The workflow becomes a thin automation layer over a broken process. Teams see inconsistent approvals, missed handoffs, and exceptions that never land in the same control path. That usually means onboarding, transfers, and offboarding are still being managed outside governed lifecycle state, which reduces control reliability.
Where the lifecycle platform stops matching the real process
When the platform and the actual joiner-mover-leaver flow drift apart, the tool no longer represents the control. The result is not simply “manual work plus automation”, it is duplicated governance, where the system records one version of the lifecycle and the business executes another. That gap makes state, approvals, and responsibility ambiguous.
In practice, the process usually fractures at the joins between HR, managers, IT, and access owners. The platform may still move tickets, but it cannot reliably enforce who should approve, what should be provisioned, or when access should be removed if those decisions happen outside the governed workflow.
Once that mismatch exists, the platform becomes a reporting layer over inconsistent behavior rather than the source of truth for lifecycle state. Joiner-Mover-Leaver (JML) Guide covers the operating model that keeps onboarding, transfer, and offboarding aligned to the same governed path.
Why the control model degrades, not just the workflow
The first thing to break is control consistency. If joiners, movers, and leavers are handled through different side channels, the organisation loses a single decision path for entitlement changes, revocation, and exception handling. That is where access creep, delayed deprovisioning, and orphaned approvals start to accumulate.
The second break is ownership. A lifecycle platform only works when it can resolve who owns the request, who validates the event, and who can override it. Without that mapping, teams end up compensating with email, chat, spreadsheet tracking, or manager memory, all of which reduce auditability and make every exception harder to reconcile later.
That is why lifecycle tools need to sit inside identity governance rather than beside it. IAM and IGA Basics explains how provisioning, entitlement control, and governance fit together when the process is designed correctly.
For broader lifecycle hygiene, NHI Lifecycle Management Guide is useful because the same failure pattern appears whenever offboarding, rotation, and visibility are not tied to the real operational state.
What the mismatch usually looks like in operations
The symptoms are usually easy to spot once you look for them as process defects rather than tool defects. New hires may receive access before the system sees them as active, movers may retain old-role permissions after the platform has logged the transfer, and leavers may remain partially active because final revocation depends on a separate manual handoff.
Those symptoms matter because they show the platform is no longer enforcing lifecycle boundaries. Once state changes are being applied outside the control path, every downstream entitlement review becomes less reliable, and no approval trail can fully explain why access was granted or removed.
Offboarding failures are especially revealing because they show how persistent access can survive after the business relationship has ended. Twitter source code leak 2023 is a concrete example of how leaver-process failure can leave sensitive access in the wrong hands long after the intended cutoff.
Risk and Threat Considerations
A lifecycle platform that does not reflect the real joiner-mover-leaver process creates control gaps that attackers and insiders can exploit. The main exposure is stale access: privileges stay active after role changes or departure, while the organisation assumes the workflow already closed them out.
Failure mechanism: lifecycle state is split across the platform, HR, managers, and technical teams, so revocation, entitlement updates, and exception handling do not converge on one authoritative event.
Impact: access persists beyond its intended lifecycle, approvals become non-reproducible, and the organisation inherits a larger blast radius for misuse, theft, or simple operational mistakes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | PS-4 — Personnel Termination | Directly addresses timely removal of access when a user leaves. |
| AC-2 — Account Management | Covers account lifecycle control for joiners, movers, and leavers. | |
| IA-5 — Authenticator Management | Lifecycle drift often leaves secrets and authenticators active after role changes or exit. | |
| Recommendation — Ensure separation and termination procedures revoke accounts and access on time. Define, provision, review, and disable accounts through one governed lifecycle process. Rotate, revoke, and retire authenticators when lifecycle state changes. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Requires managed identity lifecycle and ownership for access changes. |
| A.5.18 — Access rights | Directly supports granting, modifying, and removing access on lifecycle change. | |
| Recommendation — Align identity records and access changes to authoritative lifecycle events. Review and remove access rights when roles or employment status change. | ||
Practitioner Guidance
What to verify: Check whether the platform consumes the same authoritative lifecycle triggers that drive hiring, transfer, and termination. If the workflow depends on side emails, manual reminders, or after-the-fact cleanup, the control is already weaker than the design suggests.
Decision rule: If a move or leaver event can happen without a state change in the governed workflow, treat the process as partially uncontrolled and fix the handoff before tuning approvals or automation rules.
Common mistake: Teams often automate the visible ticket flow while leaving identity state, access removal, and exception resolution outside the same control path. That creates speed without control and is usually the reason the platform appears effective on paper but fails under real lifecycle pressure.
Practitioner takeaway: The key test is whether one lifecycle event produces one authoritative access decision. If it does not, the platform is not governing the process, it is merely documenting its failure modes.
Related resources from NHI Mgmt Group
- What breaks when joiner-mover-leaver flows are not tied to real work changes?
- What breaks when deprovisioning is not tied to the joiner-mover-leaver process?
- What breaks when joiner-mover-leaver workflows are mostly manual?
- What breaks when joiner, mover, leaver processes are handled differently for technical accounts?