The typical sequence when an employee is terminated: HR processes the termination in the HRIS, IT deactivates the network account, and someone submits a request to whoever manages physical security to deactivate the access badge. That last step happens days later, sometimes weeks later, and occasionally not at all. In buildings where access control management sits with a facilities team that doesn’t have a real-time integration with the HR system, terminated employees retain building access long after their other credentials have been revoked. The risk isn’t theoretical — insider-threat incidents and data theft cases consistently involve people whose building access wasn’t revoked on the day of termination.

Why same-day deprovisioning rarely happens without an integration

The gap between HR termination and physical access revocation exists because the two systems don’t talk to each other by default. An HRIS like Workday, ADP, UKG, SAP SuccessFactors, or BambooHR manages the employment record. The access control system — whether that’s Lenel, Software House, Genetec, Brivo, or Verkada — manages the door access record. Without an integration between them, updating one requires a human to notice that something happened in the other and take action manually.

Manual workflows fail for predictable reasons: the person responsible for badge management isn’t always notified in real time when HR processes a termination. HR terminations happen on the last day the person is in the building (sometimes before), but the deactivation request may sit in a queue until the facilities team’s next scheduled review. Involuntary terminations — where time sensitivity is highest — are also the cases where the normal notification workflow is most likely to be bypassed in the urgency of the moment. Mobile credential revocation reduces some of this risk by enabling faster credential deactivation — a mobile credential can be revoked within seconds compared to a proximity card that requires manual badge collection or database deactivation — but revocation speed only helps if the deactivation is triggered in the first place.

What an HRIS integration actually does

An HRIS-to-ACS integration automates the synchronization of employee lifecycle events from the HR system to the access control system. At minimum, this covers three event types: onboarding (new hire → create cardholder record with appropriate access group), role change (position change → update access group to match new role), and offboarding (termination → deactivate cardholder record on the effective date).

The integration is typically implemented as one of three mechanisms:

  • Direct API integration: The access control platform has a published integration with the specific HRIS. Common pairings include Brivo with BambooHR, Verkada with Workday, and Lenel with SAP SuccessFactors. Direct integrations trigger near-real-time synchronization — when HR processes the termination, the ACS record is deactivated within minutes.
  • Identity provider (IdP) intermediary: The HR system feeds an identity provider (Okta, Azure AD, Google Workspace) that manages the authoritative user record, and the ACS integrates with the IdP rather than directly with the HRIS. The IdP becomes the single source of truth for user status across IT and physical security systems. This is the architecture that enables true same-day deprovisioning — when IT deactivates the network account in the IdP, the access control badge is deactivated simultaneously.
  • CSV/file-based integration: The HRIS generates a personnel file export on a scheduled basis (nightly, twice daily), and the ACS imports the updated file to sync records. This is the most commonly deployed “integration” in commercial buildings — and it has an inherent delay equal to the export schedule. A nightly export means a person terminated at 3 p.m. has building access until the next morning’s import run.
The file-based integration trap: Many buildings believe they have HRIS-ACS integration because their access control vendor set up a nightly CSV import from HR. That is not the same as real-time deprovisioning. A nightly import has a maximum 24-hour deprovisioning delay and a practical average of 12–18 hours. For involuntary terminations, that window matters. Building owners evaluating access control platforms for HR integration should confirm whether the integration is event-driven (near-real-time) or scheduled (batch), and what the batch interval is. The cloud vs. on-prem access control post covers the platform selection variables that affect integration capabilities over a 10-year horizon — cloud-native platforms with published HRIS APIs typically offer better real-time integration options than legacy on-prem systems with flat-file interfaces.

The access group provisioning problem

Deprovisioning isn’t the only HRIS integration challenge. Provisioning — giving a new employee the right access groups on day one — is equally inconsistent without automation. The typical manual provisioning workflow involves a manager submitting an access request form, someone in facilities reviewing and approving it, and the badge being issued with access groups selected from a list that may or may not reflect the actual access needs of the new role.

Over time, this workflow produces access creep: employees accumulate access permissions from multiple role changes, project assignments, and manager requests, and no one deprovisioning pass removes the accumulated permissions that no longer apply. An employee hired in accounts payable who moved to IT three years ago may still have accounts payable physical access because no one thought to revoke it when the role changed. An HRIS integration that triggers access group updates on role changes — not just on hire and termination — addresses access creep systematically rather than relying on periodic manual audits.

Integration trigger Without HRIS integration With real-time HRIS integration
New hire Badge issued within days to weeks; access group may not match role Cardholder record and access group created on first day, provisioned from role definition
Role change Access rarely updated; old access retained, new access may not be added Access group updated automatically on effective date of role change
Involuntary termination Deactivation 1–5 days after termination; manual badge collection required Cardholder record deactivated within minutes of termination in HRIS
Leave of absence Access often not suspended; employee retains building access while out Access suspended on effective date; reinstated on return date
Contractor/temp expiry Credential may remain active indefinitely; no automatic expiry Expiry date synchronized from HR record; credential deactivated automatically

What the deprovisioning gap actually costs

The cost of a deprovisioning gap isn’t always an incident — it’s sometimes the audit finding, the insurance claim exclusion, or the compliance gap discovered when a customer or regulator asks for evidence of access control practices. Industries with regulatory access control requirements — healthcare (HIPAA physical safeguards), financial services (SOX), and government contractors (NIST 800-171, CMMC) — have explicit requirements for timely access revocation that a manual deprovisioning workflow may not satisfy. An audit finding that terminated employees retained access for days after termination can generate regulatory findings independent of whether any incident occurred.

For buildings without regulatory drivers, the cost is incident probability and incident consequence. A terminated employee with retained building access and a reason to misuse it — taking proprietary data, damaging equipment, or confronting colleagues — creates a liability that was avoidable with a $20,000–$50,000 integration that would have closed the gap. The visitor management integration post covers a related discipline — temporary credential lifecycle management for visitors — that faces a similar risk if the VMS doesn’t automatically deactivate credentials on visit expiry. Our access control services for Atlanta and Southeast commercial buildings include the HRIS integration scoping that evaluates what level of synchronization each building’s HR platform and ACS combination can actually support, and whether an IdP intermediary is needed to bridge a gap the two systems can’t close directly.

The OSDP and reader infrastructure question

HRIS-ACS integration operates at the software layer — it is entirely independent of the reader hardware. A building with Wiegand readers gets the same deprovisioning automation as a building with OSDP readers, assuming the ACS panel has an HRIS integration. The reader protocol affects security at the reader-to-panel communication level; the HRIS integration affects the speed and accuracy of cardholder record management at the database level. The two are complementary, not substitutes. The OSDP vs Wiegand post covers what the protocol upgrade at the reader layer adds to overall access control security — which is real, but does not address the deprovisioning gap that an HRIS integration does.

Evaluating access control for HR integration in Atlanta or the Southeast?

We design and install access control systems for commercial buildings in Atlanta and the Southeast — including the HRIS integration scoping, platform compatibility review, and access group structure that determines whether HR-driven deprovisioning actually closes the termination-day gap.