Four Employees Moved On: Where They Still Show Up in Your Security System

Here is an exercise any business can run in an afternoon.

Print three lists. The active credentials in the door system. The user codes in the alarm panel. The names the monitoring center calls when an alarm comes in. Then set them next to the current payroll roster and start matching.

I have helped customers work through these lists, and some were surprised to find names on them that needed to be removed. Nobody did anything wrong. People left, the way people do, and the records stayed behind because nobody’s job was to remove them.

That is what this post is about. Not the people. The records.

The short version. Every employee is set up in four separate places when they start, and each one has to be closed out separately when they leave. The door credential. The alarm user code and the monitoring call list. The video and app logins. The physical key. A card or phone credential can be deactivated in seconds from a laptop. The alarm code and the call list take one phone call. A shared login takes a password change. A key takes a decision. Put all four on your offboarding checklist with a name next to each, and compare the lists against payroll twice a year to catch what the checklist missed.

How Much Turnover a Building Actually Sees

Most owners underestimate how many people have come and gone through their doors, because the day to day does not feel like turnover. One person leaves in March. Another in June. A seasonal hire in November. It adds up faster than it feels.

The Bureau of Labor Statistics measures this every month in its Job Openings and Labor Turnover Survey. The 2025 annual averages, published in March 2026, put the total separations rate for private employers at 3.6 percent a month. That is quits, layoffs, retirements, and everything else combined. The South ran 3.4 percent. Retail ran 3.8 percent. Restaurants and hotels ran 5.5 percent.

Twelve months at 3.4 percent works out to separations equal to roughly four in ten positions over a year. A restaurant group at 5.5 percent sees separations equal to about two thirds of its headcount in the same twelve months. Some of that is the same position turning over more than once, but every one of those departures was a person who had a badge, a code, or a key.

Now think about how the door system gets maintained. Credentials get added the day someone starts, because the person needs to get in. The list of who is still active gets reviewed when the system is installed and then, in a lot of buildings, not on any schedule at all. After a few years at those turnover rates, the system is carrying a lot of names that no longer belong to anybody in the building.

Place One: The Door Credential

This is the easiest of the four to fix, which is exactly why it is easy to assume someone already did.

A card, a fob, or a phone credential is a record in your access control software. Setting it to inactive takes about fifteen seconds. On a cloud-hosted system you can do it from your phone. A phone credential stops working at the door the moment you revoke it, whether or not the phone ever comes back to the building, which is one of the practical arguments for mobile credentials I made in the mobile access post.

The reason it does not happen is not the software. It is the handoff. The manager who handles a departure is usually not the person who administers the doors. HR closes out payroll and email. Nobody tells the one person with the access control login, or that person was the office manager who left last year, which is the same problem one level up.

Two habits fix it.

First, every credential carries a person’s name. Not “Card 0417,” and not “Front Desk.” When the person leaves, you search the name and you are done. Credentials issued to a role instead of a person cannot be closed out because nobody knows who is holding them.

Second, the door administrator hears about every departure the same day payroll does. Put it on the offboarding form as a line item, with a name next to it.

Then use the report your system already produces. Every modern access control platform logs which credential opened which door and when. Once a quarter, pull the list of credentials with no activity in 90 days. Most of those belong to people who have moved on. A few belong to a drawer. Either way, they come off the list.

Place Two: The Alarm Code and the Call List

The intrusion system takes a little more care, because it has two pieces the door does not. A code that turns the whole system off, and a list of people the monitoring center calls and takes instructions from.

Start with the code. Commercial panels hold dozens of user slots, and each slot should hold one person. When the system disarms, the panel records which user did it, and your monitoring provider can see that record. It is useful information when you need it, and it is useless if six people share user 01 because programming six codes felt like extra work. In a lot of businesses, “the code” is a single four-digit number that has been handed from manager to manager for years. It is not a secret anymore. It is folklore.

When someone leaves, their user code comes out. If they were using the shared code, the shared code gets changed and the remaining staff each get their own. That is a short visit for most panels and can be done remotely on many of them.

Now the call list. This one gets overlooked because it does not live in your building. It lives at the monitoring center. When an alarm comes in, the operator works down the list in order, and whoever answers gives a verbal password to confirm it is a false alarm or to confirm the emergency and get help sent. The list is only as good as the phone numbers on it.

On a stale list, the top name may belong to a manager who left years ago, and the second number may no longer work. The operator spends minutes calling people who cannot help before reaching someone who can. In jurisdictions that prioritize verified alarms, and I wrote about where Metro Atlanta stands on that in the verified alarm response post, those minutes matter.

So the offboarding line item for the alarm reads: remove the user code, change the shared code if there was one, take the person off the monitoring call list, and set a new verbal password if they were one of the people who used it. The last two steps are a phone call to your monitoring provider and take about three minutes. While you have the operator on the line, ask them to read the whole list back to you. Owners are sometimes surprised by who is still on it.

If your business is inside the City of Atlanta, your alarm registration with the city’s false alarm program renews every year, and a false alarm from an unregistered system carries a $150 fine. The renewal is a good standing reminder to review the call list at the same time. It is the same fifteen minutes.

Place Three: The Video and App Logins

Cameras and the apps that run access control have logins, and logins drift.

The pattern is familiar because it is reasonable. The recorder was installed with one admin account. The installer wrote the password down for the owner. Over the years it went to the manager, then the assistant manager, then the IT provider, then whoever needed a clip for an insurance claim. Everyone who ever needed video got the admin credentials to the whole system, and the credentials never changed because changing them would have meant telling everyone.

I covered the cyber side of this in the camera cybersecurity post. The offboarding side is about housekeeping. When a login is shared, you cannot close out one person’s access without resetting everyone’s. That is the real cost of the shared password: it turns a fifteen-second task into an afternoon of phone calls, so it does not get done.

The fix is the same as the doors. Each person who needs video gets their own login with the level of access their job needs. Most people who review a clip do not need to delete anything or change a setting. When a person leaves, their account gets disabled. If a shared admin password exists today, change it once, stop sharing it, and issue individual logins from there.

The mobile apps count too. If your access control or alarm has an app, the app has an account tied to a person. On cloud platforms where the door system and the app are separate screens, removing someone from one and forgetting the other is an easy miss.

Place Four: The Key

The key is the one credential in the building that cannot be turned off.

A badge can be deactivated. A code can be changed. A key that went home in a coat pocket in 2022, and is still there, works until you change the cylinder. If it was cut on an unrestricted blank, there is no way to know how many copies exist.

I am not going to tell you to rekey every time a cashier leaves. Nobody does that, and it is the reason we put electronic locks on the doors that matter in the first place. But the offboarding checklist should say two things about keys.

One, every key gets signed for on the way in, so you know who has what. Two, when a key does not come back, you make a deliberate decision and write it down. Rekey, or accept it, but record which. The doors that should not depend on a brass key are the ones with cash, records, or servers behind them. Those are the ones I move to electronic access first, so that the next time this comes up, the answer is a click instead of a locksmith.

If you run a healthcare operation, there is a rule with your name on it. The HIPAA Security Rule calls for “procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends.” If you take card payments, PCI DSS version 4.0.1 expects physical access to sensitive areas to be revoked immediately when someone leaves, and their keys and access cards returned or disabled. Neither rule tells you how. Both expect you to be able to show that you did.

The One-Page Offboarding Checklist

Here is what I would put on one page and hand to whoever runs departures. With the systems set up right, it takes under thirty minutes.

  • Door credential set to inactive, by name.
  • Phone credential revoked, if one was issued.
  • Alarm user code removed. Shared code changed if the person used it.
  • Monitoring call list updated, verbal password reset if needed, confirmed with the monitoring provider by phone.
  • Video system login disabled. Shared admin password changed if one exists.
  • Access control and alarm app accounts removed.
  • Keys collected and logged. If a key is missing, the rekey decision recorded.
  • One named person signs the sheet.

The signature line is not a formality. It is the reason the other seven get done.

The Audit, Twice a Year

The sheet handles departures from today forward. It does nothing about the years before you started using it. For that, you run the exercise from the top of this post.

Twice a year, pull the three lists: active door credentials, alarm user codes, and the monitoring call list. Set them next to payroll. Anything on the lists that is not on the roster comes off that day. The first pass takes the longest. After that, the twice-a-year pass is short, because the sheet is doing its job in between.

If you want a preview before the full exercise, ask your security company for the door credentials with no activity in 90 days. That one report tells you most of what you need to know.

When the door, alarm, and video systems have never met each other, this is three exercises on three screens. That is one of the practical reasons I make the case for an integrated system. A person leaves once, and you close them out once.

Frequently Asked Questions

How soon after an employee leaves should their building access be removed?

The same day. Electronic credentials can be set to inactive in seconds from a laptop or phone, so there is no technical reason to wait, and doing it as part of the same-day offboarding steps keeps it from being forgotten. Alarm codes and the monitoring call list take one phone call. The only credential that cannot be closed out the same day is a metal key.

What happens to my alarm system’s user codes when staff turn over?

Nothing, unless someone removes them. Codes stay active until they are deleted, and a shared code stays the same until it is changed. Give each user their own code so the panel’s log is meaningful, remove codes as part of offboarding, and change any shared code when someone who used it leaves.

How often should a business audit who has access to the building?

Twice a year at minimum, plus any time ownership or management changes. Compare the active door credentials, the alarm user codes, and the monitoring call list against the current payroll roster, and remove anything that does not match. A quarterly report of credentials unused for 90 days is a good early warning between audits.

Do I need to rekey when an employee leaves?

Not for every departure. Make a deliberate decision each time a key is not returned, and record it. Rekey any door protecting cash, records, or equipment when a key is unaccounted for. Better, put electronic locks on those doors, so the answer next time is deactivating a credential instead of changing a lock.

Who should own removing someone from the security system?

One named person, with the task on the offboarding form beside the payroll and email steps. The most common gap is that the manager handling the departure is not the person who administers the doors, and no one connects the two. Your security company can make the changes for you if they hear about the departure the same day.

Is there a compliance requirement to remove access when someone leaves?

For healthcare, the HIPAA Security Rule at 45 CFR 164.308 calls for termination procedures for access to electronic protected health information. For any business taking card payments, PCI DSS 4.0.1 expects physical access to sensitive areas to be revoked immediately upon termination and keys and cards to be returned or disabled. Both expect documentation.

Start With the Three Lists

If it has been more than a year since anyone compared your door system, alarm panel, and monitoring call list against your actual staff, that is the place to start. Ask your security company for the active credential list, the user code list, and the current call list. Then sit down with your roster and a pen.

If you would like a hand with it, call us at 678-924-7480 or email service@verifiedsecurity.com. We will pull the lists, walk through them with you, and set up the offboarding sheet so this becomes a thirty-minute task instead of a project. If the lists come back clean, we will tell you that too.


Current as of September 2026. We review this post annually.


Scott Hightower founded Verified Security in 2007 and has spent nearly two decades designing, installing, and servicing commercial security systems across metro Atlanta. Verified Security is an authorized Honeywell security provider and specializes in access control, video surveillance, intrusion, and fire alarm systems. Reach Scott’s team at 678-924-7480.