TL;DR: Internal movers can accumulate access in two directions at once, with one Zluri example showing a director who grew to 52 applications and 14 admin roles after four role changes. The real governance failure is that JML workflows often add entitlements for new roles without removing old access or downgrading obsolete privilege.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “How Privilege Creep Compounds in Two Directions | The Mover's Journey”.
Key questions
Q: What breaks when internal moves are handled only as entitlement additions?
A: When movers are processed only as additions, the old role never gets reconciled.
Q: Why do internal role changes create more privilege risk than joiners or leavers?
A: Joiners start from a baseline and leavers are supposed to be fully removed.
Q: How can security teams tell whether mover workflows are actually working?
A: Look for evidence that access is removed as often as it is added, that app owners can approve changes quickly, and that periodic reviews catch stale entitlements.
Practitioner guidance
- Define mover reconciliation as a required control Treat every internal role change as both an add and remove event.
- Track horizontal and vertical drift together Build reporting that shows application count, admin role count, and change history in one view.
- Review cross-team access after each promotion or transfer Check whether the account still holds access to tools owned by prior teams and whether elevated permissions remain in systems the employee no longer manages.
Bottom line: Internal role changes can create privilege creep in two directions at once, with access sprawl and admin inflation compounding over time.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Privilege creep in movers is a two-dimensional governance failure, not a single entitlement problem. The article shows that internal role changes can add more systems on one axis and higher privilege on another, creating compounding exposure instead of simple drift. That distinction matters because a programme that only measures app count or only measures admin count will miss the real control failure. Practitioners need a mover model that treats access and privilege as separate but linked inventories.
A question worth separating out:
Q: Should organisations review access and admin rights together for internal role changes?
A: Yes. Separate reviews miss the combined risk of broad access with excessive privilege. An account can look acceptable on one dimension and still be overexposed on the other. Reviewing them together is the only way to see how far a mover has drifted from the current job need.
👉 Read our full editorial: Privilege creep compounds in two directions for employee movers