By NHI Mgmt Group Editorial TeamDomain: Best PracticesSource: Oleria SecurityPublished March 19, 2026

TL;DR: Identity lifecycle management is breaking down where joiner, mover, and leaver processes remain siloed, leaving organisations with access sprawl, incomplete offboarding, and weak audit evidence, according to Oleria Security. Unified automation is now the difference between defensible governance and manual lifecycle drift.


At a glance

What this is: The article argues that JML works only when onboarding, role changes, and offboarding are treated as one automated lifecycle, not three disconnected tasks.

Why it matters: That matters because identity teams governing human users and NHIs need complete, timely access changes to prevent privilege creep, orphaned access, and audit gaps.

By the numbers:

👉 Read Oleria Security's guide to identity lifecycle management and JML automation


Context

Identity lifecycle management is the discipline of provisioning, changing, and removing access as identities move through an organisation. In practice, the article shows that JML becomes a control failure when those transitions are handled as separate tickets instead of one governed system, especially when the identity subject may be a human user or a non-human identity such as a service account or API token.

The governance gap is not only speed. It is completeness: access must be visible, context-aware, and revoked across every connected system, or privilege creep and orphaned credentials persist. For practitioners, that makes lifecycle automation a core identity control rather than an administrative convenience.

The article’s framing is typical of mature lifecycle discussions, but its scope is broader than many JML guides because it explicitly includes NHIs and agentic AI tools. That makes the operational lesson more relevant to modern IAM programmes where identity change is no longer only a workforce problem.


Key questions

Q: How should organisations automate joiner, mover, and leaver workflows across human and non-human identities?

A: Start by defining lifecycle events in one control model, then connect HR, identity providers, cloud apps, and NHI systems to the same provisioning and revocation logic. Use role-based access bundles for joiners, remove obsolete permissions for movers, and enforce verifiable deprovisioning for leavers. The goal is complete execution, not just workflow approval.

Q: Why do manual access reviews and ticketing systems leave lifecycle gaps?

A: Manual reviews often lack context, while tickets only document intent. Neither guarantees that permissions were actually changed everywhere they exist. That creates stale access, incomplete offboarding, and weak evidence for audit or investigation. Lifecycle control has to be executed by systems that can confirm changes across the whole identity estate.

Q: What breaks when offboarding only disables the primary account?

A: The lifecycle control remains incomplete. Users may still have active sessions, linked app permissions, or residual access through connected systems, which means the organisation records termination without actually ending access. That is a governance failure because it creates a false sense of closure and leaves exposure behind.

Q: What is the difference between lifecycle automation and simple account provisioning?

A: Account provisioning only adds access at the start. Lifecycle automation governs the full identity journey, including role changes, entitlement removal, offboarding, and post-departure verification. That broader scope is what prevents permission creep and proves that access no longer exists when the business relationship ends.


Technical breakdown

Joiner, mover, leaver workflows and access bundles

JML automation translates business events into access decisions. Joiner workflows provision birthright access through predefined bundles tied to role, region, or department. Mover workflows compare current entitlements with the new role and remove stale permissions while adding required access. Leaver workflows coordinate deprovisioning across directories, SaaS apps, cloud systems, and secondary channels that often get missed. The technical value is in using a unified schema and direct system integrations so that lifecycle changes are executed consistently instead of being approximated through tickets and manual follow-up.

Practical implication: map every lifecycle event to a controlled access bundle and verify that deprovisioning reaches secondary systems, not just the primary directory.

Why manual ticketing breaks identity lifecycle control

Ticket-driven JML creates delay, fragmentation, and weak evidence. A ticket may record that access should change, but it does not guarantee that every downstream entitlement was actually removed or updated. It also leaves the system dependent on human confirmation, which is where orphaned accounts and permission creep survive. Automation reduces that gap by making the identity platform the execution layer, not the help desk queue. This is especially important when access changes are frequent or when the same identity spans multiple cloud and SaaS environments.

Practical implication: remove ticketing from the execution path for high-risk lifecycle changes and use it only as an exception workflow.

Post-departure monitoring and audit evidence

Modern lifecycle control does not stop at account disablement. The article highlights post-departure visibility as a way to catch reactivated accounts, lingering access, and missed machine tokens after offboarding. That matters because deprovisioning is often partial in environments with many integrations. A defensible lifecycle programme therefore needs auditable evidence of what was changed, when it was changed, and whether anything reappeared after the exit event. This is what separates a paper process from a control that can stand up to review.

Practical implication: keep monitoring active after termination and retain evidence that proves access removal was complete across the identity estate.


NHI Mgmt Group analysis

JML only works as a single control plane, not three disconnected processes. The article’s core lesson is that joiner, mover, and leaver events are one governance system with three execution states. When they are separated across HR, IT, and application teams, the organisation loses continuity and permissions survive beyond their business purpose. Practitioners should treat lifecycle governance as a unified identity control, not a workflow convenience.

Access sprawl is a lifecycle failure, not just an IAM hygiene problem. The article’s emphasis on unused permissions and role drift shows that excess access accumulates when movers are not reconciled against current need. That pattern is just as relevant to service accounts and other NHIs as it is to human users. The implication is that lifecycle controls must continuously remove stale access, not merely add new access faster.

Post-departure visibility is the named control gap that most lifecycle programmes still miss. The article describes monitoring after offboarding because disablement alone does not prove revocation. That gap is especially dangerous where secondary systems, shared drives, and API tokens remain outside the primary workflow. Practitioners should recognise that offboarding completeness is an evidence problem as much as a technical one.

Context-aware lifecycle decisions are replacing static access assumptions. The article notes that adaptive recommendation systems can use usage and peer data to refine bundles and removals. That is the right direction for IAM programmes because it moves lifecycle governance away from brittle static rules and toward decisions based on actual entitlement use. Teams should expect JML maturity to be measured by how well they can justify each permission, not by how many tickets they process.

NHI lifecycle governance is now part of mainstream IAM, not a side topic. By explicitly including API tokens, service accounts, and agentic AI tools, the article reflects a wider change in identity scope. Lifecycle discipline must therefore be applied consistently across human and non-human identities, with the same questions about join, move, leave, evidence, and revocation. Practitioners should align their IAM and NHI governance models before the sprawl becomes unmanageable.

From our research:

  • Over 95% of multi-cloud permissions remain unused, increasing risk without providing any business benefit, according to The 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
  • The lifecycle problem is not isolated to access hygiene, and our NHI Lifecycle Management Guide explains why provisioning, rotation, and offboarding need one control model.

What this signals

Permission creep is now a lifecycle measurement problem, not just an entitlement cleanup task. When unused permissions dominate the estate, access reviews become less about approval quality and more about how quickly teams can remove dead weight. Practitioners should use that signal to push lifecycle controls upstream, where entitlement creation decisions are made, rather than relying on periodic clean-up.

A mature JML programme will increasingly be judged by revocation completeness and evidence quality, not by how many onboarding requests it closes. The strongest programmes will unify human and NHI lifecycle governance so the same operational discipline applies across employee accounts, service identities, and emerging AI-driven actors.

Identity lifecycle management now needs to align with broader NIST and OWASP guidance. Teams that want a structured control baseline should map their access workflows to the NIST Cybersecurity Framework 2.0 and the OWASP Non-Human Identity Top 10, especially where stale access and over-privilege are recurring findings.


For practitioners

  • Unify joiner, mover, and leaver governance Map lifecycle events to a single control process that spans HR, directories, SaaS, cloud, and NHI systems so access changes do not depend on manual handoffs.
  • Replace ticket execution with system-driven workflows Use tickets only for exception handling and ensure the identity platform performs provisioning and revocation directly through API integrations.
  • Audit for orphaned and secondary access paths Verify that offboarding removes access from shared drives, email groups, VPNs, tokens, and vendor accounts, not only the primary user record.
  • Track post-departure reactivation signals Keep monitoring enabled after offboarding so reactivated accounts, lingering permissions, and surviving machine tokens are visible before they become incidents.
  • Rebuild access bundles from usage evidence Refresh role-based bundles using live usage data and peer comparisons so onboarding and mover changes reflect current business need, not stale assumptions.

Key takeaways

  • JML fails when onboarding, role change, and offboarding are managed as separate workflows instead of one governed lifecycle.
  • The evidence in the article points to widespread unused access, incomplete revocation, and audit gaps that manual processes cannot reliably close.
  • Practitioners should prioritise unified lifecycle automation, post-departure verification, and lifecycle governance across both human and non-human identities.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Lifecycle drift and stale access map directly to NHI governance gaps.
NIST CSF 2.0PR.AC-1Access provisioning and revocation are core protect-function identity controls.
NIST SP 800-53 Rev 5IA-5Authenticator and credential management underpin offboarding and revocation.
NIST Zero Trust (SP 800-207)Zero trust depends on continuous verification of identity state and access need.

Use zero trust principles to validate lifecycle changes continuously instead of relying on static approvals.


Key terms

  • Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.
  • Access Bundle: An access bundle is a packaged set of entitlements granted together under one requestable unit. It can improve usability and reduce ticket volume, but it also increases the importance of review, ownership, and expiry discipline because multiple privileges move as one decision object.
  • Post-departure Visibility: Monitoring that continues after an identity has been offboarded to confirm access really disappeared and did not reappear through secondary systems, delayed sync, or forgotten tokens. It turns offboarding from an assumption into an evidence-backed control.
  • Permission Creep: The gradual accumulation of access beyond what a user or workload currently needs. It usually happens because initial approvals are never fully removed or recertified. In practice, permission creep is a lifecycle failure that turns temporary exception access into de facto standing privilege.

What's in the full article

Oleria Security's full post covers the operational detail this post intentionally leaves for the source:

  • Step-by-step JML workflow examples for joiner, mover, and leaver automation across identity systems.
  • A four-step implementation framework for building lifecycle controls from visibility through post-departure auditing.
  • Operational comparisons between ticket-based workflows and direct system automation for identity changes.
  • Practical guidance on evaluating lifecycle automation solutions for auditability, integration, and scale.

👉 Oleria Security's full post covers lifecycle automation, audit evidence, and implementation challenges in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org