By NHI Mgmt Group Editorial TeamBased on Zluri: “Here's How to Solve User Lifecycle Management Problem in Your Organization” (September 12, 2025)

TL;DR: User lifecycle management remains a weak point because organisations still rely on manual onboarding, mid-lifecycle access changes, and offboarding steps that are slow, error-prone, and easy to miss, according to Zluri. Automated lifecycle workflows reduce operational drag, but the real security value is tighter entitlement control across the full employee journey.


At a glance

What this is: This article argues that user lifecycle management fails most often at onboarding, role changes, and offboarding because manual steps create delay and entitlement drift.

Why it matters: It matters because IAM and IGA teams need lifecycle controls that keep access aligned with job changes and departure events across the full employment journey, not just at joiner time.


Context

User lifecycle management is the process of granting, changing, and removing access as people join, move roles, and leave an organisation. When those steps rely on tickets, manual approvals, or ad hoc coordination, access becomes slower to provision and harder to revoke cleanly.

The governance gap is not limited to onboarding. Mid-lifecycle changes and offboarding are where entitlement drift, shadow IT, and delayed revocation most often appear, which makes lifecycle management a core IAM and IGA control rather than a back-office workflow exercise.


Key questions

Q: What breaks when lifecycle management is still manual?

A: Manual lifecycle management creates delays between a business event and the identity update that should follow it. New hires wait for access, movers accumulate old permissions, and leavers keep credentials longer than they should. The result is predictable drift, avoidable audit issues, and higher security exposure.

Q: Why do mover events create privilege creep so quickly?

A: Mover events create privilege creep because each internal change usually adds new access while removal is delayed, incomplete, or forgotten. Over time, the identity accumulates permissions from multiple roles, projects, and temporary coverage tasks. Without visible current access and explicit offboarding logic for old entitlements, the accumulation becomes normalised.

Q: How do organisations know offboarding is actually complete?

A: They know offboarding is complete when the revocation checklist is built from current entitlements, not from an old spreadsheet or onboarding record. Completion should be confirmed against live access data across apps, directories, and privileged systems. If the workflow cannot prove removal, the account is not fully offboarded.

Q: Should teams prioritise lifecycle automation before expanding app access requests?

A: Yes, because access request tooling does not fix a weak lifecycle model. If joiners, movers, and leavers are not governed first, faster requests simply move bad entitlement decisions more efficiently. Lifecycle automation should come before broader self-service expansion so that approvals and revocations stay aligned with role changes.


Technical breakdown

Why manual onboarding creates entitlement drift

Manual onboarding usually means access is assembled app by app, often after the employee has already started work. That creates variance between the role the business expects and the access the user actually receives. In identity governance terms, the problem is not only delay. It is the absence of a repeatable entitlement model that maps roles, app access, and approval logic into a consistent joiner process. Where that model is missing, first-day access becomes a mix of incomplete provisioning, overprovisioning, and later cleanup work.

Practical implication: define role-based onboarding workflows with the entitlement set pre-approved before the user arrives.

How mid-lifecycle changes turn into access sprawl

Promotions and role changes are the point where old access should be removed and new access should be added. In practice, organisations often add the new permissions and forget to retire the old ones, especially when approvals are handled through disconnected tickets or informal requests. That is classic privilege creep, but in employee lifecycle form. The control issue is lifecycle recertification tied to job change events, not periodic cleanup after the fact. If the mover event is not treated as an access reset point, users accumulate permissions that no longer match their responsibilities.

Practical implication: trigger access review and entitlement recalculation on every role change, not only during annual certification cycles.

Why offboarding remains the highest-risk lifecycle step

Offboarding is the point where access must stop cleanly across SaaS, SSO, and downstream systems. If revocation is delayed or partial, the former employee can retain valid access after departure, and shared business data can remain in the wrong account. This is why offboarding is not just a workflow problem. It is a control boundary problem across identity systems, licenses, and data ownership. A strong offboarding process has to remove access, transfer assets, and close the account path in one governed sequence rather than as separate administrative tasks.

Practical implication: make offboarding an automated revocation sequence that removes access, transfers ownership, and closes dormant identity paths together.


Threat narrative

Attacker objective: The objective is continued access to business systems and data after the organisation has lost the operational reason for that access.

  1. Entry occurs at onboarding when new users wait on manual provisioning and interim access decisions are made outside a governed workflow.
  2. Escalation appears during role changes when new permissions are added without removing the old ones, expanding effective access beyond the job need.
  3. Impact follows at offboarding when revoked access is incomplete or delayed, leaving ex-employees able to reach SaaS apps, data, or shared workspaces.
  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Lifecycle control is now an access-security discipline, not an HR workflow. Onboarding, mover events, and offboarding are the three places where identity governance either keeps pace with the organisation or falls behind it. The article reinforces that manual handling turns lifecycle state into entitlement drift, which means the control surface is the full employee journey, not the first-day setup task. Practitioners should treat joiner-mover-leaver design as a governed access model.

Role changes are the most undercontrolled source of privilege creep. A mover event should behave like a new access baseline, but many programmes only add rights and never retire the old ones. That creates durable over-entitlement that survives organisational change and defeats least-privilege intent. The practitioner conclusion is simple: if movers are not wired into entitlement recalculation, the access model is already stale.

Offboarding exposes the real maturity of identity governance. If revocation happens late, in fragments, or only for a subset of systems, the organisation has not removed access, it has merely created administrative residue. That is why offboarding should be assessed as a control-completeness problem across SaaS, SSO, and ownership transfer. Teams should measure whether access removal is deterministic, not whether the ticket closed.

Lifecycle automation is only valuable when it shortens the gap between business change and access change. The point is not to automate for its own sake. The point is to reduce the window in which identities carry permissions that no longer match their business role. The operational test is whether joiner, mover, and leaver events all trigger timely, auditable entitlement updates.

Well-run lifecycle programmes make identity governance observable. When onboarding playbooks, mover approvals, and offboarding revocation all follow the same control logic, teams can see where access decisions drift from policy. That visibility is what turns lifecycle management from an operational chore into a governance signal. Practitioners should use lifecycle data to find where access and role state no longer align.

What this signals

Joiner-mover-leaver governance is the real control plane behind user lifecycle management. Once organisations move beyond manual task lists, the question becomes whether every role change and exit event produces a clean entitlement change. The programme signal is straightforward: if access state and employment state can diverge for days, the lifecycle model is still compensating for process gaps rather than controlling them.

Lifecycle exceptions are the leading indicator of entitlement drift. Users whose access does not match their role, manager, or departure status reveal where workflow design is failing. Teams should treat those exceptions as governance defects, not administrative noise, because they show where identity state is no longer trustworthy.

Automation only pays off when it compresses revocation latency. Faster onboarding matters, but faster offboarding is the security hinge. If departure handling is still slower than role churn, the organisation is creating unnecessary exposure windows even when it believes lifecycle tooling is in place.


For practitioners

  • Standardise joiner workflows Build role-based onboarding templates that predefine the application and entitlement set for common job functions before the employee starts.
  • Reset access on mover events Treat promotions and department changes as entitlement reset points, with old access removed at the same time new access is granted.
  • Automate offboarding revocation Use a single offboarding sequence to revoke SaaS access, SSO sessions, and downstream app permissions, then transfer data ownership.
  • Track lifecycle exceptions Review users whose access state does not match their employment status, role, or manager approval path, and prioritise those exceptions for correction.

Key takeaways

  • User lifecycle management breaks when onboarding, role changes, and departures are handled as disconnected tasks instead of one governed access journey.
  • The main failure mode is entitlement drift, where manual handling leaves users overprovisioned, underprovisioned, or still active after they leave.
  • Practitioners should automate role-based onboarding, reset access on mover events, and make offboarding a deterministic revocation sequence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 provides the primary governance reference for this term.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementLifecycle workflows depend on managing credential issuance, change, and removal across the user journey.
Recommendation — Apply authenticator management controls to ensure credentials are issued, changed, and revoked with lifecycle events.

Key terms

  • User Life Cycle Management: User life cycle management is the end-to-end process of creating, updating, reviewing, and removing user identities and access across enterprise systems. It links identity governance to employee onboarding, role changes, and offboarding so access stays aligned with job responsibilities and business need.
  • Joiner Mover Leaver: Joiner Mover Leaver is the identity lifecycle process for creating, changing, and removing access as people enter, change roles, or leave an organization. It governs provisioning, modification, and deprovisioning across systems, ensuring access matches current job needs and reducing orphaned accounts, privilege creep, and residual access risk.
  • Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
  • Offboarding Revocation Window: The time between a user or workflow no longer needing access and that access being fully removed across relevant systems. Longer windows increase the chance that obsolete credentials, sessions, or delegated rights can be reused during or after departure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org