Vendor management · Playbook · intermediate

Vendor staff-change access reconciliation

Reconcile keys, codes, accounts, work assignments, and sensitive records when a vendor changes the people serving a property.
By Aptoria editorial team · 3 min read · Updated 2026-09-18 · Last reviewed 2026-09-18
Technical content review: Codex technical editorial review. Reviewed intent separation, internal consistency, original operating artifacts, hypothetical examples, source limits, and links. No legal, accounting, banking, security, safety, privacy, or human professional approval is claimed.
This is a technical review, not independent human or professional review.
The short answer
When vendor personnel change, inventory every credential and assignment tied to the old and new custodians, verify the vendor-authorized roster through an independent contact, revoke or recover old access, issue only the minimum replacement access, and retest open work and sensitive-data permissions.

Key takeaways

  • Vendor status does not automatically update each credential.
  • Verify roster changes independently of the request channel.
  • Reconcile open work and shared records as well as keys and codes.

Open one change event with a defined population

Record the vendor, verified contact, change reason, effective time, departing or reassigned staff, replacements, properties, open work orders, physical credentials, portal accounts, shared folders, messaging groups, payment or invoice access, and emergency contacts.
Do not publish sensitive access details in the event record. Refer to credential IDs, masked references, or protected inventories.

Reconcile each access surface independently

The absence of an active app login does not prove a key, code, shared link, or cached document was retired.
Vendor staff-change reconciliation
SurfaceOld-custodian evidenceReplacement gateClosure proof
Physical key/deviceIssued-item inventoryNeed and custody approvedReturned, rekeyed, or lost-item response
Door/access codeCode-to-person/property mapUnique minimum-scope codeOld code revoked and tested
Vendor portalEffective roles and sessionsNamed account and least privilegeOld sessions/tokens disabled
Shared recordsFolder/link recipientsWork-specific accessLinks/groups updated
Open workAssigned visits and resident contactsReassignment acceptedNext action and access owner acknowledged

Close the change only after negative tests

Where safe, verify that retired credentials no longer work and that the replacement can perform only the approved task. Review recent access history for unexpected use during the transition according to policy.
Keep lost, shared, unreturned, or untestable access as explicit exceptions with containment, owner, and follow-up. Do not close the event merely because the vendor says its roster is current.

Operational checklist

Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
0 of 7 marked

Edge cases

  • A technician remains employed but changes territory: remove old-property access.
  • A shared code prevents person-level proof: rotate it and change the issuance design.
  • An emergency call occurs during transition: preserve temporary access and retire it separately.

Sources and references

Follow each source to check the underlying claim. Access checks and professional review are different steps.

Revision history

2026-09-18
Initial Phase 4 operational article with a distinct evidence artifact, failure states, source limits, and AI-assisted technical review.
Report a correction to this resource