By NHI Mgmt Group Editorial TeamBased on Zluri: “Employee Experience Best Practices for IT Teams” (June 26, 2025)

TL;DR: Manual onboarding, mid-life access requests, and offboarding delays create productivity drag and security exposure across employee identity lifecycles, according to Zluri. The governance gap is not authentication, but whether access changes keep pace with joiner, mover, and leaver events.


At a glance

What this is: This article argues that employee lifecycle management, not login technology, is the real test of access control because manual provisioning and delayed deprovisioning slow work and widen exposure.

Why it matters: For IAM and IGA teams, the finding reinforces that access governance must track joiner, mover, and leaver events closely or business users will work around the process and security gaps will persist.


Context

Employee lifecycle management is the set of processes that grant, change, and remove access as people join, move, and leave the organisation. In this article, Zluri frames the main problem as operational delay: manual approvals and fragmented workflows stop employees from getting the right access at the right time.

That matters to IAM and IGA because the failure mode is not limited to onboarding. Mid-life role changes and offboarding both depend on timely access updates, and when those changes lag, the organisation accumulates productivity loss, lingering access, and avoidable governance debt.


Key questions

Q: What breaks when employee lifecycle access changes are handled manually?

A: Manual handling creates delays between employment events and entitlement updates. That means new hires wait for access, movers wait for role-appropriate apps, and leavers can retain access longer than intended. The practical failure is governance drift: actual access no longer matches employment status, which increases both operational friction and residual exposure.

Q: Why do delayed access approvals create security risk in SaaS-heavy environments?

A: Because the delay leaves users waiting while business work continues, which encourages workarounds and makes entitlement state harder to keep aligned with roles. In a SaaS-heavy estate, every app request adds another place where access can lag behind the business event that should have triggered it.

Q: What happens when offboarding does not remove access promptly?

A: When offboarding is slow or incomplete, departing employees can keep access to sensitive systems and data after they no longer need it. That creates avoidable exposure, especially where accounts span multiple applications or branches. Security teams should treat revocation as a required control, because delayed removal turns a normal personnel change into a standing access risk.

Q: How should organisations implement employee self-service access requests without losing governance control?

A: Organisations should put employee self-service requests inside a policy-driven IGA workflow, not treat them as open-ended access forms. The request should be filtered through role or attribute rules, routed to the right approver, and fully logged from submission to provisioning. That keeps access faster for users while preserving auditable control, least privilege, and a clear review trail for compliance teams.


Technical breakdown

Why manual provisioning fails across the employee lifecycle

Manual provisioning creates a queue between business need and access delivery. New hires wait for day-one access, movers wait for entitlements that match a new role, and leavers keep accounts alive longer than they should. The technical issue is not authentication strength, but process latency: access decisions are made by people, tickets, and handoffs instead of policy-driven lifecycle events. In a SaaS-heavy environment, that delay multiplies because every app, group, and channel becomes another approval step. The result is a control surface that is difficult to keep aligned with actual employment status.

Practical implication: replace ticket-based access handling with policy-driven lifecycle workflows tied to joiner, mover, and leaver triggers.

How self-service access changes the mover problem

A self-served model changes the mover problem by reducing dependence on central IT for routine access changes. When a promotion, transfer, or department shift occurs, employees can request or obtain approved apps through a controlled catalogue rather than waiting for ad hoc ticket fulfilment. That does not remove governance. It shifts it toward predefined access options, role alignment, request transparency, and approval paths that are easier to audit. In practical terms, the control is about speed with structure, not speed alone.

Practical implication: define a governed app catalogue and role-based request paths so mover access changes happen without unmanaged delays.

Why offboarding must revoke access, not just disable a mailbox

Offboarding fails when the organisation treats departure as a single account event instead of a full entitlement lifecycle. The article points out that former employees may still receive notifications, remain in groups, and retain access to sensitive data if deprovisioning is incomplete. That is a governance gap because access persists beyond accountability. In identity terms, the risk lives in residual group membership, unrevoked application access, and incomplete account deactivation. The lifecycle boundary has to be enforced across every connected system, not just the core directory.

Practical implication: make offboarding a full entitlement revocation workflow across applications, groups, and channels, not a mailbox closure task.


Threat narrative

Attacker objective: The practical objective is to keep access alive longer than employment status warrants so work continues and sensitive resources remain reachable.

  1. Entry occurs through manual onboarding or role change processes that leave employees waiting for access and operating outside normal workflow.
  2. Privilege persists when movers and leavers retain application, group, or channel access after their status changes.
  3. Impact follows as productivity slows, outdated access remains active, and sensitive data stays reachable after departure.
  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Employee lifecycle management is an access control discipline, not an HR convenience. When access changes do not keep pace with joiner, mover, and leaver events, the organisation is no longer governing entitlement accurately. That creates both user frustration and governance drift, because the access model no longer reflects the current workforce state. The practitioner conclusion is that lifecycle timing is itself a security control.

Manual ticketing is a control bottleneck that distorts access governance. The article shows how request queues turn routine entitlement changes into delayed exceptions. That delay encourages shadow workarounds, creates inconsistent provisioning outcomes, and makes audit evidence less reliable because access state changes are scattered across processes. The practitioner conclusion is to treat workflow latency as a governance defect, not a service desk issue.

Deprovisioning is the real offboarding test. Access removal must cover applications, groups, channels, and account state together or the organisation leaves residual access behind. The governance assumption that an employee departure ends access everywhere at once is false in fragmented SaaS estates. The practitioner conclusion is to measure offboarding by revocation completeness, not by ticket closure.

Passwordless login does not solve lifecycle governance gaps. SSO may reduce friction at authentication, but the article’s real problem sits in entitlement timing and removal. A faster login path does nothing if an employee still lacks the right app on day one or retains access after departure. The practitioner conclusion is that authentication improvements and lifecycle controls address different failure modes and should not be conflated.

Role-based access should be operationalised through lifecycle triggers, not static provisioning assumptions. The article’s strongest signal is that role, designation, and department only help when the entitlement workflow updates quickly enough to follow them. That is the named concept this article exposes: access timing drift. The practitioner conclusion is to align provisioning and deprovisioning with actual employment events, not annual cleanup cycles.

What this signals

Access timing drift: When entitlement updates lag behind joiner, mover, and leaver events, the access model stops reflecting the workforce state and governance evidence becomes stale. Programmes should watch lifecycle latency as a control signal, not just a service metric.

Manual provisioning in SaaS-heavy environments tends to move risk into the gaps between ticket submission, approval, and fulfilment. The operational question is whether access state changes are happening close enough to employment events to keep residual exposure from accumulating.

Offboarding should be measured by revocation completeness across applications, groups, and channels. If any connected system still recognises the departed user, the lifecycle boundary has not actually been enforced.


For practitioners

  • Implement joiner-mover-leaver workflows Map onboarding, transfer, and exit events to automatic entitlement changes across core business apps, collaboration tools, and directories. Replace manual approvals for standard cases with policy-driven workflows that preserve auditability.
  • Build a governed app catalogue Expose approved applications through a controlled request path so employees can obtain role-appropriate access without ad hoc ticket queues. Keep approvals, role mapping, and request status visible for audit and support teams.
  • Rework offboarding into full revocation Remove group membership, application access, and account state in one workflow when employment ends. Track completion across every connected system so former employees do not retain residual access.
  • Separate authentication from entitlement governance Use SSO or passwordless sign-in to simplify login, but do not treat it as a substitute for lifecycle controls. Measure access control success by how quickly rights change when roles change, not only by how users authenticate.

Key takeaways

  • Employee lifecycle management is the real access control test because access must change when the job changes, not when a ticket is finally resolved.
  • The article shows that manual provisioning slows work and leaves access mismatched to current roles, especially in SaaS-heavy environments.
  • Offboarding only works when every entitlement is revoked, because partial removal leaves former employees and residual exposure behind.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementThe article centers on lifecycle handling of user accounts and access changes.
Recommendation — Use CIS-5 to standardise account creation, change, and removal across the employee lifecycle.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe main issue is whether entitlements change promptly as employees join, move, and leave.
Recommendation — Apply PR.AA-05 to keep access permissions aligned with role changes and departures.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeDelayed provisioning and revocation create access that no longer matches need-to-know.
Recommendation — Enforce AC-6 so users receive only the access required for their current role.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article explicitly calls out deprovisioning failures that leave access active after departure.
NHI-05 — Overprivileged NHIRole drift can leave employees with more access than their current job requires.
Recommendation — Treat offboarding as a revocation workflow and remove all residual access paths. Review entitlements after role changes and remove access that exceeds current job needs.

Key terms

  • Employee lifecycle automation: Employee lifecycle automation is the use of workflows and system integrations to carry out onboarding, role changes, and offboarding with minimal manual handling. In identity programmes, the security test is not speed alone, but whether each event produces the correct access, entitlement, and audit outcome across connected systems.
  • Joiner Mover Leaver: Joiner Mover Leaver is the identity lifecycle process for creating, changing, and removing access as people enter, change roles, or leave an organization. It governs provisioning, modification, and deprovisioning across systems, ensuring access matches current job needs and reducing orphaned accounts, privilege creep, and residual access risk.
  • Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.
  • Self-Service Access: Self-service access lets users request, approve, or obtain access to systems and data through a controlled workflow without manual intervention from an administrator. It usually relies on policy checks, identity verification, and automated provisioning, so access is granted only when the request matches defined roles, attributes, risk conditions, and approval rules.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org