By NHI Mgmt Group Editorial TeamBased on Delinea: “Managing the identity lifecycle of Joiners, Movers, and Leavers (JML) is the backbone to strong identity security” (July 15, 2025)

TL;DR: Joiner, mover, and leaver processes determine whether identities receive the right access at the right time, and Delinea argues that manual handoffs, privilege drift, and delayed deprovisioning create avoidable security and compliance risk. The operational lesson is that lifecycle governance is an access control problem, not an administrative afterthought.


At a glance

What this is: This is a JML lifecycle governance post showing that joiner, mover and leaver handling is the control plane for access accuracy, privilege drift reduction and timely deprovisioning.

Why it matters: It matters because IAM, IGA, PAM and offboarding teams all inherit the same failure mode when access changes are slow, manual or incomplete across human and third-party identities.


Context

JML, or joiner, mover and leaver lifecycle management, is the set of processes that creates, changes and removes access as identities move through an organisation. In practical terms, it is the operating model that decides who gets access on day one, how access shifts when roles change, and how promptly it disappears when the relationship ends.

The security gap is not a lack of policy language. It is the gap between identity events and access enforcement, especially when HR, IT and application owners rely on manual handoffs, copied entitlements or delayed notifications. For IAM and IGA programmes, that gap shows up as privilege creep, orphaned accounts and incomplete offboarding.

Delinea's article treats JML as a broad identity governance problem spanning employees, contractors and other identities, not just a one-time onboarding task. That framing is typical for organisations that still depend on tickets and spreadsheets to coordinate access changes.


Key questions

Q: What breaks when joiner mover leaver processes are handled manually at scale?

A: Manual joiner mover leaver handling creates inconsistent access, delayed productivity, and incomplete removal of entitlements when people change roles or leave. It also increases help desk tickets and makes audit evidence harder to prove. Over time, the business pays in wasted time, shadow tools, and lingering access that no one can confidently explain.

Q: Why do poor leaver processes create both security and compliance risk?

A: Because access that should end with the relationship continues to exist. That lingering access can be used for unauthorised activity, and it also leaves auditors with evidence that lifecycle controls were not enforced consistently. The risk is not only compromise, but also privacy and control failures.

Q: How should organisations handle access when employees change roles internally?

A: Organisations should link internal role changes to access changes in the same workflow. New responsibilities, approvals, and collaboration tools should be updated together so old permissions do not linger. That reduces privilege drift and makes mover processes easier to audit, especially in remote-first teams where informal handoffs are harder to spot.

Q: When is it safe to leave contractor or vendor access in place?

A: Only when the identity still has an active business need, a current sponsor and a defined end date. If any of those conditions are missing, the account should be treated as stale access and removed. Preserving unused third-party access for convenience is a common governance failure.


Technical breakdown

Joiner provisioning and birthright access

Joiner provisioning starts when a person or other identity enters the organisation and a source record, often from HR, triggers downstream account creation. The technical challenge is not account creation itself but deciding the baseline set of entitlements, also called birthright access, without overgranting access to systems the role does not require. In mature IAM and IGA designs, role models, attributes and approval paths reduce the need for human guesswork. When that trigger is fragmented or delayed, provisioning becomes inconsistent and new users either wait for access or receive too much of it.

Practical implication: tie identity creation to a reliable source of truth and predefine baseline access so onboarding does not depend on manual reconstruction.

Mover events, privilege drift and access creep

Mover events happen when an identity changes role, department, manager or project context. The technical problem is that access is additive by default: old permissions often remain because nobody owns the removal step, while new permissions are added to keep work moving. That creates privilege drift, where the entitlement set no longer matches current job needs. In access governance terms, this is a lifecycle failure, not a simple provisioning delay. It becomes especially visible in matrixed organisations where project access is temporary but entitlement cleanup is not.

Practical implication: treat role changes as entitlement subtraction events as well as addition events, with explicit removal logic in the workflow.

Leaver deprovisioning and orphaned accounts

Leaver processing is the point at which identity and access must be fully severed across directory accounts, SaaS logins and application-specific permissions. The technical risk is orphaned accounts, meaning active credentials or accounts that no longer have a valid owner or business relationship. Those accounts create standing access that survives the employment or vendor relationship and can be abused later. Effective offboarding therefore needs event-driven deprovisioning across connected systems, not only directory disablement. Where third parties are involved, the risk increases because future reuse is often used as a reason to leave access in place.

Practical implication: ensure offboarding reaches every connected application, not just the primary directory, and verify that dormant access is actually removed.


Threat narrative

Attacker objective: The attacker or insider aims to exploit stale, overbroad or orphaned access to reach data and systems after the original business need has ended.

  1. Entry occurs through a joiner or third-party onboarding path that creates accounts and grants baseline access before ownership and scope are fully disciplined.
  2. Escalation happens when mover events add new entitlements while older permissions remain active, creating privilege creep and excess access.
  3. Impact follows when leaver accounts are not fully deprovisioned, leaving orphaned credentials that can be used for unauthorised access, fraud or data exposure.
  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

JML is not an HR workflow, it is the access control system that identity security rests on. When joiner, mover and leaver events are not connected to authoritative identity enforcement, access decisions become a patchwork of manual exceptions. That breaks least privilege in practice, because entitlement accuracy depends on lifecycle state, not on static role design. The practitioner conclusion is simple: lifecycle governance is the control plane for all identity programmes.

Privilege drift is the lifecycle symptom that most organisations normalise for too long. Movers accumulate access when job changes, temporary projects and manager requests add entitlements faster than removals are executed. This is not just administrative clutter. It means the organisation has lost alignment between current function and current access, which is where audit friction, fraud exposure and internal misuse begin. The operational conclusion is that removal logic matters as much as provisioning logic.

Leaver offboarding is the point where accountability either ends cleanly or persists as an orphaned identity. The article's third-party examples are especially important because contractor and vendor access is often left in place for convenience. That creates access that outlives the business relationship and undermines the assumption that an account always has an owner. The practitioner conclusion is that leaver governance must cover every account tied to the identity, not just the primary login.

Automating JML does not replace governance, but it makes governance enforceable at lifecycle speed. Manual handoffs cannot reliably keep pace with role changes, short-term access needs or rapid exits. Automated workflows tied to HR or other authoritative systems reduce delay, but only if entitlement logic, approvals and deprovisioning are defined up front. The practitioner conclusion is that automation should close lifecycle gaps, not merely accelerate bad ones.

JML belongs inside identity governance, not beside it. The article correctly ties lifecycle management to IGA because recertification, access reviews and offboarding only work when the underlying identity state is accurate. Where JML is weak, downstream governance becomes evidence collection after the fact rather than active control. The practitioner conclusion is that governance maturity starts with lifecycle accuracy.

From our research library:

What this signals

Lifecycle accuracy is now the practical boundary between governance and drift. Once onboarding, role change and offboarding are handled through separate tickets or disconnected systems, the programme stops governing entitlement state and starts documenting exceptions. For IAM and IGA teams, the next step is to connect identity events to enforced access changes rather than to approval queues alone.

Orphaned access is the clearest sign that JML is failing. If a former employee, contractor or vendor can still authenticate or reach data, the organisation has a lifecycle control problem, not just an offboarding delay. That failure mode should drive tighter ownership, automated deprovisioning and more disciplined access review cycles.


For practitioners

  • Define lifecycle ownership for every identity class Assign explicit ownership for employees, contractors and third parties so joiner, mover and leaver changes do not depend on informal handoffs between HR, IT and application teams.
  • Automate leaver deprovisioning across connected systems Trigger account disablement, token revocation and application-level removal from the HR or source-of-truth event, not from a manual ticket that can lag behind the departure date.
  • Treat mover events as removal plus addition Build workflows that revoke obsolete entitlements when role, department or project context changes, instead of only appending new access to the existing profile.
  • Eliminate orphaned third-party access Review contractor and vendor accounts for business sponsorship, end dates and actual usage so stale accounts are removed instead of preserved for hypothetical future reuse.
  • Use access reviews to verify lifecycle state Focus certification on whether current access still matches the user's present role and relationship, especially where provisioning and offboarding have been manual or fragmented.

Key takeaways

  • JML governance determines whether identities are provisioned, adjusted and removed in line with real business state.
  • When lifecycle steps are handled manually, organisations accumulate privilege drift, orphaned accounts and inconsistent offboarding.
  • The control that matters most is end-to-end lifecycle enforcement, especially where HR, IT and application owners all touch the same identity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article repeatedly focuses on failed leaver handling and orphaned access after departure.
NHI-05 — Overprivileged NHIJoiner and mover mistakes create excess access beyond current role needs.
Recommendation — Map offboarding workflows to NHI-01 and verify every identity is fully removed when the relationship ends. Use NHI-05 to review whether current entitlements exceed the minimum required for the identity's present role.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe topic is fundamentally about controlling and updating authorisations as identities change.
Recommendation — Apply PR.AA-05 to keep entitlements aligned with joiner, mover and leaver state changes.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article discusses revoking credentials and deprovisioning access as identities leave.
Recommendation — Use IA-5 to manage credential lifecycle and remove authenticators when access is no longer needed.
CIS Controls v8CIS-5 — Account ManagementJML is account management across the identity lifecycle, especially for movers and leavers.
Recommendation — Apply CIS-5 to govern account creation, modification and removal through a defined lifecycle.

Key terms

  • Joiner Mover Leaver: Joiner Mover Leaver is the identity lifecycle process for creating, changing, and removing access as people enter, change roles, or leave an organization. It governs provisioning, modification, and deprovisioning across systems, ensuring access matches current job needs and reducing orphaned accounts, privilege creep, and residual access risk.
  • Privilege Drift: Privilege drift is the gradual gap between the permissions an identity was meant to have and the permissions it actually retains. In AI agent environments, drift grows quickly because roles are reused, tasks change, and lifecycle reviews often lag behind deployment velocity.
  • Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
  • Birthright Access: The baseline set of entitlements that a user should receive by default because of role, department, or another stable attribute. It is a governance construct, not a blanket permission model. The control challenge is proving that the baseline stays current as jobs, applications, and ownership change.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org