Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Physical access and JML: where identity lifecycle still breaks


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12324
Topic starter  

TL;DR: Joiner-mover-leaver governance only works when lifecycle events revoke and adjust access across both digital systems and physical credentials, according to AlertEnterprise. The control gap is not the workflow itself but the perimeter it fails to cover, because badge access often remains on a parallel manual track after HR changes.

NHIMG editorial — based on content published by AlertEnterprise: The Joiner-Mover-Leaver Process and Physical Access

By the numbers:

  • The 2025 State of NHIs and Secrets in Cybersecurity found that 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches.
  • The 2025 State of NHIs and Secrets in Cybersecurity found that 62% of all secrets are duplicated and stored in multiple locations, causing unnecessary redundancy and increasing the risk of accidental exposure.
  • The 2025 State of NHIs and Secrets in Cybersecurity found that 60% of NHIs are being overused, with the same NHI utilised by more than one application, increasing the risk of widespread compromise if exposed.

Questions worth separating out

Q: How should organisations extend joiner-mover-leaver to physical access?

A: They should connect lifecycle events from the authoritative HR source to badge issuance, badge modification, and badge revocation.

Q: Why do physical badges often outlast employee status changes?

A: Because many organisations run physical access on a separate manual track.

Q: What do security teams get wrong about lifecycle audits?

A: They often treat audits as evidence collection after the fact, instead of using them to expose control failures in access governance.

Practitioner guidance

  • Extend lifecycle triggers to physical access Connect HR status changes to badge issuance, badge modification, and badge revocation so physical access follows the same joiner-mover-leaver event as digital access.
  • Time-bind contractor credentials Require every non-employee badge or mobile credential to carry an expiry tied to the engagement end date, with renewal only through explicit approval.
  • Measure revocation latency across domains Track the hours between the leaver event and the last active access right, including the badge, and report that number alongside digital deprovisioning metrics.

What's in the full article

AlertEnterprise's full blog covers the operational detail this post intentionally leaves for the source:

  • The exact SailPoint integration flow used to extend joiner-mover-leaver events into physical access decisions.
  • The certified Alert Enterprise Guardian for SailPoint handoff for badge and mobile credential provisioning.
  • The full contractor and non-employee lifecycle discussion, including time-bound access and revocation across digital and physical domains.
  • The companion-guide references for certifications and access reviews that span facility access and application entitlements.

👉 Read AlertEnterprise's blog on extending joiner-mover-leaver to physical access →

Physical access and JML: where identity lifecycle still breaks?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11878
 

JML that stops at the digital perimeter is not complete identity lifecycle governance. The article correctly exposes a common governance split: HR-driven lifecycle events govern applications, while physical access often remains manually administered. That split means the identity has one status in IAM and another in facilities operations, which is a lifecycle control failure rather than a tooling limitation. For practitioners, the conclusion is simple: if badges are outside the same lifecycle event model, the programme is not governing the full identity.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when contractor badge access is still active after the engagement ends?

A: Accountability sits with the organisation that owns the access decision and the lifecycle process, not with the badge hardware. If contractor access is not time-bound, not tied to engagement expiry, or not revoked through the same governance path, the control failure is organisational.

👉 Read our full editorial: Joiner-mover-leaver governance now extends to physical access



   
ReplyQuote
Share: