Ask a facility manager how many people can open their building right now and you will get an estimate. Ask the system and you will get a different number. Here is how to find out which one is true.

Where I am standing

My company sells a service that keeps credential lists current, so I have an obvious interest in you discovering that yours is not. What I would say is that the audit below costs nothing, needs no vendor, and works on any system from any manufacturer. Plenty of organizations run it, find they are in decent shape, and carry on. That is a fine outcome and I would rather you knew.

Access control gets bought as a security purchase and then quietly becomes an administrative one. The hardware works for a decade with almost no attention. The database underneath it degrades from the first month, and nothing tells you it is happening, because a credential that should have been deactivated behaves exactly like a credential that should not have been.

Which is the uncomfortable part. A stale credential list produces no alarms, no faults, and no symptoms. It surfaces during an incident, during an insurance review, during a due diligence exercise before a sale, or during an argument about who was in the building on a particular Tuesday. By then it is a discovery rather than a finding.

So this is an audit you can run yourself, in a week, on any system. Ten steps, each with a specific thing to check and a realistic account of what you are likely to find.

01 Why the list is always wrong

This is not a story about carelessness. It is a story about an asymmetry built into how access gets managed, and it happens in well run organizations as reliably as in badly run ones.

Granting access has an owner. Somebody needs to get into a room, they cannot, they raise it, and it gets fixed that day because a person is inconvenienced until it is. There is urgency, a requester, and a clear moment of completion.

Revoking access has none of that. Nobody is inconvenienced by a credential that still works. No ticket is raised. Nobody follows up. The only thing standing between a departure and a deactivation is somebody remembering, at a moment when they are busy with an actual handover.

So the list drifts in one direction only. It never gets shorter by accident. Over five years, with ordinary turnover and no deliberate process, the gap between who should have access and who does becomes substantial, and the organization has no way of noticing because nothing about the system looks any different.

Run the check

Before you look at anything, write down your guess: how many active credentials exist in your system?

What you will find is that the real number is higher than the guess, usually by a margin that surprises the person who made the guess.

What to do is keep the written guess. The gap between it and reality is the most useful single figure this audit produces, and it is the number that gets a process funded.

02 Get the list out of the system

Step one is producing a current export of every active credential. On most platforms this takes a few minutes. If it takes you longer than an afternoon, or if it requires calling your vendor, you have already found something worth knowing.

The columns you want are the credential identifier, the person it is assigned to, the access groups it belongs to, the date it was issued, and the date it was last used. Some systems will give you more. Almost all will give you those.

Pay particular attention to last used, because it is the most informative column in the export and the one people ignore. A credential that has not been presented to a reader in six months belongs to somebody who has either left, changed roles, or never needed the access in the first place. All three are worth knowing and all three are invisible without that column.

Sort by last used, oldest first, and read the top of that list. You will recognize some of the names. That recognition is the point of the exercise.

Run the check

Export all active credentials, sort by last used date, oldest first, and read the top fifty rows.

What you will find is credentials that have not been used in over a year and are still active, and at least a few names nobody in the room can place.

What to do is not deactivate them immediately. Work out who they belong to first, because a credential nobody recognizes is a more interesting question than a credential nobody uses.

03 Reconcile it against your actual roster

Now put the credential export beside a current employee roster from HR or payroll, and compare them properly rather than by eye.

Three categories fall out. People on the credential list who are not on the roster, which is the group everyone expects and the reason most people run this audit. People on the roster with no credential, which is usually harmless but occasionally reveals somebody who has been propping a door for eight months because their badge never worked. And people on both lists whose access no longer matches their role, which is chapter six and is the largest category by some distance.

Expect friction here. HR and facilities frequently do not share data, sometimes for good reasons, and the first time anybody asks for a roster to compare against badge records there is a conversation about why. Have that conversation. It is considerably easier to have it now, as part of a housekeeping exercise, than during an investigation.

Also worth noting: name mismatches are not always leavers. They are marriages, legal name changes, nicknames in one system and legal names in the other, and duplicates created when somebody was issued a second badge after losing the first. Resolve those before concluding anything.

Run the check

Match the credential export against the current roster and list every credential holder who is not on it.

What you will find is departures that were never deactivated, plus a set of names that turn out to be duplicates or spelling variants rather than people.

What to do is deactivate the confirmed departures the same day, and fix the duplicates so the next audit is cleaner than this one.

04 Contractors, vendors, and service providers

This is the worst category in every building I have ever looked at, and the reason is structural rather than cultural.

Employees have an HR record with a start date and an end date, so at least in principle there is something to reconcile against. Contractors have none of that. A cleaning company, an HVAC service provider, an elevator contractor, an IT vendor, a landscaping crew, a vending supplier. Each was issued credentials at some point by somebody who has possibly also left.

Then the contract ends, or the vendor is replaced, or the individual working for that vendor moves on, and the badge goes with them. There is no leaver process because the person was never a joiner in your system in the first place.

Two things make this tractable. First, credentials issued to contractors should carry an expiry date matching the contract rather than running indefinitely, which almost every access platform supports and almost nobody enables. Second, the vendor should be contractually obliged to tell you when the individual holding your badge stops working for them, and to return it. That is a clause, not a favor, and it belongs in the service agreement.

Run the check

List every non-employee credential and name the company, the contract, and the contract end date for each.

What you will find is credentials belonging to companies you no longer use, and credentials with no expiry date at all.

What to do is set an expiry on every contractor credential going forward, dated to the contract rather than to somebody's memory.

05 Visitors and temporary credentials

Temporary credentials are issued in a hurry, at a front desk, by somebody being helpful. That is exactly the right thing to do operationally and exactly the wrong conditions for record keeping.

The pattern is familiar. A visitor badge goes out, the visitor leaves without returning it or returns it to a drawer nobody empties, and the credential stays active because deactivating it was nobody's specific job. Multiply by a few years and there is a population of live credentials in circulation that no list accounts for.

The fix is not more discipline at the front desk, because the front desk is doing a different job under time pressure. The fix is that temporary should mean automatically expiring. A visitor credential that stops working at the end of the day does not depend on anybody remembering anything, which is the only kind of control that survives contact with a busy reception.

Run the check

Count your active visitor and temporary credentials, then physically count how many badges are in the drawer.

What you will find is that those two numbers do not match, and that the difference is credentials out in the world somewhere.

What to do is configure temporary credentials to expire automatically, then deactivate every unaccounted one in the current pool and start the count again from a known number.

06 Access creep in long-serving staff

This is the largest category and the one nobody looks for, because everybody involved is a current employee doing their job properly.

Somebody joins in a warehouse role and gets warehouse access. Two years later they move into scheduling and get office access added. Later they cover for a supervisor and get the supervisor group. Then they move to a different site and get access there too. At no point in that sequence does anybody remove anything, because removing things requires a decision and adding things only requires a request.

After a decade you have people who can open almost every door in the organization, not through any failure of judgment but through the accumulation of a series of individually reasonable decisions. If one of those credentials is later lost, cloned, or used by somebody it was not issued to, the exposure is the sum of a career rather than the requirements of a role.

The principle is that access should reflect the job somebody does now rather than the jobs they have done. Applying that does not require a policy document. It requires looking.

Run the check

Pick your three longest-serving employees and list every door each of them can currently open.

What you will find is that each of them can open considerably more than their current role requires, and that they did not know it either.

What to do is add a review of existing access to your internal transfer process, so that role changes subtract as well as add.

07 The doors your system does not control

Step away from the database for a day and walk the building, because a perfect credential list is worth nothing at a door that is standing open.

Look for propped doors, and when you find one, work out why rather than simply closing it. A door held open with a wedge is almost always somebody solving a real operational problem in the only way available to them: a delivery route with no convenient credentialed entry, a smoking area on the wrong side of a locked door, a badge reader that takes too long when your hands are full. Removing the wedge without solving the underlying problem produces a new wedge by Thursday.

Then look at mechanical override. Almost every access controlled door also has a key cylinder, and the key system is a parallel access control system that is usually older, less documented, and never audited. Ask who holds a master key. The answer is frequently a list nobody has updated since the building opened.

Also worth checking: doors that were credentialed at some point and have since been left on a permanent unlock schedule that outlived its reason, and secondary entrances that were never brought into the system at all.

While you are walking the doors

Verify that access controlled egress doors release on a fire alarm. That interface breaks whenever either system is serviced, and each trade tests only its own side. It is a life safety question rather than a security one, and if nobody can tell you when it was last tested end to end, treat it as untested.

Run the check

Walk every exterior and restricted door at the busiest hour of your day, not at eight in the morning.

What you will find is at least one door propped for a reason that makes complete sense to whoever propped it.

What to do is fix the reason. A door held open is a design problem being solved by staff, and they will keep solving it until you solve it properly.

08 Credentials that are not badges

The card is the credential everybody audits. It is rarely the only one in circulation.

Keypad codes get shared verbally, written on the underside of things, and passed to new starters by colleagues rather than issued by anybody. A code has no holder, so it cannot be deactivated for a specific person. It can only be changed for everybody, which is why in practice it never is.

Mobile credentials live on personal devices, which leave with their owners immediately and completely. If your leaver process covers collecting a plastic card but says nothing about revoking a phone credential, then it covers the easier half.

And then keys, which deserve their own paragraph. Mechanical keys are a complete parallel access system operating alongside your electronic one, typically with no database, no audit trail, and no revocation mechanism beyond changing a cylinder. Most organizations that run a careful badge audit have never once audited their keys, and the key system is the one where a departure genuinely cannot be undone remotely.

Run the check

List every way a person can open a door in your building: card, fob, PIN, mobile, mechanical key, remote release.

What you will find is more routes than the access control system knows about, and at least one with no record of who holds it.

What to do is bring each route under the same leaver process. Anything outside that process is a credential you cannot revoke.

09 Can you actually produce the audit trail?

The whole argument for access control over locks is that it produces a record. It is worth confirming that yours does, before the day somebody asks.

Test it properly. Pick a specific door and a specific date roughly six months back, and produce a list of every credential presented at it. Time how long that takes and note who had to be involved. If the answer requires calling your vendor, then the record exists but you do not have practical access to it, which is a different situation from the one you thought you were in.

While you are there, establish three things. How far back the history goes, because retention is a setting and it is often shorter than people assume. Who in your organization is permitted to pull it. And whether pulling it is itself logged, which matters more than it sounds when the question is ever about an internal matter.

One caution worth raising with your own counsel rather than resolving from an article. Badge data is employee data, and using it for purposes beyond building security touches workplace privacy expectations and, in New York, notice requirements around electronic monitoring of employees. Build the capability, then have somebody qualified write the policy governing its use. Doing it in that order is considerably easier than the reverse.

Run the check

Produce a full access log for one door on one day six months ago. Time it.

What you will find is either that it takes two minutes, or that nobody in the building has ever done it.

What to do is make sure at least two people can do it, and write down how, because the day you need it is not the day to learn.

10 Keeping it current once the audit is over

Here is the part that decides whether any of the preceding work mattered. An audit is a snapshot. The problem is a flow, and a snapshot does not fix a flow.

Every organization I have watched do this well has the same two things, and neither is technology. The first is that a named person owns credential administration as a defined part of their job rather than as something they absorb. The second is that specific events trigger a credential action automatically: a hire, a departure, a role change, a contractor starting, a contract ending, a badge reported lost. Written down, and attached to whatever process already handles those events.

The failure mode is predictable and I have seen it many times. The audit gets run, the list gets cleaned, everybody feels considerably better, and eighteen months later it has drifted back because the underlying asymmetry from chapter one was never addressed. The credentials went out for reasons and came back for nobody's.

Realistically there are two workable answers. Assign it internally to somebody whose job description says so and who has time for it, then audit annually to check the process is holding. Or hand the function to somebody outside the organization who does it as their actual work, which is the service my firm provides and which exists precisely because the internal version so often gets absorbed by whoever already has a full job.

Both work. What does not work is assuming it will happen because it obviously should.

The audit, in one place

  • Write down your guess before looking, then compare it to the real number
  • Export active credentials with issue date and last used date
  • Sort by last used, oldest first, and read the top of the list
  • Reconcile against the current roster from HR or payroll
  • Resolve duplicates and name variants before concluding anything
  • List every non-employee credential with its company and contract end date
  • Set expiry dates on all contractor credentials going forward
  • Count active visitor credentials against badges physically in the drawer
  • Configure temporary credentials to expire automatically
  • Check what your three longest-serving employees can open
  • Add access review to your internal transfer process
  • Walk every door at the busiest hour, and fix the reason for any that are propped
  • Verify egress doors release on fire alarm
  • Find out who holds mechanical master keys
  • List every non-badge route: PINs, mobile credentials, keys, remote release
  • Produce a six month old access log for one door, and time it
  • Confirm retention period, who may pull history, and whether that is logged
  • Name the person who owns credential administration from here on
  • Attach credential actions to hire, leave, transfer and contract events

Nineteen items, and most of them are an afternoon with a spreadsheet rather than a project. The organizations that never have a problem with this are not the ones with the newest systems. They are the ones where somebody decided the list was theirs.

Want somebody to run this with you?

We will do the audit on any access control system regardless of who installed it, and tell you what we find in writing. If you would rather not own the ongoing administration afterward, our Customer Access Maintenance program takes it off your team entirely: adds, removes, visitor credentials, group changes, and the reporting somebody eventually asks for.

About the author

David J. is the founder of GSMG Inc., a security and life safety engineering firm formed in 2011 and headquartered in Rochester, New York. Its New York State licensed Professional Engineers design access control, intrusion, video and fire alarm systems, and its Customer Access Maintenance program manages day to day badging for clients who would rather not. Related reading: what to check before you sign a security or fire alarm contract.

This article is general operational guidance, not legal advice. Employee badge data carries privacy and workplace monitoring considerations that vary by jurisdiction. Have your own counsel write the policy governing how access records are used.