Access Revocation
Access revocation is the process of withdrawing permissions, credentials, or system access that were previously granted to a user. It is used when access is no longer appropriate, such as when someone leaves an organization, an account is compromised, or a relationship ends. In a third-party context, it typically applies to removing a vendor's or their personnel's access once it is no longer needed.
Access revocation is the removal of previously granted access rights, privileges, credentials, or group memberships from a user or account across relevant systems and applications. Triggering circumstances commonly include employee or contractor termination, account compromise, role changes, and the end of a contractual engagement; in emergency scenarios it may involve revoking all access for a given identity at once. Effective revocation typically encompasses de-provisioning, removing group memberships, and deleting orphaned accounts, and may be performed manually or through automated workflows. In third-party programs, timely revocation depends on maintaining accurate visibility into which external identities hold access; the scope of this term covers the withdrawal of access itself and does not by itself confirm downstream removal in unmanaged or Nth-party systems, nor does it address independent verification that access has in fact been terminated.
Why it matters
In third-party risk management, access granted to external parties is one of the most persistent and easily overlooked exposures. Vendors, contractors, and their personnel frequently receive credentials, system logins, or elevated privileges to perform contracted work, and those permissions often outlive the need for them. When a contractual engagement ends, a role changes, or an account is compromised, access that is not withdrawn promptly becomes a standing point of entry into systems and data. Timely access revocation is the control that closes this gap by withdrawing permissions, credentials, group memberships, and access rights once they are no longer appropriate.
The difficulty in a third-party context is visibility. Revocation can only be as complete as an organization's knowledge of which external identities hold access to which systems. Orphaned accounts, shared credentials, and access granted directly by a vendor within their own environment can all persist after the primary relationship is formally terminated. Because the scope of access revocation covers the withdrawal of access itself, it does not by itself confirm that access has been removed in unmanaged or Nth-party systems, nor does it substitute for independent verification that termination actually took effect.
For these reasons, revocation is best treated as one component of a broader identity lifecycle and offboarding discipline rather than a one-time action. In emergency scenarios such as a compromised account, the ability to revoke all access for a given identity at once can materially limit the window of exposure, but only where accurate identity inventories and functioning de-provisioning processes are already in place.
Who it's relevant to
Inside Access Revocation
Common questions
Answers to the questions practitioners most commonly ask about Access Revocation.
