TL;DR: Access onboarding and termination policies are meant to enforce least privilege, automate offboarding, and prevent internal misuse, but StrongDM’s guidance shows they still fail when role changes, third-party systems, and manual handoffs are left outside the process. The real issue is that access review cadences assume lifecycle events are captured consistently, which is often untrue.
Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “Best Practices When Writing Your Access Onboarding & Termination Policy”.
By the numbers:
- Employees and other internal users were the cause of 60% of data breaches in 2016.
Key questions
Q: What breaks when access onboarding and termination is only managed in one directory?
A: The control breaks when access exists in more than one system.
Q: Why do role changes create so much access creep?
A: Role changes create access creep because organisations are faster at adding new access than removing old access.
Q: How can security teams tell whether termination controls are actually working?
A: Look for complete revocation evidence across every system that can authenticate the user, not just the HR or primary directory record.
Practitioner guidance
- Map every access-bearing system Build a complete inventory of internal applications, external portals, support tools, and managed service platforms that can grant or retain access after onboarding or termination.
- Tie mover events to entitlement reset Require every role change to trigger an entitlement review against the new job scope, with old access removed before new access is confirmed.
- Automate termination closure checks Use workflow triggers to confirm that access has been revoked in every system listed for the user, not only in the central directory.
Bottom line: Access onboarding and termination only works when it governs every place access can exist, not just the primary identity store.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Lifecycle control fails first as a governance design problem, not an implementation gap. Access onboarding and termination policies assume that identity state changes are captured once and propagated everywhere that access exists. That assumption breaks when HR, IT, app owners, and third-party platforms maintain different records of who should still have access. The implication is that lifecycle governance must be measured by actual entitlement closure, not by policy existence.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should prioritise access governance over access management first?
A: Organisations with heavy regulation, complex role structures, or weak visibility into entitlements should usually prioritise governance first. That includes environments that must prove access decisions to auditors or manage many role changes across business units. If enforcement already exists but oversight is thin, governance closes the policy, review, and evidence gap that operational tools do not solve.
👉 Read our full editorial: Access onboarding and termination policies still fail on lifecycle control