Systems
The badge nobody turned off
Collecting the card at the exit interview feels like the end of the offboarding. The card was never the thing that opened the door, and the record that did is usually held in more places than one team can name.
In short
- The card is not the credential. The credential is a record in an access system, and taking the plastic back does nothing to the record, so an uncollected card and a collected one leave the same door open.
- Revocation is a two-system problem with nothing joining the systems. A termination is recorded in HR and a permission is held in the access platform, and at most sites the connection between them is a person remembering to do something.
- A controller holding a cached allow-list keeps honoring it when the head end is unreachable, which is the behavior that was bought, so a door can open for a revoked credential with no failure visible anywhere.
- Reader-to-panel wiring is the layer nobody audits. Wiegand carries a card number in the clear with no supervision, and OSDP Secure Channel was standardized as IEC 60839-11-5 in May 2020 specifically to close that.
- The only honest test is retrospective: take five people who left in the last year and ask the system, per door, whether their credential would be accepted right now. A site that cannot answer within an hour has its answer.
Every organization with badges has an offboarding step that says collect the card, and almost every one treats that step as the end of the physical access question. It is a reasonable belief and it is the wrong object. The card is a token that carries a number. What opens the door is a record in an access system saying that number is allowed, and that record is untouched by the plastic changing hands.
So the interesting question is not whether the card came back. It is what happened to the record, in every system that holds a copy of it, and how long the gap was. At most sites nobody has ever been asked, which is why the answer is worth finding out before somebody else does.
Why does a returned badge leave the access open?¶
A returned badge leaves access open because the two facts live in different systems and nothing joins them. Termination is recorded by whoever runs payroll and onboarding. Door permission is held in an access control platform, usually administered by facilities or by a contractor, frequently on a server in a closet that the IT team does not consider theirs. The join between those two is a human being remembering to send a message.
That works while the organization is small enough for one person to know everyone. It degrades in a specific and predictable way: it survives the planned departures, where there is an exit interview and a checklist, and it fails on the unplanned ones, which are the departures where revocation matters. A resignation with four weeks of notice gets processed. A dismissal on a Friday afternoon gets processed on Monday, if the person who does it is in.
The second copy is the one people forget. Contractor badges, temporary credentials issued at a front desk, a visitor card that was never returned to the pool, and the credential issued to somebody who changed roles rather than left. None of those has a termination event to hang the revocation on, so none of them is reached by a process built around leavers.
What does the panel do when the server is unreachable?¶
A door controller with no route to the head end falls back to a list it already holds, and it opens doors from that list. This is not a defect. It is the property the system was bought for, because the alternative is a building where a network outage locks everybody out of their own offices, and the fire code has views about that.
The consequence is that revocation is not an event, it is a propagation. A permission removed at the head end reaches a controller when that controller next syncs, and a controller that has been offline since Tuesday is still holding Tuesday's answer. Nothing about this is visible from the administrative screen, which shows the intended state rather than the distributed one. The screen says removed. The door says yes.
Ask two questions of whoever maintains the system. How long, at most, between a change at the head end and that change being true at the furthest door. And what the system does when that sync has not happened for a week: does it report the staleness anywhere, or does it continue regardless. The second question is the one that separates a platform that can be audited from one that can only be believed.
What is on the wire between the reader and the panel?¶
On most installed sites the reader-to-panel link is Wiegand, which sends a card number as a sequence of pulses with no encryption, no authentication and no supervision of the line itself. A device spliced into that run can read every number that crosses it and can present a number of its own, and the panel has no means of telling the difference, because the protocol gives it none.
The replacement exists and is not new. OSDP, the Open Supervised Device Protocol (opens in a new tab) carries a secure channel. The Security Industry Association describes it as "high-end AES-128 encryption (required in federal government applications)", and says the protocol "constantly monitors wiring to protect against attack threats". It communicates in both directions rather than one. The IEC approved it as an international standard in May 2020 and published it as IEC 60839-11-5:2020.
The reason this belongs in an argument about revocation is that supervision and bidirectionality are what make a door answerable. A one-way protocol cannot report that a reader was removed from the wall, cannot confirm that a credential list arrived, and cannot be asked anything. Replacing it is a capital project rather than an afternoon, and it does not have to be done everywhere at once. It has to be done at the doors where the answer matters.
Is this over-engineering for a building with one door?¶
For a single-tenant office with one controlled entrance and twelve staff, most of this is over-engineering and saying otherwise would be selling. One person knows everyone, the list is short enough to read, and a quarterly look at the credential list finds anything that has gone wrong. The argument earns its cost somewhere specific, and it is worth naming the threshold rather than implying it is universal.
Three conditions make it real, and one is usually enough. The site has doors that protect something other than office furniture, such as a plant floor, a pharmacy cupboard, a server room or a bonded store. The population includes people the organization does not directly employ, because contractors and agency staff are where the credential lifecycle has no owner. Or there is an auditor, an insurer or a customer who will at some point ask for evidence rather than assurance.
Where none of those holds, collect the card and keep the list short. Where one of them holds, the cost of finding out during an incident is the entire reason to find out now.
The audit that settles it¶
Take five people who left in the last twelve months, chosen to include at least one contractor and at least one unplanned departure. For each, ask the access platform a single question per controlled door: would this credential be accepted at this reader right now. Not was it removed. Would it be accepted.
Three outcomes are possible and each tells you something different. The system answers in minutes and every answer is no, which means the process works and you now have evidence of it rather than a belief. The system answers and some answer is yes, which is a finding with a name, a door and a date attached. Or the system cannot answer the question in the form it was asked. That is the most common result and the most useful one: a platform that cannot report its own effective state cannot be audited by anybody, including the people relying on it.
Sources
- 1.Open Supervised Device Protocol (OSDP) (opens in a new tab), Security Industry Association
Next step
Send us five names and a door list.
Five people who have left in the last year, and the doors that matter. We will give you the specific queries to run against your access platform to establish whether each credential is still accepted, and tell you which of the answers your system is not able to produce.
- Phone
- (214) 723-2510
- Reply
- A person replies, not a sequence: within one business day, from someone who would be on the engagement.
Related reading
- Security5 min read
The card number is not a credential
Most badge systems authenticate by reading a number off a card and comparing it to a list. That is an identifier, not proof of anything, and the federal standard that governs the largest deployment of badges in the country removed the equivalent mechanism outright.
- Systems5 min read
The update path is the product
A device that cannot be updated safely is a device with a fixed expiry date, and the date is set by the first security advisory nobody can act on. The update path is decided in the first two weeks of a hardware project and paid for over its whole life.
- Systems9 min read
What an estate review actually inspects, in order
Almost nobody replacing an IT provider has a current inventory, because the outgoing provider holds it. This is the method for building one from the estate rather than from an interview, and what each pass usually turns up.
- Delivery8 min read
The handover pack, published before you need it
Every managed service agreement promises reasonable cooperation on the way out. Nobody says what the artifact is. Here is ours, section by section, so you can hold it against whatever your current provider has agreed to.