By NHI Mgmt Group Editorial TeamBased on Zluri: “Top 3 Reasons Why ULM Tools Fail with Midlife Cycle Changes” (October 13, 2025)

TL;DR: User lifecycle management tools often work at onboarding and offboarding but struggle when employees change roles, because access grants, revocations, approvals, and app discovery become error-prone midstream, according to Zluri. The deeper issue is that lifecycle governance breaks when entitlement state changes faster than review and approval workflows can absorb.


At a glance

What this is: This article argues that user lifecycle management breaks down most visibly during midlife cycle role changes, when access decisions become more complex than onboarding or offboarding flows.

Why it matters: IAM and IGA teams need to treat role changes as a distinct governance moment because delayed approvals, manual access changes, and weak app discovery can quickly turn into productivity and compliance issues.


Context

User lifecycle management is the set of processes that grant, change, and revoke access as people move through joiner, mover, and leaver stages. This article focuses on the mover problem, where role transitions force entitlement changes across applications, approvals, and discovery workflows.

The governance gap is not that lifecycle tools fail everywhere. It is that many tools are optimised for clean entry and exit states, while midlife cycle changes create messy transitions that are slower, more manual, and easier to get wrong. That makes the mover stage a distinct IAM and IGA control problem rather than a simple extension of onboarding.


Key questions

Q: What breaks when user lifecycle tools handle role changes poorly?

A: The mover stage breaks first. Access no longer matches the employee’s current role, so teams end up with either stale permissions or delayed access to needed applications. That creates productivity friction and governance risk at the same time, because the identity state lags behind the business change.

Q: Why do midlife cycle access changes create more risk than onboarding?

A: Because the identity already has existing access that must be selectively changed rather than simply created. That makes the process more complex, more error-prone, and more dependent on accurate app discovery, timely approvals, and correct revocation. Small workflow delays can leave the wrong access in place.

Q: How can security teams tell whether mover workflows are actually working?

A: Look for evidence that access is removed as often as it is added, that app owners can approve changes quickly, and that periodic reviews catch stale entitlements. If employees keep old access after moving teams, the workflow exists on paper but not in practice.

Q: Should organisations treat role changes as a separate lifecycle control?

A: Yes. Role changes deserve their own governance treatment because the access state must be recalculated, not just updated. Treating movers as a distinct control point helps teams define who approves changes, how app needs are discovered, and when access should be removed or replaced.


Technical breakdown

Why midlife cycle entitlement changes are harder than onboarding

Midlife cycle changes are operationally difficult because the identity still exists, but its required access profile changes. That means teams must decide what to keep, what to remove, what to add, and what to approve across multiple systems at once. Manual handling increases the chance of stale access, overprovisioning, and delayed access to required tools. The technical issue is not just workflow friction. It is entitlement drift during a live employment transition, where access state must be synchronised with a changing role and business need.

Practical implication: model role changes as entitlement recalculation events, not simple user updates.

How approval chains slow down access revocation and provisioning

When approval workflows are long or fragmented, the identity state can lag behind the business state. A user may already have moved roles while requests are still waiting, which creates a window where old access remains in place or new access is not yet available. In lifecycle terms, the system is treating entitlement change as an exception process rather than a standard governed transition. That makes timing as important as policy, because the control failure comes from delay as much as from incorrect decisioning.

Practical implication: measure approval latency alongside access accuracy, not as a separate service metric.

Why app discovery and self-service matter in mover workflows

Mover governance depends on knowing which applications are relevant to the new role and letting the user or IT team request them without unnecessary friction. If app discovery is weak, teams miss required applications or rely on tribal knowledge to rebuild access after a role change. If the request path is too manual, employees wait while IT becomes the bottleneck. The architecture problem is incomplete visibility into the app set combined with a request process that is not aligned to changing business roles.

Practical implication: connect app discovery, request workflows, and role-based access logic so mover changes can be handled consistently.


  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Midlife cycle access change is a distinct lifecycle failure mode, not a minor variant of onboarding. The article is right to separate mover workflows from joiner and leaver workflows, because the control objective changes from provisioning or deprovisioning to controlled entitlement transformation. When role changes are treated as ordinary account maintenance, access drift becomes predictable. Practitioners should treat mover governance as its own identity lifecycle control surface.

Approval latency is a governance risk, not just an operational inconvenience. The article shows that lengthy approval chains can leave access either too broad or too delayed for the new role. That creates a gap between business reality and permission state, which is exactly where entitlement errors accumulate. IAM and IGA teams should view request turnaround as part of control effectiveness, not only service quality.

App discovery is part of lifecycle governance, not a side feature. If teams cannot reliably identify the right application set for a role transition, they will either overgrant to be safe or undergrant and slow work down. That is a governance failure because the role definition and the access catalogue are no longer aligned. The practitioner conclusion is that mover workflows need visibility, not just automation.

Employee self-service only helps when it is anchored to governed role context. The article’s emphasis on simplified requests and employee choice points to a broader truth: usability can reduce IT bottlenecks, but only if access options remain tied to approved role needs. Otherwise the organisation shifts work from IT to the user without improving control. The control question is whether self-service accelerates governed access decisions or merely hides the same approval debt.

Midlife cycle changes expose a lifecycle management gap that many programmes still underestimate. Joiner-leaver thinking assumes the risky moments are entry and exit, but the article shows that role transition can be the more error-prone state. That matters for IGA maturity because it changes where control failure is most likely to occur. The practitioner takeaway is to prioritise mover-stage governance as a first-class lifecycle requirement, not an edge case.

From our research library:

What this signals

Midlife cycle entitlement drift is the real test of lifecycle maturity. Many programmes can create accounts and remove them cleanly, but role transitions reveal whether access governance is actually aligned to business change. When the mover stage is weak, the organisation discovers that lifecycle management is being measured at the wrong points in time.

Role changes should be governed as recalculation events, not exception handling. That framing forces IAM and IGA teams to connect app discovery, approval routing, and entitlement removal into a single control path. The practical consequence is that control owners must watch for delay, not just error, because delay is often where risk accumulates.

Employee choice only improves governance when the catalogue is authoritative. Self-service can reduce ticket pressure, but it does not solve lifecycle design unless the request options map to approved role needs. Otherwise the programme simply trades IT bottlenecks for inconsistent access decisions.


For practitioners

  • Define mover-stage entitlement standards Create role-transition rules that specify which access should be removed, retained, or added when employees move between functions. Use the role change as the trigger for a fresh entitlement decision, not a manual case-by-case rebuild.
  • Measure approval latency for access changes Track how long midlife cycle access requests stay open and where they stall. Separate true policy exceptions from process delay so teams can see whether the lifecycle workflow or the approval model is the bottleneck.
  • Build application discovery into role change workflows Maintain a current application catalogue tied to job profiles so IT and business owners can identify what a moved employee actually needs. Without that mapping, the access request process will keep relying on memory and ad hoc decisions.
  • Use self-service only inside governed role boundaries Let employees request applications through a controlled catalogue, but constrain the available options to what the new role actually allows. This keeps convenience from turning into uncontrolled entitlement expansion.
  • Review mover exceptions as a lifecycle control signal Analyse repeated exceptions, manual overrides, and delayed approvals as evidence that the mover process is not absorbing role changes cleanly. Recurrent exceptions usually point to broken workflow design or an incomplete access model.

Key takeaways

  • Midlife cycle role changes are where user lifecycle management often becomes least reliable, because existing access must be transformed rather than simply issued or removed.
  • The main failure modes are entitlement drift, approval latency, and incomplete app discovery, which together create both security risk and operational delay.
  • Treat mover workflows as a distinct lifecycle control, with role-based entitlement standards, authoritative app catalogues, and measurable approval performance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on changing permissions when users move roles.
Recommendation — Align mover workflows to PR.AA-05 so entitlements are recalculated when roles change.
CIS Controls v8CIS-5 — Account ManagementRole changes depend on accurate account and access lifecycle handling.
Recommendation — Use CIS-5 to standardise account changes, removals, and access updates during role transitions.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeMidlife cycle changes risk overprovisioning if access is not adjusted tightly.
Recommendation — Apply AC-6 to remove unnecessary access immediately when users change roles.
ISO/IEC 27001:2022A.5.18 — Access RightsThe article is about managing access rights as employees move within the organisation.
Recommendation — Use A.5.18 to govern access rights through role transitions and periodic reviews.

Key terms

  • Midlife Cycle Change: A midlife cycle change is a role or responsibility shift that happens after an identity has been provisioned but before it is offboarded. In lifecycle governance, this is the state where access must be re-evaluated, adjusted, and validated quickly to avoid stale permissions or business interruption.
  • Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
  • Access Catalogue: An access catalogue is the set of applications, roles, entitlements, or requestable resources exposed to users through a service desk or portal. It should mirror the real access model closely, or it will mislead requesters and create shadow approval paths.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org