but forget delegated access, SSO-linked services, local admin rights, cloud consoles, chat tools, or remote support channels. Another common gap is delayed action, where the final day passes before access is removed.

Equally dangerous are invisible dependencies. An account may appear inactive while the real exposure sits in a connected credential, a cached session, a vaulted secret, or a system where ownership was never recorded. In those cases, the termination process fails because nobody can prove that all access paths were actually found.

For organisations with machine or service credentials, termination should also trigger review of any secrets or keys the person could rotate, export, or embed in code or CI/CD systems. That is where offboarding becomes a control over broader access continuity, not just a user record change.

The 2025 State of NHIs and Secrets in Cybersecurity is a useful companion source because it ties lifecycle weakness to secrets exposure, rotation gaps, and excessive privilege patterns that can persist after personnel changes.

Risk and Threat Considerations

Termination is a high-value attack window because access that is no longer business-justified can remain technically valid. Former staff, contractors, or attackers using stolen credentials may exploit that gap to reach email, cloud consoles, production systems, or sensitive data before revocation catches up.

Failure mechanism: delayed or incomplete deprovisioning leaves live accounts, sessions, tokens, or shared secrets active after separation, creating an easy path for unauthorised access and persistence.

Impact: the result can be data theft, account misuse, privilege abuse, sabotage, or extended exposure that is hard to detect until after damage is done.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 5 — Account ManagementTermination is a core account removal and access revocation event.
CIS Control 6 — Access Control ManagementOffboarding must remove permissions, sessions, and remote access paths tied to the departed user.
CIS Control 4 — Secure Configuration of Enterprise Assets and SoftwareTermination often requires disabling remote access paths and reverting unsafe access-enabled configurations.
Recommendation — Revoke accounts and access promptly when employment ends. Remove or reassign access rights tied to separated users. Disable unnecessary remote access paths left behind after termination.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlTermination is an access-control lifecycle action that ends identity-based access.
GV.OC — Organizational ContextTermination requires cross-functional ownership and defined accountability across HR, IT, and security.
PR.PS — Platform SecurityOffboarding must eliminate residual remote connectivity and account-based platform exposure.
Recommendation — Apply identity lifecycle controls to deactivate access at separation. Assign clear ownership for offboarding decisions and completion checks. Remove leftover platform access and remote connections during offboarding.
NIST SP 800-63IAL/AAL/FAL — Digital Identity Assurance and Authentication AssuranceTermination affects authenticator validity and the continued trust in login mechanisms tied to the separated user.
Recommendation — Invalidate or retire authenticators that should no longer confer access.
OWASP Non-Human Identity Top 10NHI-01 — Identity Lifecycle and OffboardingThe term maps directly to removing non-human access at the end of its authorized lifecycle.
NHI-02 — Secrets and Credential ManagementTermination commonly requires revoking or rotating credentials that survive the person or process change.
NHI-03 — Authorization and Least PrivilegeTermination is the point where excessive or lingering access must be removed or reassigned.
Recommendation — Deactivate non-human access and rotate dependent secrets during offboarding. Rotate or revoke secrets that could persist after termination. Strip unused privileges and reassign ownership before residual access becomes exposure.

Practitioner Guidance

Governance implication: termination should have clear ownership across HR, IT, security, and system owners, with a single process that defines who triggers revocation, who confirms completion, and what evidence proves the closeout happened. The biggest practical mistake is treating it as an IT ticket rather than a lifecycle control that must be verified end to end.

Practitioner takeaway: a termination process is only effective when the organisation can prove that no access path, credential, or delegated approval survived the employee’s last day.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org