Offboarding checklist for security systems: cameras, alarms and intercoms
When someone leaves, everyone thinks of the laptop, the email account and the access badge. Almost nobody thinks of the camera app on their phone, the alarm code or the recorder login. That is how a former employee is still watching two years later, and nobody knows.
Short answer
How do you revoke access to security cameras when an employee leaves?
By giving everyone their own account and managing those accounts in one place. Then you remove that one person when they leave, and everything else keeps working. With a shared login you can’t: you would have to change the password for everyone, and in practice that doesn’t happen.
If the camera system is linked to your Active Directory, it follows automatically. Nx Witness syncs every ten minutes by default, and someone removed from AD can no longer log in to the cameras after that. Without the link you delete the user once, and any active sessions are closed straight away.
Why it goes wrong
Why do security systems get forgotten in offboarding?
Because they sit outside IT. The offboarding checklist from HR and IT covers the network, email and laptop. The cameras were installed by a contractor years ago, the alarm code is on a note at reception and the intercom app has its own account. Nobody owns it, so nobody ticks it off.
With one site that is manageable. With five sites, each with its own recorder, it becomes a round trip nobody makes. When we take over systems we see it again and again: accounts of people who left years ago, and an admin password that never changed because “everyone uses it”.
Checklist
What belongs in the security part of an offboarding checklist?
Add these points to your own leaver procedure. They complement what IT already does.
- Camera system. Remove or disable the personal account, at every site. With an AD link this happens automatically.
- Camera app on the phone. Disconnect a cloud account on their own email address from your system, even if the phone is private.
- Shared logins. Did the person know a shared or admin login? Then that password changes now. And after that, replace the shared login with personal accounts.
- Alarm. Remove the personal alarm code or the user in the alarm app.
- Intercom and doors. Revoke the app, badge or code in the access control system.
- External parties. A guard company or contractor leaving? Their accounts belong on this list too.
- Record it. Note when which account was revoked. That is your evidence in an audit.
Frameworks
Do NIS2 and ISO 27001 require you to revoke access?
NIS2 lists access control policies and human resources security among the measures in Article 21. The Dutch implementation spells it out: the access policy must include revoking identities and authorisations, and be applied demonstrably.
ISO 27001 has a control for exactly this: responsibilities after termination or change of employment (Annex A 6.5), next to access rights (5.18). And the GDPR requires every organisation to keep unauthorised people away from personal data. A former employee still watching is precisely that. What to do if it has already happened is on the audit trail of your camera system.
Honest
Can you remove someone everywhere with one button?
Not across every system. Cameras, alarm and intercom each have their own management environment, and no button removes someone from all three at once. What you can have is one place per system instead of one per site. For cameras through Nx Witness, optionally from Active Directory. Some alarm platforms also support sign-in with Microsoft Entra ID, and then it follows automatically there too.
So not one button, but one list with three actions. Instead of a tour of every recorder at every site. How we set that up across your sites is on access management for cameras, alarms and intercoms, and where you stand now shows in the access check.
Questions about leavers and camera systems
How quickly does someone lose access after being removed from Active Directory?
Nx Witness syncs with your AD or LDAP server every ten minutes by default. After that sync the user can no longer log in. The interval can be changed.
What happens to a deleted user’s actions in the audit trail?
They stay. Even after a user is deleted you can still see what that account did, within the retention period of the audit trail.
Everyone uses the same login now. Where do I start?
Change the password of that shared login first, so former employees are locked out. Then create a personal account for everyone who needs one, with only the cameras that fit their job. We are happy to set that up with you.
Does this apply to temporary staff and external guards?
Especially to them. Nx Witness supports temporary users with an expiry date, so access stops by itself when the assignment ends.
Do you know who can still see your footage?
We review every account on all your systems and tell you which ones need to go. You get it in writing, so it fits your leaver procedure.

A quick word
Questions about your situation? Call Sander.
Calls again after handover to walk through it together until it really sits right. Describe your situation and you will hear straight away what we would do — with no obligation.
Sander · Adviser and aftercare