They depend on people noticing change quickly enough to update access before risk accumulates. In multi-site operations, that assumption breaks because roles, contractors and partners change too often for ticket-based handling to stay accurate.
Why manual onboarding and offboarding stops scaling
Manual joiner, mover and leaver handling works when the organisation is small, the number of changes is low, and one team can keep a near-real-time picture of who should have access. As headcount, contractor volume and partner integrations grow, the process becomes too slow, too dependent on memory, and too likely to miss the exact moment when access should change.
The core failure is not that people stop caring. It is that the control model depends on humans spotting change, interpreting it correctly, and updating multiple systems before the window for misuse opens. In a growing environment, that window widens because roles change faster than tickets can be processed, and access state drifts away from business reality.
Manual handling also struggles with inconsistent inputs. HR records, manager requests, project assignments and vendor relationships rarely arrive in one clean sequence, so onboarding and offboarding decisions become patchwork decisions rather than governed lifecycle events. That is why lifecycle discipline becomes a Joiner-Mover-Leaver (JML) process problem, not just an administration problem.
Where scale breaks onboarding accuracy
At small scale, manual onboarding can seem precise because the same people know the roles, the exceptions and the system owners. At larger scale, role design, entitlement mapping and approval paths become too varied for ticket-based handling to stay current. The result is either delayed access that slows work, or overgranting that tries to avoid delays but increases exposure.
Onboarding errors also compound when there are many access types to coordinate. A new starter may need application access, data access, group membership, shared resource permissions and third-party access, each with different owners and SLAs. IAM and IGA Basics covers why this breaks down when provisioning, access review and entitlement governance are left to ad hoc handling.
Multi-site and multi-partner operations make the problem worse because local teams often apply different interpretations of the same role. That creates inconsistent birthright access, duplicate requests and role drift. Over time, the organisation starts onboarding people into a shadow version of the access model that no longer matches the approved one.
Why offboarding failure creates the bigger risk
offboarding is usually the more dangerous side because access that should disappear can remain usable long after employment, contract terms or partner status has ended. The practical issue is not only dormant accounts, but the wider set of credentials, tokens, keys and shared paths that are easy to forget when a departure is handled manually.
That is why leaver handling must include more than disabling a primary account. It needs a reliable way to remove all access paths tied to the person or relationship, including systems that do not sit in the main ticket queue. The Top 10 NHI Issues page is useful here because stale non-human access often survives human offboarding and keeps the same trust path alive.
Where secrets are long-lived, manually managed offboarding can leave high-impact credentials active even after the human owner is gone. The issue is not just account closure, but ensuring that anything capable of acting on the person’s behalf is rotated, revoked or retired on time. The Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is relevant because lifecycle control is what closes the gap between employment change and access removal.
Risk and Threat Considerations
Manual onboarding and offboarding create a predictable exposure pattern: access lingers when business change happens faster than administration. That matters because attackers, insider misuse and simple process failure all benefit from stale access, especially where shared accounts, contractor access or inherited privileges remain in place after the original need has ended.
Failure mechanism: change events enter the organisation through HR, vendor management or local managers, but access removal depends on separate human action, so revocation is delayed, partial or missed entirely. In practice, attackers do not need a complex exploit if they can reuse an account, token, key or partner path that should already have been retired.
Impact: the longer access persists after role change or departure, the greater the chance of unauthorized use, lateral movement, data exposure and audit failure. The risk scales with contractor churn, partner integrations and distributed operations, because each extra handoff adds another opportunity for stale permissions to survive.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Manual onboarding/offboarding is fundamentally account lifecycle control. |
| Recommendation — Automate account provisioning and timely deprovisioning for joiner-mover-leaver events. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | The question centers on creating, changing, and removing access as people move or leave. |
| IA-5 — Authenticator Management | Leaver failure often leaves passwords, tokens, keys, and other authenticators active. | |
| Recommendation — Define authoritative account lifecycle triggers and revoke access promptly on role change or departure. Rotate or invalidate authenticators and secrets when ownership or employment changes. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Onboarding and offboarding depend on governed identity creation, change, and removal. |
| Recommendation — Maintain a controlled identity lifecycle with defined ownership and approvals. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Stale non-human access commonly survives human offboarding in growing organisations. |
| Recommendation — Revoke non-human access paths automatically when the owning human or workflow ends. | ||
Practitioner Guidance
What to verify: treat onboarding and offboarding as evidence-backed lifecycle events, not completed tickets. Verify that every access change can be tied to an authoritative source, that revocation reaches downstream systems, and that exceptions are recorded when a system cannot be updated automatically.
Decision rule: if a person, contractor or partner can enter or leave without triggering access removal in the same workflow, the process is already too manual. Prioritise automation for high-turnover roles and any access path that can materially affect production systems, customer data or shared credentials.
Practitioner takeaway: the scale problem is not volume alone, it is the growing distance between business change and access change. When that distance widens, manual processes stop being a control and become a lagging indicator of who already had access.
Related resources from NHI Mgmt Group
- Why do manual certificate tracking processes fail as organisations grow?
- When should organisations prioritise automated user lifecycle management over manual onboarding and offboarding processes?
- Why do manual onboarding and offboarding processes increase security risk?
- Why do spreadsheet-based compliance processes fail as organisations grow?