Removing someone from an Apple Home is only one step in security offboarding. A former resident, caregiver, cleaner, contractor, or guest may also retain a lock code, alarm code, camera account, vendor-app share, garage credential, Wi-Fi password, voice-assistant access, mechanical key, or trusted phone. Use a written inventory, remove access in the right order, and prove that old credentials fail.
HomeKit member-removal checklist
| Layer | Action | Pass condition |
|---|---|---|
| Apple Home | Review residents and remove the departing person using the current Apple Home process | Their account no longer appears and cannot control the home |
| Native vendor apps | Remove shares, sessions, mobile keys, and linked accounts | Old native-app access fails |
| Locks and entry | Revoke named codes, wallet keys, fobs, cards, fingerprints, and temporary access | Every removed credential fails at each entry |
| Alarm | Remove users and rotate exposed master, guest, installer, and duress credentials safely | Old codes cannot arm, disarm, or change settings |
| Cameras | Review members, sharing links, sessions, storage, and privacy controls | No live view, clip, or settings access remains |
| Recovery | Review owners, trusted devices, recovery contacts, and emergency access | Recovery no longer depends on the removed person |
When to use this checklist
Run it when a resident moves out, a relationship or employment ends, a caregiver changes, a rental turns over, a contractor finishes, a phone is lost, or an account may be compromised. If there is stalking, domestic abuse, coercive control, theft, or an immediate threat, prioritize safety and professional help. Do not alert or confront a risky person merely to test access.
1. Map access before removing it
List the Apple Home owner and residents, Apple devices, home hubs, bridges, Matter fabrics, alarm account, monitoring account, camera apps, lock apps, garage and gate systems, router, Wi-Fi, voice assistants, smart displays, email recovery, phone numbers, password managers, installers, landlords, property managers, and physical keys. Note which person owns each account and which device can change other users.
2. Preserve evidence when access may have been misused
Record times, user lists, trusted devices, lock events, alarm events, camera sharing, deleted or disabled devices, unexpected automations, password-reset messages, and support cases before making changes. Export records lawfully and minimize copies. Do not factory-reset devices first if that may erase useful history.
3. Secure the owner and recovery accounts
Confirm that the continuing owner controls the primary email, phone number, Apple Account, password manager, authenticator, carrier account, and vendor accounts. Review trusted devices and recovery methods, use unique passwords, and enable strong multi-factor authentication where supported. A removed Home member can still return if they control account recovery.
4. Remove the person from Apple Home
Follow Apple’s current official instructions for sharing control of a home. Record the member list before and after. Check every home if the household manages more than one property. Review remote access, accessory control, cameras, recordings, notifications, and any permissions shown by the current software. Menu names and available controls can vary by software version and role.
5. Remove access from native device apps
Apple Home membership does not necessarily remove access granted in a lock, camera, alarm, garage, bridge, or vendor app. Review owners, administrators, members, guests, installers, shared links, API tokens, linked services, and active sessions in every native app. Revoke the person, then sign out unknown or obsolete devices.
6. Revoke every door and gate credential
| Credential | Action | Test |
|---|---|---|
| Named keypad code | Delete it rather than renaming it | Old code fails; replacement works only on intended schedule |
| Home key/mobile key | Revoke the person and relevant wallet/device credential | Removed phone or watch cannot unlock |
| Fingerprint, card, or fob | Delete the exact credential and audit duplicates | Revoked credential fails at every reader |
| Mechanical key | Recover, rekey, or replace when exposure and authority justify it | Approved emergency keys work; old key does not |
| Garage, gate, or building access | Remove remotes, codes, apps, and building credentials separately | Old access fails at each boundary |
7. Rotate alarm and monitoring access
Remove the departing alarm user. Rotate shared codes, verbal passwords, monitoring contacts, call order, emergency contacts, and installer credentials when they were exposed. Verify permits and account ownership. Use provider-approved test mode before triggering monitored alarm, panic, fire, medical, or duress functions.
8. Audit cameras, recordings, and privacy
Review camera members, household roles, native-app shares, viewing devices, download links, cloud storage, local storage, smart displays, voice assistants, and privacy automations. Confirm the removed person cannot see live video, recordings, thumbnails, notifications, camera names, or activity zones. Check that cameras in private spaces remain appropriate and lawful.
9. Inspect automations and presence rules
Search for routines tied to the departing person’s phone, presence, voice, button, code, or schedule. Remove or rebuild routines that unlock, open, disarm, change camera privacy, suppress alerts, or simulate occupancy. Do not rely on presence as proof of identity for high-impact actions.
10. Review hubs, bridges, and Matter access
Inventory Apple TV and HomePod home hubs, Thread border routers, Matter controllers, bridges, and vendor hubs. Confirm which account owns each device and where automations run. Removing an Apple Home member may not remove access from another Matter fabric or vendor account. Remove only known stale access, then test accessories after changes.
11. Decide whether network credentials must change
Change Wi-Fi and router-administration credentials when the departing person knew them and continued access creates risk. Review unknown clients, remote administration, DNS, port forwarding, guest access, and shared passwords. Plan the reconnect order for hubs, cameras, bridges, locks, displays, and backup communication before changing the network.
12. Test removed access
- Confirm the removed person is absent from Apple Home and every native app.
- Try each revoked code, key, fob, card, mobile credential, and remote under safe conditions.
- Verify old alarm credentials cannot arm, disarm, or change users.
- Confirm camera live view, recordings, notifications, and sharing no longer work.
- Test a priority door for sensor, alarm, siren, alert, history, and monitoring response.
- Test internet loss, AC-power loss, primary-phone loss, and recovery ownership.
- Recheck after device sync, firmware updates, and 24 hours.
What not to do
- Do not assume Apple Home removal revokes every vendor account or physical credential.
- Do not rename an old lock code and treat it as a new credential.
- Do not leave recovery email, phone, or trusted devices under the removed person’s control.
- Do not reset the home before preserving evidence and confirming ownership.
- Do not test emergency or monitored functions without the proper process.
- Do not create a hidden surveillance setup or violate tenancy, employment, privacy, or recording laws.
Related security workflows
Use the HomeKit account recovery guide, smart-lock code audit, HomeKit privacy guide, and account-compromise response checklist when offboarding exposes a broader problem.
Where Abode fits
For a home using Abode alongside Apple Home, review Abode app users, alarm codes, automations, cameras, locks, monitoring contacts, plan status, cellular backup, Apple Home residents, and any native vendor shares separately. Compare the Smart Security Kit and current Abode plans.
Verdict
Member removal is complete only when the old Apple Home role, native-app shares, sessions, lock and alarm credentials, camera access, automations, physical keys, network access, and recovery paths have been reviewed—and the removed access fails in a real test.
FAQ
Does removing someone from Apple Home remove their smart-lock code?
Not necessarily. Lock codes and native-app access may be managed separately. Delete and test every credential.
Should I change the Wi-Fi password after someone moves out?
Change it when the person knew it and continued network access creates risk. Plan device reconnection first.
Does removing a Home member remove camera access?
It removes the Apple Home role, but a native camera account, sharing link, session, or another platform may still grant access.
How do I prove offboarding worked?
Confirm the person is absent from every account and test that each old digital and physical credential fails.
Turn member removal into a revocation evidence plan
Removing a person from an Apple Home is one step, not the full security boundary. The same person may still have a vendor-app account, smart-lock code, shared password, camera link, monitoring contact, trusted browser session, old phone, automation, or mechanical key. Build one revocation worksheet that names every access path, its owner, the removal action, and the proof that the path no longer works.
| Access path | Removal action | Evidence to save |
|---|---|---|
| Apple Home member | Remove the person from the correct Home and confirm the current owner | People list, Home name, removal time, and failed retest from the removed account |
| Vendor security app | Remove or disable the user, revoke invitations, and rotate shared owner credentials | Current user list, role, session list, and failed sign-in or control test |
| Smart-lock code or mobile key | Delete the credential from every affected lock and bridge | Lock audit, code list, door name, sync status, and failed entry test |
| Camera access | Remove shared viewers, links, downloads, and vendor roles | Viewer list, live-view test, clip-access test, and retained-evidence owner |
| Alarm and monitoring | Remove app access, keypad code, call list, duress code where applicable, and contact authority | User list, call-list record, arming test, cancellation-word control, and provider confirmation |
| Physical access | Recover or replace keys, fobs, garage remotes, mailbox keys, and building credentials | Count, serial or label, return record, rekey decision, and failed physical-entry test |
Separate routine removal from a safety response
A planned roommate move-out, cleaner offboarding, or expired house-sitter visit can use the ordinary checklist. A separation involving coercion, stalking, account compromise, or physical risk needs a different order. Keep personal safety ahead of device cleanup, preserve evidence where lawful, and avoid an action that could escalate danger.
Review the Apple Safety Check and HomeKit security audit when the concern extends beyond one Home invitation. Safety Check can affect broader sharing and account relationships; record the intended scope before changing settings.
Assign two people where the situation allows. The account owner performs removals. A witness records time, current access lists, lock and alarm states, failed retests, and any unresolved physical credential. Do not ask the removed person to prove revocation by entering the property.
Audit trusted devices and sessions
A removed Home member may retain access through a shared vendor login, an old tablet, a remembered browser, or a phone that still holds an active session. Run the home-security trusted-device and session audit for Apple, camera, lock, alarm, router, password-manager, and monitoring accounts.
- List every current device and browser session by account.
- Name the owner, location, last use, and security role.
- Revoke unknown, former-resident, lost, sold, or shared devices.
- Change any credential that was shared instead of individually assigned.
- Confirm multi-factor recovery methods belong to current authorized owners.
- Sign out one controlled test session and verify that it cannot regain access without current approval.
Do not treat a password change as proof that every session ended. Some services keep existing tokens active. Use the service’s session or trusted-device controls, then retest the old device or browser where it is safe and authorized.
Check owner and administrator continuity
Before removing an administrator, confirm that another current owner can manage people, hubs, cameras, locks, automations, vendor apps, billing, and recovery. The HomeKit administrator-change checklist covers the ownership and recovery handoff.
Record which account owns the Home, iCloud storage used by cameras, vendor subscriptions, monitoring service, router, password vault, and device warranties. If the departing person owns one of these services, decide whether to transfer, replace, export, or retire it before removing the last working administrator.
Test the successor account before the old administrator is removed. The successor should be able to view current device state, manage intended people, operate a priority lock, control the alarm where authorized, view required cameras, export evidence, and recover the account without the departing person’s phone or email.
Remove caregiver and temporary access by shift
Caregiver access may cross Home membership, lock codes, cameras, medication areas, gate controls, and alert routing. Use the HomeKit caregiver handover checklist when access changes between people or shifts.
Do not remove an outgoing caregiver before the incoming caregiver has a tested authorized route if the resident depends on help. Keep privacy and safety separate: a caregiver may need entry and selected alerts without live access to private cameras or authority to remove other residents.
Record start and end time, doors, alarm permissions, camera boundary, emergency contact, physical key, code, mobile credential, and revocation owner. After the shift ends, test that the old access fails and the resident’s emergency route still works.
Delete every temporary lock credential
Removing a person from Home does not prove that their keypad code, mobile key, vendor-app guest, or bridge credential disappeared. Run the smart-lock temporary access-code removal checklist on each affected door.
- List the lock, door, bridge, app, code label, schedule, and owner.
- Delete the code or credential from the exact lock, not only from a contact record.
- Wait for sync and confirm current lock state.
- Test the removed credential once without exposing a working code to an unauthorized person.
- Test one retained resident credential and the mechanical fallback.
- Review auto-lock, arrival, guest, cleaner, and rental automations for the removed identity.
If a code cannot be attributed to a current person, remove it or replace the code set under a documented owner. Avoid one shared household code for residents, contractors, and guests; individual credentials make revocation and incident review possible.
Cover death, incapacity, and long-term absence
Member removal can also follow death, medical incapacity, or a long absence. In that case, preserve lawful evidence and household access while transferring operational ownership. The home-security digital estate plan covers accounts, codes, cameras, monitoring, recovery, and handover.
Do not delete the only account that owns camera history, billing, device enrollment, or monitoring before export and succession are settled. Record the person authorized to act, the supporting document where required, the account owner, retained evidence, privacy decision, device-reset plan, and next review date.
Run a 60-minute member-removal evidence test
- Minutes 0–10: capture Apple Home, vendor-app, lock, alarm, camera, monitoring, and physical-access inventories.
- Minutes 10–20: remove the Home member and vendor-app roles; revoke invitations, sessions, and shared links.
- Minutes 20–30: delete lock codes, mobile keys, alarm codes, garage remotes, and other temporary credentials.
- Minutes 30–40: test the removed account, old browser or device, lock credential, live view, clip access, and alarm control where safe and authorized.
- Minutes 40–50: test a retained owner, resident, emergency contact, local key, priority lock, alarm mode, camera event, and evidence export.
- Minutes 50–60: review automations, notifications, monitoring contacts, physical keys, unresolved ownership, and the next audit date.
Pass only when the removed person cannot use any scoped digital or physical path, retained users still have the intended access, emergency entry still works, and the evidence record names every unresolved item and owner.
Member-removal blockers
- The current Home or vendor-app owner is unknown.
- The departing person owns the only recovery email, phone, trusted device, subscription, or monitoring account.
- A shared password, keypad code, camera link, or physical key cannot be attributed.
- Priority camera evidence has not been exported or assigned a lawful owner.
- A replacement administrator or caregiver has not passed an access test.
- Removing access would leave a resident without an authorized emergency route.
- A safety concern requires a coordinated response rather than ordinary offboarding.
- The removed account can still open a lock, control the alarm, view a camera, or use an active session.