Access Credential Issue and Revoke
Purpose
In an access control log, a credential that should have been revoked looks exactly like a credential that is supposed to be there. The system records that card 4471 opened the loading dock at 23:14 and reports it as an authorized entry, because as far as the panel knows it is one. Nothing in the software will ever tell the customer that the person who carried 4471 was let go in March.
That is why revoke is the half shops skip and the half that matters. Revoking a credential is only possible if somebody wrote down, at issue time, which credential number went to which named human on whose authorization. This procedure guarantees that record exists at issue, that every credential carries an end date rather than living forever by default, and that a revoke is proved against a physical door rather than against a screen that says the change was saved.
Scope
Covers issue, modification, revocation and periodic reconciliation of electronic credentials (cards, fobs, mobile credentials, PIN codes and biometric enrolments) on customer access control systems this shop administers or services, and the mechanical keys that sit alongside them on the same openings.
Does not cover installation, wiring or commissioning of the access control system, owned by the Electronic Access Control Commercial Install SOP. Does not cover restricted key blank stock, cutting authority or the shop's own key inventory, owned by the Key Blank and Key Control Inventory SOP; where a credential change also requires a mechanical key returned or a cylinder re-pinned, that SOP owns the key side and this one owns the electronic side. Does not cover the customer's own employment decisions, which are theirs.
Roles and responsibilities
| Role | Owns | Handoff |
|---|---|---|
| Customer's authorized signer | The only person who may request an issue, change or revoke for their site | Named in writing on a signer list held by the shop, with a phone number the shop sourced; the list is reconfirmed annually |
| Shop administrator | Executes issues and revokes, keeps the credential register, runs the quarterly reconciliation | Sends written confirmation of every change back to the signer the same day |
| Technician | Proves the change at a door, hands over the physical credential, collects returns | Returns the door-test result and the signed handover; a change confirmed only in software is not confirmed |
| Owner or lead | Approves any credential issued without a named holder, and owns the orphan list | Reviews the reconciliation each quarter; an orphan that survives two reconciliations is escalated to the signer's superior |
The handoff worth naming is administrator to technician on proving. Software says saved; a door says revoked. Only one of those is evidence.
Procedure
Step 1: Take the request only from a named signer, verified on a channel you own. Match the requester against the site's signer list and call back on the number the shop holds, not the number the request arrived from. Acceptance: requester matched to the list, callback logged with time and person reached, and the request restated in writing. Wrong looks like an emailed request from a lookalike address asking to issue a credential to a new contractor tonight. Stop rule: a request from anyone not on the signer list is refused and referred to a signer, no matter how urgent it sounds, because urgency is the standard pretext and the shop's only defence is that the list is the list.
Step 2: Capture the holder and the credential as two separate identities. Record the holder's full name, role and employer, and separately the credential's own identifiers: facility code and card number, or the system's internal credential ID, or the PIN's assigned slot. Acceptance: both sets recorded in the credential register, with no credential entered against a blank or generic holder. Wrong looks like a register full of entries reading "contractor" or "spare", which is exactly the population that cannot be revoked because nobody knows who has it. Stop rule: a credential with no named holder is not issued without written approval from the owner or lead, and it is entered on the orphan list the same day if it is.
Step 3: Assign an access group and an expiry date, never an open-ended one. Give the credential the narrowest door set and schedule that lets the holder do the job, and set an end date on every credential without exception. Contractor and temporary credentials expire at 30 days and are renewed by the signer if the work continues; permanent staff credentials carry an annual reconfirmation date. Acceptance: door set, schedule and expiry all populated, with the expiry inside those limits unless the signer has approved a longer term in writing. Wrong looks like a contractor issued the same all-doors, all-hours group as the facilities manager because it was the quickest profile to copy. Stop rule: no expiry, no issue; an open-ended credential is the one that is still working three years after the person left.
Step 4: Prove the issue at a door before handing anything over. Take the credential to one door inside its group and one door outside it, and test both. Acceptance: the credential grants at the in-group door and is denied at the out-of-group door, and both events appear correctly in the system log with the right holder name attached. Wrong looks like a credential that works everywhere because the group was applied to the wrong record. Stop rule: a credential that grants where it should be denied is disabled immediately, before it leaves your hand, and the group is corrected and re-tested. Hazard: never prove a group by locking down an occupied stairwell or an exit path, and never leave a door in a locked-against-egress state between tests, because free egress is required at all times under the life safety code your authority having jurisdiction has adopted.
Step 5: Hand over against a signature, and say what the holder is responsible for. Give the credential to the named holder in person, record the handover with the credential number, and state the two obligations: report a lost credential the same day, and return it on the last day of the assignment. Acceptance: a signed handover naming the credential number and the holder, with the reporting obligation acknowledged. Wrong looks like a stack of cards left at a reception desk for distribution, which converts a controlled issue into an unmanaged one within a day. Stop rule: no named holder present means no handover; the credential stays disabled in the register until it is issued in person.
Step 6: Revoke on the signer's word, inside a stated window, and disable rather than delete. A written revoke request from a signer is executed within 4 business hours; a verbal from a verified signer is executed immediately with written confirmation to follow the same day. Disable the credential rather than deleting it, so its history stays attached to the log. Acceptance: the credential shows disabled with a timestamp, the register carries the revoke reason and requesting signer, and the audit history is still queryable. Wrong looks like a deleted record, which leaves a year of door events attached to a credential number nobody can now identify. Stop rule: a lost or stolen credential is disabled immediately on report and its number is retired permanently rather than reissued to the next person, because a reused number makes the old log entries ambiguous.
Step 7: Prove the revoke at a door, and close the mechanical side. Present the revoked credential at a door that was inside its group and confirm the denial, then check whether the holder also held mechanical keys or a restricted key on those openings. Acceptance: a logged denial event for the revoked credential, plus either the mechanical keys returned and counted, or a written re-pin recommendation to the signer. Wrong looks like an electronic revoke completed cleanly on an opening where the same person still holds a brass key to the override cylinder. Stop rule: unreturned restricted keys on a revoked holder's openings go to the signer in writing the same day with a re-pin recommendation; the shop does not decide for the customer, but it does not let the gap go unrecorded either.
The record this produces
A credential register held per site, plus a change log:
- Signer list with sourced phone numbers and the date last reconfirmed
- Per credential: identifiers (facility code and number, or internal ID), holder name, role, employer, issuing signer, issue date, access group, schedule, expiry date
- The step 4 proving result: in-group grant, out-of-group denial, and the log entries showing the correct holder
- Signed handover with credential number and the acknowledged reporting obligation
- Per revoke: requesting signer, request channel, time received, time executed, reason, disabled rather than deleted, and the step 7 denial event
- Mechanical keys held by that holder on the same openings, returned and counted or flagged for re-pin
- Quarterly reconciliation results and the current orphan list
Readers later: the customer's HR or security manager after an incident, an auditor asking who could open a door on a given night, the shop's own administrator working the next revoke, and an insurer or investigator reconstructing access. A log without a register behind it answers when a door opened but never who opened it.
Worked pass: a quarterly reconciliation that finds three problems
A logistics site with 62 active credentials. The administrator pulls the register against the signer's current roster in the first week of the quarter.
Fifty-eight credentials reconcile cleanly to named, current staff. Four do not, and they fail in three different ways.
The first is an orphan: a credential entered as "night contractor" with no holder name, issued eleven months earlier by a signer who has since left. It has no expiry, which means step 3 was not followed when it was issued. It is disabled first and investigated after, in that order, because an unidentifiable credential with all-hours access is not something to leave live while emails go back and forth.
The second and third are expired-but-active contractor credentials from a roofing job that finished in the previous quarter. Both carry proper holder names and both were issued with 30-day expiries that a previous administrator extended twice by hand without a signer request. They are disabled, and the signer is told in writing that the extensions were made without a request, because the gap here is a process one and hiding it guarantees a repeat.
The fourth is the one that matters. A named holder shows as terminated on the roster, and the register shows his credential revoked on the correct date. Step 7 is run anyway rather than trusted: the card is presented at a door that was in his group and correctly denied. But the mechanical check on the same openings finds he was also issued two restricted keys to the dock override cylinders, and the key-control record shows neither was returned. The electronic revoke was executed properly and the man can still open the dock with brass.
That finding goes to the signer the same day with a re-pin recommendation for the two override cylinders, priced as its own job. The signer approves it that week.
Of 62 credentials, four failed, and only one of the four would have been visible from the access control software alone; the other two were visible only because a register existed to compare the log against. The fourth, the one that mattered, was invisible to both, and surfaced because step 7 asks about brass on a job that looks entirely electronic.
References
- Life safety code as adopted by your authority having jurisdiction, in the edition it has adopted, for the free-egress requirement that gates door testing in step 4; the code binds the facility and reaches your work through the permit and the inspection
- Access control platform documentation for the specific system on disable versus delete behaviour and on how credential history is retained; the two are not equivalent on every platform
- ALOA Security Professionals Association guidance on key control and credential accountability
- See related: Electronic Access Control Commercial Install SOP (the install and commissioning this follows), Key Blank and Key Control Inventory SOP (the mechanical half of step 7), Commercial Master Key System Setup SOP