Join our Newsletter — 33% off our NHI Course

What breaks when onboarding and offboarding are not part of IT maintenance metrics?

Maintenance looks healthy while access drift continues underneath it. If joiner, mover, leaver activity is not part of the scorecard, then stale accounts, vendor access, and unneeded licences can remain active even when the team appears operationally efficient. That is a control failure, not a reporting issue.

What breaks when onboarding and offboarding are missing from the maintenance scorecard?

When joiner, mover, and leaver activity is not measured, the maintenance function stops reflecting access reality. The team can still report clean ticket closure, patch cadence, and system uptime while stale entitlements, orphaned accounts, and forgotten vendor access continue to accumulate. In practice, the scorecard rewards operational motion, not control effectiveness.

Why the metric becomes misleading

The problem is not that onboarding and offboarding are “extra” work, it is that they are part of identity hygiene. If a person, contractor, application, or vendor can arrive, change role, or leave without a matching access event, then maintenance metrics only tell you that tasks were completed, not that access was correctly adjusted. That gap hides privilege creep, access drift, and license waste.

For practitioners, this is the difference between counting administration and measuring exposure. A healthy-looking maintenance dashboard can coexist with active accounts that no longer have a business owner, which means the organisation still has functioning access paths that no one is accountable for.

What failure looks like in operations

In the field, the break usually shows up in three places. First, onboarding is treated as a one-time provisioning event, so later role changes are never reflected in access. Second, offboarding is tracked by HR or IT as a completion status, but not as revocation, so entitlements survive after departure. Third, third-party and service access is left outside the same lifecycle discipline, so vendor accounts and technical credentials outlive the need they were created for.

This is why lifecycle metrics matter more than activity metrics. Joiner-Mover-Leaver (JML) Guide is a useful reference point for treating onboarding and offboarding as continuous access governance rather than an administrative checklist.

It also matters at the non-human end of the estate, where machine and service access can linger long after the business use case has changed. NHI Lifecycle Management Guide shows why provisioning, rotation, and offboarding need to be measured as one lifecycle, not as isolated tasks.

For the same reason, a mature scorecard should track old-role access removal, orphaned account cleanup, and credential retirement alongside the usual operational indicators. That is the difference between maintenance that keeps systems available and maintenance that actually reduces exposure.

Risk and Threat Considerations

When onboarding and offboarding are absent from maintenance metrics, the main risk is control drift that stays invisible until an account is abused or a review finally catches it. The environment can look stable while access accumulates across former staff, vendors, and service identities, which increases the attack surface and weakens accountability.

Failure mechanism: Access is created and never fully removed, so stale entitlements, dormant accounts, and long-lived secrets remain usable after the business need has ended.

Impact: Attackers and insiders gain more opportunities to reuse forgotten access, while the organisation carries hidden privilege, compliance, and licence exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Onboarding and offboarding metrics depend on timely account lifecycle control and removal of inactive access.
Recommendation — Measure account creation, change, and removal so stale access is revoked on time.
NIST CSF 2.0 PR.AA-05 — Managed Service Identities and Access Are Authorized, Managed, and Reviewed The question is about measuring whether access lifecycle events are actually controlled, not just processed.
ID.AM-01 — Physical Devices and Systems Are Inventoried Maintenance metrics fail when the asset and access inventory is incomplete or stale.
Recommendation — Track whether identities are provisioned, reviewed, and deprovisioned on schedule. Keep the inventory current so ownership and access changes can be reconciled.
ISO/IEC 27001:2022 A.5.15 — Access control The issue is whether access is governed across joiner, mover, and leaver changes.
Recommendation — Define and enforce access control rules across the full employee and vendor lifecycle.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Offboarding failures often leave credentials and authenticators active after they should be retired.
Recommendation — Revoke or rotate authenticators promptly when an identity leaves or changes role.

Practitioner Guidance

What to verify: The scorecard should prove that joiner, mover, and leaver events are measured as lifecycle controls, not just processed as tickets. If a report does not show who gained access, who lost access, and how quickly the change was completed, it is incomplete for control purposes.

What to measure: Track revocation timeliness, orphaned account count, stale entitlement age, and the share of onboarding and offboarding events that result in access changes within the expected service window. These are the signals that tell you whether maintenance is reducing drift or merely documenting it.

Common mistake: Treating licence reclamation, account closure, or workflow completion as proof that access has been removed. In reality, the useful test is whether the identity, entitlement, or credential can still be used after the event.

Practitioner takeaway: If onboarding and offboarding are not in the scorecard, the team is measuring effort instead of exposure, and that usually means the control failure will be discovered by audit, incident response, or asset cleanup rather than by operations.