By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: AlertEnterprisePublished July 15, 2026

TL;DR: Joiner-mover-leaver governance only works when lifecycle events revoke and adjust access across both digital systems and physical credentials, according to AlertEnterprise. The control gap is not the workflow itself but the perimeter it fails to cover, because badge access often remains on a parallel manual track after HR changes.


At a glance

What this is: This is an identity lifecycle management analysis showing that joiner-mover-leaver processes must extend beyond digital access to physical credentials and facilities to close a common governance gap.

Why it matters: It matters because IAM, IGA, and PAM teams cannot claim complete lifecycle control while badges, contractors, and facility access remain outside the same joiner-mover-leaver decisions.

By the numbers:

  • The 2025 State of NHIs and Secrets in Cybersecurity found that 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches.
  • The 2025 State of NHIs and Secrets in Cybersecurity found that 62% of all secrets are duplicated and stored in multiple locations, causing unnecessary redundancy and increasing the risk of accidental exposure.
  • The 2025 State of NHIs and Secrets in Cybersecurity found that 60% of NHIs are being overused, with the same NHI utilised by more than one application, increasing the risk of widespread compromise if exposed.

👉 Read AlertEnterprise's blog on extending joiner-mover-leaver to physical access


Context

Joiner-mover-leaver is the identity lifecycle discipline that turns hiring, role change, and termination into access decisions. The article's primary point is that this discipline is incomplete when it stops at application and cloud access, because physical access often follows a separate manual process that does not receive the same lifecycle trigger.

In practical terms, that means digital entitlements may be governed by HR events while badges, doors, and facility access remain outside the same control plane. For IAM teams, the governance problem is not whether JML exists, but whether it governs every access path attached to a person, contractor, or other human identity.

This is a human identity and lifecycle issue, not an NHI or agentic AI problem. The same governance logic that handles provisioning, mover revocation, and offboarding should apply consistently across badges, facilities, and physical credentials.


Key questions

Q: How should organisations extend joiner-mover-leaver to physical access?

A: They should connect lifecycle events from the authoritative HR source to badge issuance, badge modification, and badge revocation. Physical access must be governed with the same joiner, mover, and leaver logic used for applications so the person’s employment status and facility authority never diverge.

Q: Why do physical badges often outlast employee status changes?

A: Because many organisations run physical access on a separate manual track. The badge office may depend on requests, reminders, or batch processing rather than the same lifecycle trigger that disables accounts, which creates revocation lag and leaves terminated or transferred users with lingering access.

Q: What do security teams get wrong about lifecycle audits?

A: They often treat audits as evidence collection after the fact, instead of using them to expose control failures in access governance. A better approach is to make audits reveal whether approved applications, risky users, and unauthorized access are being corrected on a recurring basis.

Q: Who is accountable when contractor badge access is still active after the engagement ends?

A: Accountability sits with the organisation that owns the access decision and the lifecycle process, not with the badge hardware. If contractor access is not time-bound, not tied to engagement expiry, or not revoked through the same governance path, the control failure is organisational.


Technical breakdown

Why digital JML breaks at the physical perimeter

Joiner-mover-leaver works when a single authoritative event, usually from HR, drives provisioning and revocation across all access systems. The failure mode appears when physical access control sits on a separate operational track, with its own request path, timing, and ownership. In that setup, the person’s employment status changes before the badge system does. That creates a governance split where one identity state exists for applications and another for facility access. The result is not just inefficiency, but a broken lifecycle correlation between status and authority.

Practical implication: if physical access does not subscribe to the same lifecycle trigger as digital access, JML is only half implemented.

Birthright access, mover changes, and leaver revocation in PIAM

Physical Identity and Access Management, or PIAM, extends identity governance to badges, mobile credentials, and facility entitlements. Birthright access becomes the baseline facility access a role should receive on day one. Mover logic subtracts old facility access and adds new access in the same event. Leaver logic removes badge and credential authority immediately when the person leaves. The technical point is that PIAM does not replace PACS hardware. It governs who should hold physical access, while PACS only enforces the door decision at runtime.

Practical implication: model physical access as an identity lifecycle outcome, not a facilities-only administrative task.

Why contractor and non-employee access is the hardest lifecycle test

Contractors and vendors often sit outside clean HR-based lifecycle processes, which means their access is easier to issue than to time-bound and revoke. That creates lifecycle drift: the engagement ends, but the badge or credential remains valid. Because the underlying relationship is weaker and often shorter-lived than employment, the governance burden is higher, not lower. The article treats that as a core control problem, because non-employee identities tend to expose the weakest offboarding and recertification discipline in the enterprise.

Practical implication: tie non-employee physical access to engagement expiry and require explicit renewal rather than open-ended continuation.



NHI Mgmt Group analysis

JML that stops at the digital perimeter is not complete identity lifecycle governance. The article correctly exposes a common governance split: HR-driven lifecycle events govern applications, while physical access often remains manually administered. That split means the identity has one status in IAM and another in facilities operations, which is a lifecycle control failure rather than a tooling limitation. For practitioners, the conclusion is simple: if badges are outside the same lifecycle event model, the programme is not governing the full identity.

Physical access is the missing lifecycle domain in many IAM and IGA programmes. Facilities access is often treated as a local operational problem, but the identity decision belongs with lifecycle governance. PIAM is the discipline that closes that gap by making physical credentials subject to the same joiner, mover, and leaver logic as digital entitlements. The broader lesson is that access governance loses credibility when one domain can still lag behind HR status by hours or days.

Contractor access reveals the weakest assumptions in lifecycle design. Non-employees join and leave on engagement timelines, not employment timelines, and many organisations still manage them with ad hoc badge issuance. That creates stale physical access, weak expiry discipline, and inconsistent offboarding. The named concept here is physical access lifecycle drift: the gap between the identity event and the last active badge or credential. Practitioners should treat that drift as a measurable governance defect, not an administrative inconvenience.

Unified lifecycle governance is now the standard practitioners should expect. The value of JML is not automation for its own sake, but alignment between identity status and every access right attached to that status. When provisioning, mover subtraction, and leaver revocation all happen from the same trigger, the audit story becomes coherent across digital and physical access. The discipline should be judged on whether it can produce one identity record, one access history, and one revocation outcome.

Auditability is the real test of lifecycle maturity. The article points to a useful standard: if a manager cannot certify facility access alongside application entitlements, governance is still fragmented. That is where lifecycle programmes become defensible or fail under review. For IAM and IGA leads, the practical conclusion is to measure whether physical access can be reviewed, revoked, and evidenced with the same fidelity as digital access.

From our research:

What this signals

Physical access lifecycle drift: when badge access is not driven by the same lifecycle event as digital access, the identity programme becomes two governance systems pretending to be one. That creates audit blind spots, delayed revocation, and inconsistent manager certification across facilities and applications.

With 91% of former employee tokens still active after offboarding in our research, the broader signal is that revocation latency is a systemic governance issue, not an edge-case failure. Teams that manage badges, contractors, and facility access in separate workflows should expect the same class of stale-authority problem unless they unify lifecycle triggers.

Practitioners should treat physical access as part of the identity control plane, then align it with lifecycle evidence in the Ultimate Guide to NHIs only where the broader governance model needs NHI context.


For practitioners

  • Extend lifecycle triggers to physical access Connect HR status changes to badge issuance, badge modification, and badge revocation so physical access follows the same joiner-mover-leaver event as digital access.
  • Time-bind contractor credentials Require every non-employee badge or mobile credential to carry an expiry tied to the engagement end date, with renewal only through explicit approval.
  • Measure revocation latency across domains Track the hours between the leaver event and the last active access right, including the badge, and report that number alongside digital deprovisioning metrics.
  • Separate birthright from transferred access Define baseline physical access for each role before automation, then remove old facility access before adding new entitlements when a person moves roles.
  • Run access reviews on facilities alongside applications Include badge, door, and site access in the same certification campaigns as application entitlements so reviewers see one lifecycle record rather than two partial views.

Key takeaways

  • Joiner-mover-leaver governance is incomplete if it stops at digital access and leaves badges outside the same lifecycle trigger.
  • The strongest evidence of weak lifecycle control is revocation lag, especially for movers, contractors, and leavers with lingering physical access.
  • Practitioners should measure, certify, and revoke physical access with the same rigor they already expect for application entitlements.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Lifecycle access provisioning and revocation map directly to access control.
NIST SP 800-53 Rev 5AC-2Account management governs provisioning, modification, and deactivation across lifecycle events.
ISO/IEC 27001:2022A.5.18Access rights management covers granting, modifying, and removing user rights.
NIST SP 800-63SP 800-63CFederation and identity proofing are relevant where physical credentials derive from authoritative identity events.

Use AC-2 to ensure physical and digital access are provisioned and revoked from the same lifecycle trigger.


Key terms

  • Joiner, Mover, Leaver Workflow: A joiner, mover, leaver workflow is the process that grants, updates, and removes access as a user or identity changes state. In modern programs, the same logic should extend beyond employees to service accounts and AI agents so access does not persist after need ends.
  • Physical Identity And Access Management: PIAM is the governance layer that connects HR, identity, and physical security systems so access decisions follow one lifecycle model. It aligns badge issuance, revocation, certification, and policy enforcement across facilities, contractors, and employees, reducing the gaps that appear when physical access is managed separately from digital identity.
  • Birthright Access: The baseline set of entitlements that a user should receive by default because of role, department, or another stable attribute. It is a governance construct, not a blanket permission model. The control challenge is proving that the baseline stays current as jobs, applications, and ownership change.
  • Revocation Latency: Revocation latency is the time between a decision to remove access and the point at which that access is actually gone. It is a practical measure of how long stale privilege remains usable after a role change, offboarding, or contract end. Shorter latency means smaller exposure and cleaner audit evidence.

What's in the full article

AlertEnterprise's full blog covers the operational detail this post intentionally leaves for the source:

  • The exact SailPoint integration flow used to extend joiner-mover-leaver events into physical access decisions.
  • The certified Alert Enterprise Guardian for SailPoint handoff for badge and mobile credential provisioning.
  • The full contractor and non-employee lifecycle discussion, including time-bound access and revocation across digital and physical domains.
  • The companion-guide references for certifications and access reviews that span facility access and application entitlements.

👉 AlertEnterprise's full post covers PIAM, contractor access, and the lifecycle controls behind unified governance.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org