Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What breaks when joiners, movers, and leavers are…
NHI Lifecycle Management

What breaks when joiners, movers, and leavers are handled manually in a shared care environment?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: NHI Lifecycle Management

Manual joiner, mover, and leaver processes break down when access changes happen slowly or depend on helpdesk intervention. In a shared care environment, that creates delays for clinicians, leaves temporary access in place too long, and increases the burden on IT teams. It also makes it harder to maintain an accurate audit trail and consistent control over patient data.

Why manual JML breaks the care model

Manual joiner, mover, and leaver handling fails because access changes depend on people noticing the event, raising the right ticket, and waiting for another team to act. In a shared care environment, that creates a gap between role change and access change. The result is delayed care access for legitimate users and lingering access for users who no longer need it.

That gap is especially harmful where clinical work crosses teams, shifts, or organisations. Temporary exceptions become normal, and the process stops reflecting the real state of employment, case assignment, or clinical responsibility.

For a broader operating view, the problem is the lifecycle itself: provisioning, mover updates, and deprovisioning need to stay aligned with real-world responsibility changes. The Joiner-Mover-Leaver (JML) Guide and the IAM and IGA Basics guide both map that lifecycle to access governance and recertification.

What breaks in shared care operations

Three things usually break first. Access becomes too slow for clinicians who need it now, so workarounds appear. Access becomes too broad for people who have moved roles, so stale entitlements remain active. And the control record becomes unreliable, because the organisation can no longer trust that the current access set matches the current care relationship.

Shared care makes this worse because the same patient, system, or workspace may be used by multiple teams. A mover event may need old-role access removed while new-role access is granted, and a leaver event may need both immediate revocation and review of delegated or shared credentials. Manual handling often misses one side of that change.

That is why lifecycle controls are not just administrative hygiene. The NHI Lifecycle Management Guide is useful here because it ties lifecycle actions to provisioning, offboarding, and visibility, which are the same failure points that show up when access is managed by ticket queue instead of state change.

Why the control record and audit trail deteriorate

Manual workflows also weaken auditability. If access changes are handled through emails, approvals, and helpdesk intervention, the organisation may have partial evidence of intent but not a clean record of when access actually changed. That makes it harder to prove timely removal, consistent approvals, and accurate assignment of responsibility.

In a shared care setting, that matters because patient data access needs to be explainable after the fact. If the access trail is fragmented, teams cannot easily show who had access, why they had it, or whether the access still matched the care function at the time it was used.

Where the issue extends beyond human users to accounts, tokens, or service identities, lifecycle evidence becomes even more important. The Top 10 NHI Issues resource covers the wider pattern of stale accounts, excessive permissions, and poor visibility that manual processes tend to leave behind.

Risk and Threat Considerations

Manual JML creates a security window where access outlives the legitimate need for it. In a shared care environment, that can expose patient information, delay containment after role change, and leave inactive or moved users with standing access that should already have been removed.

Failure mechanism: The organisation depends on human-triggered ticketing and coordination, so deprovisioning lags behind role change and access reviews do not keep pace with actual clinical responsibility.

Impact: Excess access persists, audit evidence becomes weaker, and any mistake or misuse of that stale access becomes harder to detect, explain, and contain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementJML is account lifecycle control and entitlement removal for changing roles.
AU-2 — Event LoggingManual JML needs traceable evidence of who changed access and when.
Recommendation — Automate account lifecycle changes and promptly disable or remove access when roles change or end. Log provisioning and deprovisioning events so access changes are auditable end to end.
ISO/IEC 27001:2022A.5.16 — Identity managementShared care access depends on controlled identity lifecycle and role changes.
Recommendation — Maintain authoritative identity records so access follows current business and care roles.
CIS Controls v8CIS-5 — Account ManagementManual JML breaks consistent account provisioning, review, and removal.
Recommendation — Centralise account management and remove stale access as soon as it is no longer required.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingLeaver handling in shared care leaves access active when offboarding is delayed.
Recommendation — Revoke access and credentials immediately when a user or workload leaves scope.

Practitioner Guidance

What to prioritise: Treat joiner, mover, and leaver handling as an access-state problem, not a paperwork problem. The first thing to stabilise is the authoritative source of role change, because everything else depends on whether the system knows that access should change now.

What to verify: Check that mover events remove old-role access as deliberately as they add new-role access, and that leaver events revoke everything that should not survive the person’s departure, including temporary exceptions and shared access paths.

What good looks like: The access record updates quickly enough that clinicians are not forced into workarounds, while the audit trail still shows who approved what, when it was applied, and when it was removed.

Practitioner takeaway: In shared care, the real failure is not just delay, it is drift between current responsibility and current access. If that drift is not automated and evidenced, both care delivery and control assurance degrade together.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org