Join our Newsletter — 33% off our NHI Course

What breaks when access cleanup only happens at onboarding and offboarding?

Access accumulates during the middle of employment when role changes and temporary grants are not re-evaluated. Onboarding can be correct and offboarding can still be handled, yet excess access remains because the organisation never resets the baseline when job context changes or temporary need ends.

Where Access Cleanup Breaks Down

Cleanup at onboarding and offboarding handles the edges of the employee lifecycle, but it misses the middle, where most entitlement drift happens. Role changes, temporary projects, emergency access, and manager approvals often create permissions that are never re-baselined. The result is not a failed joiner or leaver process, but a missing mover process.

That gap matters because access usually grows by accumulation, not by one dramatic mistake. A person can remain productive while carrying old-role access long after the business need has ended, which makes the excess harder to notice and easier to normalise.

Two patterns commonly drive the breakage: stale access that should have been removed after a job change, and temporary access that quietly becomes permanent. When the organisation does not re-evaluate entitlements during the employment lifecycle, the access model stops reflecting current duties and starts reflecting history.

What Actually Breaks in the Control Model

The control failure is a broken baseline, not just a delayed cleanup. Onboarding sets the starting point, and offboarding removes the endpoint, but neither action corrects the fact that access has drifted in between. That means least privilege, separation of duties, and access review all lose accuracy because the current role no longer matches the current permissions.

This is why mover events are security-relevant. Promotions, transfers, reorganisations, and temporary backfills change what someone should be able to reach. If those changes are not tracked with the same discipline as joiner and leaver events, the organisation keeps authorising access on outdated assumptions.

In practice, this can break in any environment where entitlements are role-based, ticket-based, or manually approved. The more exceptions the business allows, the more likely it is that the access record becomes a historical archive instead of an operating control.

Why the Risk Persists Even When Onboarding and Offboarding Look Good

The risk is that security teams may see clean joiner and leaver workflows and assume access governance is working. But the highest exposure often sits in the long middle period, where no one has triggered a full recertification of role, need, and privilege. That is why Joiner-Mover-Leaver (JML) Guide is the right mental model for this problem, because it treats movement as a control event, not an administrative detail.

IAM and IGA Basics is useful here because it frames access review and entitlement management as ongoing governance, not one-time provisioning. That matters when access cleanup is being measured only at the edges instead of at each role transition.

For lifecycle failures that involve secrets or keys, the same pattern can create persistence even after someone leaves a role. NHI Lifecycle Management Guide shows why rotation, offboarding, and visibility need to be part of the same control loop, because retained access can survive long after the business justification has ended.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Mover events and cleanup are account lifecycle issues that AC-2 directly governs.
AC-6 — Least Privilege Excess access after role changes is a least-privilege failure.
IA-5 — Authenticator Management Temporary credentials and stale secrets often persist across mover events.
Recommendation — Revoke or reauthorize entitlements when role changes and set review triggers for active accounts. Remove permissions that are no longer required for the current job function. Rotate or retire credentials when access no longer matches the current need.
ISO/IEC 27001:2022 A.5.18 — Access rights Access rights must be provisioned, reviewed, and adjusted as duties change.
A.5.16 — Identity management The issue is an identity lifecycle gap between joiner and leaver events.
Recommendation — Review and adjust access rights when users change roles or responsibilities. Tie identity changes to HR or workflow events so access stays aligned with current duties.

Practitioner Guidance

What to prioritise: Treat mover events as mandatory cleanup points. If role changes, temporary assignments, or project-based grants are not feeding a review cycle, the access model is already stale even if onboarding and offboarding are well run.

What to verify: Check whether every entitlement has an owner, an expiry expectation, and a review trigger tied to role change. If temporary access cannot be shown to expire or be reapproved, assume it will become permanent by default.

Common mistake: Teams often audit leavers and assume that removes excess access risk. In reality, the more common failure is retained access for active users whose responsibilities have changed but whose permissions were never reset.

Practitioner takeaway: Good lifecycle control is not measured by how well access starts and ends, but by whether it is continuously re-aligned in the middle.