DSC Blog | Security Industry Insights For Houston TX

The Employee Left in June. Their Badge Still Works.

Written by DSC | August 24, 2026

Think about the last person who left your company. Maybe they moved to a new job. Maybe they retired. Maybe it did not end well.

Now answer one question: can they still get in the building?

Most facility managers say no right away. Then they check the access control system, and the answer changes. A badge from two years ago is still active. A contractor who finished a job last spring still has rights to the roof door. A card marked "TEMP-04" opens everything, and nobody remembers who has it.

This is one of the most common gaps we find in commercial buildings. It is also one of the easiest to fix.

Why old credentials stay active

Nobody decides to leave a former employee's badge working. It happens because the handoff between people breaks down.

Here is the usual chain of events. HR processes the departure. IT shuts off email and network accounts, often the same day, because that process is automated. But the door badge lives in a different system, managed by a different person — maybe the office manager, maybe a facilities lead, maybe someone who left the company themselves last year.

So the email dies and the badge lives on.

The problem grows quietly. One survey of security leaders found that nearly 90% of former employees keep some form of access to company systems after they leave. Most of that research focuses on data and software. Physical access gets even less attention, because there is rarely an alert when it goes wrong. A badge that still works does not send anybody an email. It just works.

Turnover makes it worse. A building with 200 badge holders and 20% annual turnover creates roughly 40 chances a year for something to slip. Over five years, that is 200 chances. It only takes one.

What it actually costs

Most of the time, nothing happens. A former employee has no interest in coming back, and the old badge sits in a junk drawer.

But the exceptions are expensive. The Ponemon Institute's 2026 study on insider risk put the average annual cost of insider incidents at $19.5 million across the organizations it surveyed. Big number, big companies — but the finding underneath it applies to everyone: the longer a problem goes undetected, the more it costs. Incidents contained within 30 days cost far less than incidents that run past 90 days.

An active badge belonging to someone who no longer works for you is exactly that kind of slow problem. It can sit unnoticed for years.

There is a second cost that comes up more often than theft: your records stop being trustworthy. When something goes missing from a stock room, the first thing anyone asks is who badged in. If your system says a person entered who left the company in 2024, you no longer have an answer. You have a mess. That matters for insurance claims, for HR investigations, and for any regulated facility that has to show a clean audit trail.

The audit that takes one afternoon

You do not need new hardware to close this gap. You need a list and two hours.

  1. Pull the full cardholder report. Every access control platform can export one — LenelS2, OpenOptions, RS2, DSX, Avigilon, all of them. Export active credentials with names, groups, and the date of last use.

  2. Sort by last use. Anything that has not been used in 90 days deserves a look. Anything unused for a year is almost certainly dead weight.

  3. Compare the list to your current payroll roster. Ask HR for an active employee list and put the two side by side. Names on the badge list that are not on the payroll list are your problem children. Deactivate them, do not delete them — you want the history.

  4. Hunt down the generic cards. "TEMP," "LOANER," "VISITOR-03," "CONTRACTOR." These are the ones that never get cleaned up because they are not tied to a person. Either assign each one to a named owner or kill it.

  5. Check the contractor and vendor list separately. Cleaning crews, HVAC techs, elevator service, landscapers, IT vendors. These credentials often have wide access and long lives. Confirm every one still has an active contract behind it.

  6. Look at the doors, not just the people. While you are in there, review which groups can reach sensitive areas — server rooms, records storage, chemical storage, cash handling. Access tends to expand over the years and never shrink.

Making it stick

An audit fixes today. A process keeps it fixed.

The single most effective change is tying badge deactivation to the same trigger that shuts off email. When HR marks someone as departed, one person is responsible for both. Put a name on it, not a department.

After that, three habits do most of the work:

  • Run the cardholder audit quarterly. Put it on the calendar the same way you schedule fire extinguisher checks.
  • Use groups, not one-off permissions. When access is granted person by person, nobody can tell later what a role is supposed to have.
  • Set expiration dates on temporary credentials. Most systems support this and almost nobody uses it. A contractor badge that expires on its own is a badge you never have to remember.

If your system supports mobile credentials, they help here too. A phone-based credential can be revoked instantly and cannot be handed to a friend as easily as a plastic card.

Where we come in

If you are not sure how to pull a cardholder report — or you inherited a system nobody has documented — that is a normal place to be. Plenty of buildings we walk into have an access control system installed by a company that is no longer around.

DSC works on nearly every major access control platform, including systems we did not install. We can pull the report with you, walk the list, clean up the credentials, and set up a schedule so it stays clean. It is usually a short visit, not a project.

If it has been more than a year since anyone looked at your cardholder list, it is worth a look. Give us a call at (713) 464-8407 and we will help you figure out who still has keys to your building.