I was reading the LUKS specification and noticed that revoking a user's key does nothing to stop them from accessing the encrypted partition if they have stored the master key from the partition. Once given access, they can decrypt and store the master key, and nothing short of changing the master key can prevent future access.