Manual joiner mover leaver handling creates inconsistent access, delayed productivity, and incomplete removal of entitlements when people change roles or leave. It also increases help desk tickets and makes audit evidence harder to prove. Over time, the business pays in wasted time, shadow tools, and lingering access that no one can confidently explain.
Why This Matters for Security Teams
Manual joiner mover leaver handling looks manageable in small environments, but at scale it becomes a control problem, not an admin task. Every delay in role change or termination creates a window where access no longer matches business need. That breaks least privilege, weakens auditability, and leaves security teams unable to prove who had access, when, and why. The risk is even sharper for NHIs and service accounts, where lifecycle steps are often less visible than human onboarding.
NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, and only 20% have formal processes for offboarding and revoking API keys. That is the practical consequence of manual lifecycle management: identity sprawl, lingering entitlements, and evidence gaps that surface during audits or incidents rather than during routine reviews. The Ultimate Guide to NHIs — Why NHI Security Matters Now explains why this gets worse as identity volume and privilege density increase.
NIST’s Cybersecurity Framework 2.0 treats identity governance as a core operational capability, not a clerical back office function. In practice, many security teams encounter excess access only after a role change, termination, or audit finding has already exposed the gap.
How It Works in Practice
Manual JML processes usually depend on tickets, emails, spreadsheets, and human follow-up. That workflow fails because identity state changes are not event-driven, and access is not revoked or adjusted at the same pace as business change. The result is inconsistent provisioning, delayed deprovisioning, and approvals that reflect old job titles instead of current need. For NHIs, the same pattern shows up in API keys, tokens, certificates, and service accounts that remain active long after their owners or workloads have changed.
Current guidance suggests moving from manual review to policy-driven lifecycle automation. That means mapping each joiner, mover, and leaver event to a defined access outcome, then enforcing it through IAM, PAM, and secrets management controls. For humans, this often includes Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs as a model for rotation, expiration, and revocation discipline. For NHIs, best practice is to couple inventory with ownership, expiration, and automated removal so that access does not outlive the business process that justified it.
- Trigger access changes from authoritative sources such as HR, ITSM, or CMDB, not from manual email requests.
- Use RBAC for baseline entitlements, then layer approval checks for exceptions and privileged access.
- Automate revocation for leavers and time-bound elevation for movers with JIT controls.
- Track both human and non-human identities in the same lifecycle review so orphaned access is visible.
For broader control design, NIST CSF 2.0 and the CISA Zero Trust Maturity Model both support continuous validation rather than one-time access decisions. These controls tend to break down when identity records are fragmented across SaaS, cloud, and legacy directories because no single system has complete authority over entitlement state.
Common Variations and Edge Cases
Tighter automation often increases implementation and governance overhead, requiring organisations to balance faster access changes against the cost of integrating source systems, cleanup rules, and exception handling. That tradeoff is real, especially where mergers, contractor populations, or shared service accounts complicate ownership.
There is no universal standard for every JML scenario yet, but the direction of travel is clear: policy should decide what access should exist, while systems should enforce it without waiting for human intervention. In mature environments, this includes role mining, periodic access recertification, and clear offboarding for both people and machine identities. In less mature environments, a phased approach is often safer: start with termination revocation, then expand to mover events, then automate joiner provisioning.
Edge cases usually involve exceptions that never expire, emergency access that becomes permanent, or shared accounts with no accountable owner. The NIST Cybersecurity Framework 2.0 supports documenting and governing those exceptions, but it does not remove the need for local policy discipline. The operational lesson is simple: manual JML works until identity volume, turnover, and privilege complexity exceed what people can reliably reconcile by hand.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Addresses access enforcement and revocation across identity lifecycle events. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Lifecycle gaps often leave non-human identities orphaned or overprivileged. |
| CSA MAESTRO | IAM-03 | Agent and workload identities need continuous lifecycle governance, not manual handling. |
| NIST AI RMF | AI RMF stresses governance and accountability for dynamic identity and access decisions. | |
| NIST Zero Trust (SP 800-207) | SP 800-207 | Zero Trust requires continuous verification as identities and entitlements change. |
Use lifecycle automation to keep agent and workload access aligned to current task scope.
Related resources from NHI Mgmt Group
- What breaks when joiner, mover, leaver processes are handled differently for technical accounts?
- What breaks when joiner-mover-leaver processes are applied to AI agents?
- What breaks when CSR processes are handled manually at scale?
- What breaks when vendor access reviews are handled manually at scale?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org