Deprovisioning should be prioritised wherever stale access is common, because inactive accounts and lingering entitlements create direct security exposure. Onboarding matters for productivity, but offboarding closes the door on residual access and ownership ambiguity. In practice, the right sequencing depends on where the largest governance gap already exists, but leaver control is often the most urgent.
Why deprovisioning usually comes before onboarding
When access is already overstaying its welcome, deprovisioning has the bigger security payoff. Every inactive account, stale role, or forgotten token extends the period in which an attacker, ex-employee, contractor, or overloaded system can still act with legitimate access. Onboarding improves productivity, but it does not reduce existing exposure the way revocation does.
That is why lifecycle work is not just a process preference. It is an exposure-reduction decision. If your current state includes orphaned accounts, overlapping entitlements, or unclear ownership, removing access closes real attack paths faster than adding new users opens them.
For lifecycle governance, the strongest starting point is usually the largest source of residual access. If the environment has many dormant accounts, long-lived credentials, or delayed leaver processing, deprovisioning deserves priority because it directly shrinks the active trust surface before new access is added.
When onboarding should lead instead
There are cases where onboarding first is the right operational choice. If access requests are blocking business-critical work and the organisation already has reliable leaver controls, the immediate problem may be the lack of timely, controlled provisioned access rather than excess access. In that case, the priority is to make sure new access is granted through a governed path rather than by exception or shadow IT.
Onboarding also comes first when the organisation has a strong default-deny posture and leaver processing is already automated and measurable. Then the main risk is not residual access, it is operational drag, manual workaround behaviour, or delayed delivery of approved access that drives unsafe user behaviour.
This is the practical sequencing rule: prioritise the control that closes the largest current gap. If stale access is the dominant issue, fix deprovisioning. If access delay is forcing uncontrolled workarounds and offboarding is already dependable, improve onboarding.
How to decide the sequence in practice
Use evidence, not intuition. Look at where the organisation loses control today: dormant accounts, unrevoked credentials, delayed terminations, delayed role removal, or excessive manual provisioning. The answer should follow the bigger failure mode, not a generic lifecycle slogan.
- If orphaned or dormant access is common, start with deprovisioning controls.
- If joiner requests are creating ungoverned access paths, stabilise onboarding with tighter approval and automation.
- If both are weak, fix leaver processing first, then standardise joiner workflows.
- If a regulated or high-risk environment is involved, treat revocation latency as the more urgent control gap.
That sequencing aligns with the operational reality of identity governance. Joiner-Mover-Leaver (JML) Guide is the clearest model for deciding whether the problem sits in arrival, change, or departure handling, while NHI Lifecycle Management Guide and SCIM and Automated Provisioning Guide show why automated lifecycle control matters when provisioning and deprovisioning must stay synchronized.
Risk and Threat Considerations
Stale access is dangerous because it creates a long tail of legitimate but no longer justified access. That gives attackers a place to hide inside valid entitlements, and it also leaves room for ex-staff, contractors, or forgotten integrations to keep operating after ownership has changed. The longer those accounts remain active, the harder it becomes to prove who should still have access.
Failure mechanism: revocation lags behind departure, role change, or system retirement, so credentials, tokens, or entitlements remain usable after their business need has ended.
Impact: residual access can enable unauthorized use, privilege creep, audit findings, and avoidable blast radius if the account or secret is later abused.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle control governs provisioning and removal of active access. |
| Recommendation — Tighten account lifecycle controls to remove stale access before expanding onboarding volume. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle management is central when deprovisioning must revoke usable access material. |
| AC-2 — Account Management | Account provisioning, disabling and removal directly determine whether onboarding or offboarding is the bigger gap. | |
| Recommendation — Revoke and rotate authenticators promptly when users leave or roles change. Disable or remove accounts as soon as business need ends, then standardize approved onboarding. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity lifecycle governance covers joiner and leaver handling across the access lifecycle. |
| Recommendation — Define joiner and leaver ownership so access changes are timely and auditable. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The question prioritizes leaver control where stale access and lingering rights create exposure. |
| NHI-07 — Long-Lived Secrets | Lingering credentials and tokens are a direct reason deprovisioning often outranks onboarding. | |
| NHI-05 — Overprivileged NHI | Excess entitlements are a consequence of weak lifecycle control and raise the urgency of deprovisioning. | |
| Recommendation — Treat offboarding gaps as the first lifecycle weakness to eliminate when stale access persists. Shorten secret lifetimes and revoke unused credentials before adding new access. Reduce excessive entitlements first when dormant access and privilege creep are already present. | ||
Practitioner Guidance
What to prioritise: start by ranking the highest-risk stale-access populations, such as terminated users, dormant privileged accounts, and long-lived tokens with production reach. Those are usually the quickest way to reduce exposure because the security value is immediate and measurable.
Decision rule: if you can only improve one side of the lifecycle now, prioritise the side that removes access already on the books. If deprovisioning is weak, close that first; if deprovisioning is already dependable, shift to onboarding controls that stop exceptions and manual bypass.
What good looks like: leaver access is removed on a consistent SLA, residual entitlements are rare, and onboarding happens through an approved workflow rather than ad hoc grants. In mature environments, both sides are governed, but revocation is usually the more urgent control when access sprawl exists.
Practitioner takeaway: choose the sequence based on current exposure, not process symmetry, because removing unjustified access usually reduces risk faster than adding justified access increases it.
Related resources from NHI Mgmt Group
- Should organisations prioritise JIT access or automated deprovisioning first?
- What is the difference between rotation and deprovisioning for NHIs?
- Should organisations prioritise external exposure or internal credential governance first?
- How can organisations reduce the risk of stale API keys and machine tokens?