The short answer
When vendor personnel change, inventory every credential and assignment tied to the old and new custodians, verify the vendor-authorized roster through an independent contact, revoke or recover old access, issue only the minimum replacement access, and retest open work and sensitive-data permissions.
Key takeaways
- Vendor status does not automatically update each credential.
- Verify roster changes independently of the request channel.
- Reconcile open work and shared records as well as keys and codes.
Open one change event with a defined population
Record the vendor, verified contact, change reason, effective time, departing or reassigned staff, replacements, properties, open work orders, physical credentials, portal accounts, shared folders, messaging groups, payment or invoice access, and emergency contacts.
Do not publish sensitive access details in the event record. Refer to credential IDs, masked references, or protected inventories.
Reconcile each access surface independently
The absence of an active app login does not prove a key, code, shared link, or cached document was retired.
| Surface | Old-custodian evidence | Replacement gate | Closure proof |
|---|---|---|---|
| Physical key/device | Issued-item inventory | Need and custody approved | Returned, rekeyed, or lost-item response |
| Door/access code | Code-to-person/property map | Unique minimum-scope code | Old code revoked and tested |
| Vendor portal | Effective roles and sessions | Named account and least privilege | Old sessions/tokens disabled |
| Shared records | Folder/link recipients | Work-specific access | Links/groups updated |
| Open work | Assigned visits and resident contacts | Reassignment accepted | Next action and access owner acknowledged |
Close the change only after negative tests
Where safe, verify that retired credentials no longer work and that the replacement can perform only the approved task. Review recent access history for unexpected use during the transition according to policy.
Keep lost, shared, unreturned, or untestable access as explicit exceptions with containment, owner, and follow-up. Do not close the event merely because the vendor says its roster is current.
Operational checklist
Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
☐
Roster change independently verified
☐
Affected properties and open work listed
☐
Physical and digital access inventoried
☐
Old credentials retired or excepted
☐
Replacement scope approved
☐
Negative tests completed where safe
☐
Receiving operator acknowledges assignments
0 of 7 marked
Edge cases
- A technician remains employed but changes territory: remove old-property access.
- A shared code prevents person-level proof: rotate it and change the issuance design.
- An emergency call occurs during transition: preserve temporary access and retire it separately.
Sources and references
Follow each source to check the underlying claim. Access checks and professional review are different steps.
Continue the workflow
Vendor access credential lifecycle for rental propertiesA vendor lifecycle control recordAfter-hours maintenance closeoutRevision history
2026-09-18
Initial Phase 4 operational article with a distinct evidence artifact, failure states, source limits, and AI-assisted technical review.