When join, move, and leave processes are weak, access quickly drifts away from what users actually need. New accounts may be overprovisioned, role changes may leave excess access behind, and departing users may retain privileges that should have been revoked. That creates persistence risk, weakens least privilege, and makes identity sprawl much harder to control.
Why inconsistent JML governance causes access drift
Join, move and leave governance is the control that keeps identity state aligned with job state. When those events are not handled consistently, access stops matching the person’s current role, environment or employment status. The result is not just delay, it is systematic drift: access accumulates, changes linger, and old privileges remain active long after the business need has changed.
This is especially visible in Ultimate Guide to NHIs, which treats lifecycle governance as part of the same control problem across identities and credentials. The lifecycle view matters because a missed join or move is not a one-off admin error, it is a recurring gap that weakens entitlement accuracy over time.
In practice, weak JML handling creates three predictable patterns: new starters are overprovisioned to speed onboarding, movers keep old role access because no one removes it, and leavers retain accounts or privileges because offboarding is incomplete. Each pattern broadens the set of identities that can still authenticate, authorize, or reach sensitive systems after the original need has disappeared.
Where the control failure becomes operationally dangerous
Once JML coverage is inconsistent, access reviews stop reflecting reality. Managers may approve access based on stale role assumptions, application owners may assume another team removed access, and security teams may inherit an inaccurate inventory of active privileges. That creates identity sprawl, increases the blast radius of a compromise, and makes least privilege difficult to prove rather than simply difficult to achieve.
The risk is not limited to humans. Modern environments also rely on service accounts, API keys and other non-human identities that often follow the same join, move and leave gaps. NHIMG’s NHI Lifecycle Management Guide is useful here because it shows the same lifecycle logic applied to provisioning, rotation and offboarding where machine access persists if no one closes the loop.
Published NHIMG research also points to the scale of the problem: only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them. That is the same failure mode JML governance is meant to prevent, stale access that outlives the business event that created it.
Risk and Threat Considerations
Inconsistent join, move and leave handling creates a durable access path for both accidental misuse and malicious persistence. Former staff, changed roles or bypassed approvals can leave behind privileges that are no longer expected, which gives attackers more opportunities to abuse old accounts, stale entitlements or forgotten credentials.
Failure mechanism: Identity lifecycle events are not tied tightly enough to provisioning, transfer and revocation workflows, so access changes lag behind employment or role changes and remain effective after the need has ended.
Impact: The organisation gets wider attack surface, weaker least privilege, harder containment after compromise, and a much higher chance that stale access becomes a persistence or lateral-movement route.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 5 — Account Management | JML governance is fundamentally account lifecycle control and access revocation. |
| 6 — Access Control Management | Join, move and leave drift is an access-control failure that leaves excess privilege active. | |
| 14 — Security Awareness and Skills Training | Users and approvers often create lifecycle exceptions that weaken JML governance. | |
| Recommendation — Automate account creation, change and removal so access follows employment state. Revoke stale permissions promptly and enforce least privilege on role changes. Train approvers and service owners to report role changes and departures immediately. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | JML consistency is a direct identity and access control issue affecting entitlement accuracy. |
| PR.PT — Protective Technology | Lifecycle automation and enforcement reduce the chance that stale access persists. | |
| ID.AM — Asset Management | Identity and entitlement inventories must stay current to expose stale access and orphaned accounts. | |
| Recommendation — Keep identities, roles and access rights synchronized with current business need. Use automated provisioning and deprovisioning controls to reduce access drift. Maintain an accurate inventory of active identities, accounts and entitlements. | ||
| NIST Zero Trust (SP 800-207) | 3 — Policy Decision Point and Policy Enforcement Point | Access should be continuously evaluated against current state, not assumed from old role assignments. |
| Recommendation — Re-evaluate access decisions as identity state changes and enforce policy centrally. | ||
| OWASP Non-Human Identity Top 10 | NHI-03 — Overprivileged Non-Human Identities | Lifecycle gaps often leave machine identities with privileges beyond current need. |
| NHI-04 — Improper Offboarding | Leave events that do not revoke access are a direct offboarding failure. | |
| Recommendation — Review and remove excess privileges whenever a non-human identity changes purpose or owner. Revoke credentials and access immediately when an identity is retired or transferred. | ||
Practitioner Guidance
What to prioritise: Treat leavers first, movers second, joiners third. If you cannot reliably remove access on departure and role change, onboarding automation will only make the drift happen faster.
What to verify: For each critical system, verify that JML triggers update the identity record, entitlement set and account status together, not as separate manual tasks. The control is only trustworthy when the business event and the access state change at the same time.
Practitioner takeaway: The practical test is simple: if you cannot explain why a user still has a permission after a move or departure, the access model is already ahead of governance and should be treated as a containment risk, not an admin issue.
Related resources from NHI Mgmt Group
- What is the difference between human IAM controls and NHI governance?
- What does a mature secrets governance program need to cover?
- What does the 144:1 NHI-to-human ratio mean for IAM governance programmes?
- What happens when incident teams rely on ChatOps for just-in-time access during sensitive events?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org