Show Notes
The Credential That Outlives the Work
Vendor access is not always a metal key on a ring. It can be a badge, a network credential, a service code, or another credential that opens a mechanical room, server closet, loading dock, or even a fire alarm panel. The problem begins when the work ends but the credential does not.
This episode examines the vendor-access life cycle gap: a contractor may finish programming a building automation controller, yet a temporary badge can continue opening the mechanical room years later. The access-control system may be operating exactly as configured. The failure is often procedural: nobody tells the system that access should end.
Why Orphaned Vendor Access Matters
Unmanaged access is more than a theoretical security concern. It creates a liability that building teams may not know they are carrying. The risk is not limited to stolen equipment or a dramatic intrusion. It is also an operational-resilience issue: who can reach systems that could disrupt the building if they are changed, damaged, or used improperly?
- A former vendor employee may still have an active badge after leaving the vendor.
- A contractor may retain access to return for convenience, such as using a loading dock after the job is complete.
- A badge can remain active because it was extended repeatedly or marked temporary without a true end date.
- A vendor relationship can outlive a specific work order, causing access to persist by default rather than by a deliberate decision.
The episode shares an anonymized review in which an active badge belonged to a person no longer employed by the vendor. The vendor confirmed that the individual was gone, but the building badge still worked. That was not a technology failure. No one had directed the system to remove the access.
The Core Problem: Access Granted by Default
Vendor access often accumulates because the building has an access list that gets updated only when someone remembers. That is not a reliable process. It allows access to become a ghost: it outlives the project and can even outlive the vendor relationship itself.
The critical distinction is between a vendor relationship and an active need for access. A vendor may remain an approved service provider, but that does not mean every technician who worked on a prior job should continue to enter sensitive rooms. Access should be tied to current work, not retained automatically because a company has worked in the building before.
A Simple Vendor Access Lifecycle
The recommended starting point is straightforward: tie vendor access to an active work order. When the work is complete, the access should be reviewed and removed unless there is a clear, current reason to retain it.
- Grant access for a defined work purpose.
- Associate that access with an active work order rather than a general vendor relationship.
- Set a regular schedule to review the access list.
- Compare active credentials against active contracts and current work.
- Remove access that no longer matches a valid need.
This approach does not require replacing an access-control platform. It requires managing the life cycle around the platform. The process can be improved without ripping out the underlying technology.
Treat Access Reviews Like Maintenance
Buildings test generators regularly so failures are discovered during a controlled test rather than during a blackout. Vendor access should be handled with the same discipline. Pull the access list, compare it to active contracts, and remove the entries that no longer align. That is the test.
The review must be a scheduled event, not a task performed only when someone happens to remember. Put it on the calendar with the same seriousness as a fire drill. Recurring discipline is what turns a list of credentials into a manageable control.
Shared Accountability Between Facilities and Security
No single team typically sees the complete picture. Security owns the access-control system, while facilities knows which vendors are actively working on-site and why. If the process is treated as facilities-only, an important door can remain open. If it is treated as security-only, the system may not reflect current vendor activity.
The key is to make the intersection of those responsibilities explicit. Facilities and security should participate in a scheduled review that connects system records with active contracts and work orders. The episode emphasizes that this shared responsibility is often where access management falls through the cracks.
Start With the Highest-Impact Doors
A complete cleanup does not have to happen in one day. Start with the access that could cause the greatest operational impact if it is misused or left unmanaged.
- Mechanical rooms
- Electrical rooms
- IT closets
- Fire alarm panels
Not every door carries the same consequence. A vendor who can reach a fire alarm panel deserves more immediate attention than a vendor who waters plants. Prioritizing critical infrastructure makes the process practical and focuses effort where unmanaged access can break something.
Practical Homework for Building Teams
Begin with the list you already have. Pull the building access list and compare it with active contracts. Expect to find names you do not recognize. Finding those names is not a sign that the review failed; it is the reason to perform the review.
The goal is not to make vendor maintenance harder. It is to ensure that necessary access remains current, purposeful, and accountable while old access is removed. A simple, recurring vendor-access review can close doors that were unintentionally left open.
Vendor Access Should End When the Work Ends
Every commercial building depends on outside vendors. Contractors and technicians may need access to building automation controls, mechanical rooms, electrical rooms, IT closets, loading docks, or fire alarm panels. To get their work done, they receive badges, credentials, or service codes.
That access is necessary. The risk begins when it survives longer than the work that justified it.
A temporary badge may be extended. A contractor may finish programming a building automation controller. A vendor may remain in the building’s broader service ecosystem even though the individual technician is no longer assigned to the site. Over time, credentials can remain active simply because nobody made a decision to end them.
This is the vendor-access life cycle gap: the work has an end date, but the access does not. The result is an orphaned credential that can continue opening sensitive parts of a building long after the project is complete.
Why Old Badges and Credentials Create Building Risk
It is easy to frame unmanaged vendor access as a security issue alone. It is a security issue, but it is also an operational-resilience problem. Building teams must consider not only whether someone could take an improper action, but also what systems they can reach and what could be disrupted if that access is used inappropriately.
An active credential may open more than a common entrance. It may provide a path to critical infrastructure. Mechanical rooms, electrical rooms, server closets, and fire alarm panels are not ordinary spaces. Access to those areas has consequences because the systems inside them support building operations.
The risk is not always a dramatic event. A former vendor employee may keep a badge after leaving the company. A contractor may return to use a loading dock because it is convenient. Neither example needs to begin with an elaborate intrusion to create a problem for the property. Convenience for the person retaining the credential becomes risk for the building.
One anonymized access review found an active badge tied to a person who no longer worked for the vendor. When the building contacted the vendor, the company confirmed that person was no longer employed there. Yet the badge still worked.
The access-control system had not malfunctioned. It had done what it was told to do. The problem was that nobody had told it to do anything different.
The Problem Is Usually the Process, Not the Platform
Buildings often assume that an access-control system will somehow keep its own records current. It cannot. A system can enforce access rules, but it cannot determine on its own whether a contractor has completed the work, whether a contract is still active, or whether a vendor employee has left the company.
Those are operational decisions. When they are not connected to the access-control process, credentials remain active by default.
Many properties have an access list that someone updates when they remember. That is not a dependable vendor-access process. It is an informal habit, and informal habits do not provide the consistency needed for sensitive building access.
The good news is that this gap can be fixed without replacing the access-control system. The answer is lifecycle management: a repeatable way to connect vendor access with a current business purpose, review it on a schedule, and remove it when that purpose ends.
Use Active Work Orders as the Basis for Access
A simple rule creates a stronger foundation: vendor access should be tied to an active work order, not to the fact that a vendor has worked for the building in the past.
A vendor relationship and a work assignment are not the same thing. A company may still be an approved vendor, but a technician who completed a prior job may have no current reason to enter the building. Retaining access simply because the vendor relationship persists turns a temporary operational need into a long-term default.
Tying access to active work creates a clearer question for every credential: what current work justifies it? If there is no active work order, active contract, or defined need, the access should be reviewed for removal.
This does not mean slowing down urgent maintenance. It means creating clarity before and after the work. The building can grant needed access for a defined purpose, while also establishing a point at which the access must be reconsidered.
Make Vendor Access Reviews a Scheduled Control
The episode compares access reviews with generator testing. A building tests a generator regularly so a failure is discovered during a controlled test rather than during a blackout. Access should receive similar discipline.
The practical review is straightforward:
- Pull the current access list.
- Compare the names and credentials against active contracts.
- Confirm which vendors and individuals are currently working on-site.
- Identify entries that no longer match a current need.
- Remove access that is no longer justified.
The important factor is not complexity. It is consistency. The review must be scheduled rather than dependent on memory. Putting it on the calendar like a fire drill gives the task a defined cadence and makes it less likely that outdated access will quietly accumulate.
A review should not be treated as a one-time cleanup project. A one-time effort may find old badges, but a recurring process is what prevents the same gap from returning.
Facilities and Security Must Share the Intersection
Vendor access often falls through the gap between two valid responsibilities. Security may own the access-control system. Facilities may own vendor relationships, service schedules, and on-site work. Each team has information the other needs.
Facilities can often identify which vendors are actively working in the building and which assignments are complete. Security can determine what credentials remain active and what rooms those credentials can open. Neither function sees the whole picture alone.
That is why access review should not become a facilities-only activity. A facilities-only process can leave security controls disconnected from the system of record. A security-only process can leave the access list disconnected from actual maintenance work.
The responsibility that must be named is the intersection: who ensures that the vendor record, work status, and active credential agree? A scheduled review creates a place for that accountability to happen rather than leaving it to an assumption.
Prioritize the Access That Can Disrupt Critical Systems
Properties do not need to solve every access issue in one day. The most practical approach is to start with the doors and systems that matter most to building operations.
Focus first on access to:
- Mechanical rooms
- Electrical rooms
- IT closets
- Fire alarm panels
These spaces should rise to the top because the systems they contain can affect the building directly. The episode makes the distinction clearly: a vendor who can reach a fire alarm panel warrants more immediate attention than a vendor who waters plants.
Prioritization does not imply that lower-risk access is unimportant. It recognizes that teams need a manageable starting point. By reviewing high-impact access first, a property can reduce meaningful exposure while building the discipline needed to expand the process across the full access list.
A Practical Starting Point
For building owners, property managers, facilities teams, and security teams, the first action is simple: pull the access list and compare it with active contracts. Expect to see names that are unfamiliar. That discovery is useful. It reveals where the building’s current records and its actual vendor activity have separated.
From there, document the reason each credential remains active. Confirm that the person is still associated with the vendor and has a current need for the access. Remove credentials that no longer align with active work.
The objective is not to make necessary vendor maintenance difficult. Buildings need vendors to perform critical work. The objective is to make access purposeful, current, and accountable. When work ends, access should not continue indefinitely simply because nobody decided otherwise.
Close the Doors That Were Left Open
Orphaned badges and credentials are often invisible until someone performs a review. They can remain in place for years because temporary access was extended, because a vendor relationship outlived an assignment, or because no one owned the handoff between facilities and security.
A vendor-access lifecycle does not require a complex transformation. Tie access to active work orders. Review the list on a schedule. Compare it with active contracts. Start with critical infrastructure. Give facilities and security shared accountability for the results.
Those controls help protect building operations while preserving the access vendors need to maintain essential systems. For more discussion on building technology, security, and operational accountability, listen to this episode of Built, Wired & Secured.