The Real Cost of Slow Access Revocation

Every minute between an employee leaving and their VPN access being removed is a window of risk your organisation carries unnecessarily

Employee Leaves on Bad Terms

Without instant revocation, a departing employee retains VPN access until someone manually removes their credentials - a window that can stretch to hours or days.

Contractor Engagement Ends

Temporary credentials for contractors frequently outlive the engagement. Instant revocation closes that window the moment the work is done.

Device Lost or Stolen

An active session on a lost device stays open until it is explicitly terminated. PrivyNet lets you cut that session immediately from the admin dashboard.

Security Incident Response

When a threat is detected, every second counts. Instant revocation terminates the compromised session the moment the incident is identified - not after a ticket is raised.

Most VPN solutions require manual configuration changes to revoke access - a process that can take hours or days depending on who is available to action it. PrivyNet makes it a single click.

How PrivyNet Revocation Works

Four things happen the moment you revoke a credential - all of them immediately

Single Action from the Dashboard

Select the user or session in the admin dashboard and revoke. No config files, no CLI commands, no waiting for propagation.

Session Terminated Immediately

The active session is cut instantly. The revoked credentials cannot be used to reconnect - a new credential must be explicitly issued to restore access.

Logged with Timestamp and Actor

Every revocation event is written to the audit log immediately - recording who was revoked, when, and which admin performed the action.

Automatable via API

Revocation can be triggered programmatically, making it possible to integrate with HR systems and offboarding workflows for zero-touch access removal.

Two Levels of Revocation Control

Revoke precisely what needs to be revoked - a single user, or the entire VPN

User-Level Revocation

Remove access for a specific individual without affecting anyone else on the VPN. The user's active session is terminated immediately and their credential is invalidated - the rest of your team continues working uninterrupted.

  • Employee offboarding - one action, access gone
  • Contractor end of engagement - targeted removal
  • Suspected account compromise - isolate the individual
  • Device lost or stolen - cut that session only

VPN-Level Revocation

Terminate all active sessions across the entire VPN simultaneously. Every connected user is disconnected and all credentials are invalidated in a single action - used when a broad threat or incident requires a full reset.

  • Security incident requiring full access lockdown
  • Infrastructure maintenance requiring clean disconnection
  • Suspected credential breach across the team
  • Emergency shutdown - zero access until re-provisioned

When to Use Instant Revocation

Common scenarios where immediate access removal is the difference between a controlled situation and a security incident

ScenarioAction RequiredPrivyNet Response
Employee offboardingRevoke all credentials
Instant - dashboard or API
Lost or stolen deviceRevoke device session
Instant - session terminated
Contractor end of engagementExpire temporary credentials
Instant - no lingering access
Suspected account compromiseRevoke & investigate
Instant - session terminated + audit log
Security incident responseRevoke all active sessions
Bulk revocation - all sessions cleared

The Security Model That Makes It Possible

Instant revocation is only possible because of how dedicated VPN infrastructure is architected

Single-Tenant Infrastructure

Because each organisation runs on its own dedicated node, there is no shared session state to propagate across - revocation takes effect at the node level, instantly.

Server-Authoritative Credentials

Sessions require continuous server validation. Once a credential is revoked, the server refuses to authorise any further session - the client cannot bypass this.

Admin-Controlled at All Times

Revocation authority sits with your admin team, not PrivyNet. You control who has access and when that access ends - no dependency on third-party intervention.

Automate Revocation via API

Integrate PrivyNet revocation into your existing HR and offboarding workflows - no manual steps required

HR System or Offboarding Tool

Employee departure is recorded in your HR platform or identity provider.

Webhook or Automation Trigger

Your offboarding workflow fires a webhook or calls a script as part of the standard process.

PrivyNet API Call

A single API call to PrivyNet revokes the credential - no dashboard interaction required.

Access Removed Instantly

Session terminated, credentials invalidated, and revocation event written to the audit log.

Frequently Asked Questions

Common questions about instant VPN session revocation

How quickly does VPN access revocation take effect?

Revocation is immediate. The moment you revoke a credential from the PrivyNet dashboard, the active session is terminated and the credential is invalidated. The user cannot reconnect using the revoked credential.

Can I revoke access via API?

Yes. PrivyNet provides an API for credential management, including revocation. This makes it possible to automate access removal as part of HR offboarding workflows or incident response playbooks.

What happens to an active session when I revoke a credential?

The active session is terminated immediately. The revoked user is disconnected and cannot re-establish a session with the revoked credential. A new credential must be explicitly issued to restore access.

Is the revocation event recorded in the audit log?

Yes. Every revocation event is logged immediately with a timestamp, the identity of the admin who performed the action, and the credential that was revoked.

Can I revoke all active sessions at once?

Yes. PrivyNet supports bulk revocation - you can terminate all active sessions for your organisation simultaneously, which is particularly useful during a security incident response.

Never Leave Access Open by Accident Again

One click. Access gone. Every revocation logged. PrivyNet gives your admin team complete, immediate control over who is connected - and who isn't.

Instant revocation
Full audit log
API-automatable