Employee Leaves on Bad Terms
Without instant revocation, a departing employee retains VPN access until someone manually removes their credentials - a window that can stretch to hours or days.
Remove access in seconds, not days. PrivyNet lets you terminate an active VPN session and invalidate credentials immediately - the moment an employee leaves, a device is lost, or a threat is detected. No config changes, no ticket queues, no waiting.
Every minute between an employee leaving and their VPN access being removed is a window of risk your organisation carries unnecessarily
Without instant revocation, a departing employee retains VPN access until someone manually removes their credentials - a window that can stretch to hours or days.
Temporary credentials for contractors frequently outlive the engagement. Instant revocation closes that window the moment the work is done.
An active session on a lost device stays open until it is explicitly terminated. PrivyNet lets you cut that session immediately from the admin dashboard.
When a threat is detected, every second counts. Instant revocation terminates the compromised session the moment the incident is identified - not after a ticket is raised.
Most VPN solutions require manual configuration changes to revoke access - a process that can take hours or days depending on who is available to action it. PrivyNet makes it a single click.
Four things happen the moment you revoke a credential - all of them immediately
Select the user or session in the admin dashboard and revoke. No config files, no CLI commands, no waiting for propagation.
The active session is cut instantly. The revoked credentials cannot be used to reconnect - a new credential must be explicitly issued to restore access.
Every revocation event is written to the audit log immediately - recording who was revoked, when, and which admin performed the action.
Revocation can be triggered programmatically, making it possible to integrate with HR systems and offboarding workflows for zero-touch access removal.
Revoke precisely what needs to be revoked - a single user, or the entire VPN
Remove access for a specific individual without affecting anyone else on the VPN. The user's active session is terminated immediately and their credential is invalidated - the rest of your team continues working uninterrupted.
Terminate all active sessions across the entire VPN simultaneously. Every connected user is disconnected and all credentials are invalidated in a single action - used when a broad threat or incident requires a full reset.
Common scenarios where immediate access removal is the difference between a controlled situation and a security incident
| Scenario | Action Required | PrivyNet Response |
|---|---|---|
| Employee offboarding | Revoke all credentials | Instant - dashboard or API |
| Lost or stolen device | Revoke device session | Instant - session terminated |
| Contractor end of engagement | Expire temporary credentials | Instant - no lingering access |
| Suspected account compromise | Revoke & investigate | Instant - session terminated + audit log |
| Security incident response | Revoke all active sessions | Bulk revocation - all sessions cleared |
Instant revocation is only possible because of how dedicated VPN infrastructure is architected
Because each organisation runs on its own dedicated node, there is no shared session state to propagate across - revocation takes effect at the node level, instantly.
Sessions require continuous server validation. Once a credential is revoked, the server refuses to authorise any further session - the client cannot bypass this.
Revocation authority sits with your admin team, not PrivyNet. You control who has access and when that access ends - no dependency on third-party intervention.
Integrate PrivyNet revocation into your existing HR and offboarding workflows - no manual steps required
Employee departure is recorded in your HR platform or identity provider.
Your offboarding workflow fires a webhook or calls a script as part of the standard process.
A single API call to PrivyNet revokes the credential - no dashboard interaction required.
Session terminated, credentials invalidated, and revocation event written to the audit log.
Common questions about instant VPN session revocation
Revocation is immediate. The moment you revoke a credential from the PrivyNet dashboard, the active session is terminated and the credential is invalidated. The user cannot reconnect using the revoked credential.
Yes. PrivyNet provides an API for credential management, including revocation. This makes it possible to automate access removal as part of HR offboarding workflows or incident response playbooks.
The active session is terminated immediately. The revoked user is disconnected and cannot re-establish a session with the revoked credential. A new credential must be explicitly issued to restore access.
Yes. Every revocation event is logged immediately with a timestamp, the identity of the admin who performed the action, and the credential that was revoked.
Yes. PrivyNet supports bulk revocation - you can terminate all active sessions for your organisation simultaneously, which is particularly useful during a security incident response.
One click. Access gone. Every revocation logged. PrivyNet gives your admin team complete, immediate control over who is connected - and who isn't.