Accountability should sit with identity governance, HR data owners, and business managers together, because onboarding and access changes depend on accurate people data and timely approvals. HR provides source data, managers validate access needs, and IGA teams enforce workflows and controls. Shared accountability prevents gaps when users join, move, or leave.
Why This Matters for Security Teams
Joiner, mover, leaver accuracy is not just an HR hygiene issue. It is a control that determines whether access is granted, changed, or removed at the right time. For human users, stale entitlements create privilege creep; for non-human identities, the same failure mode can leave service accounts, API keys, and automation tokens active long after ownership has changed. NHIMG notes that only 20% of organisations have formal processes for offboarding and revoking API keys, which shows how often lifecycle accountability breaks down in practice. The Ultimate Guide to NHIs also shows why this matters at scale: NHIs outnumber human identities by 25x to 50x in modern enterprises.
That scale makes shared accountability essential. HR owns the source data, business managers validate whether access still matches the role, and identity governance teams enforce the workflow, evidence, and revocation controls. Security teams often assume the system of record will fix itself, but access drift usually starts when ownership is ambiguous and no one is explicitly responsible for closure. Current guidance from OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls supports least privilege and timely revocation as operational controls, not optional cleanup. In practice, many security teams encounter overprovisioned access only after a leaver account or stale entitlement has already been abused.
How It Works in Practice
Effective accountability for joiner, mover, leaver events depends on clear ownership across the full identity lifecycle. HR should maintain authoritative employment and status data, managers should confirm role changes and access relevance, and identity governance or IAM teams should translate those inputs into approvals, provisioning, and revocation. The control point is not just who clicks approve. It is who is responsible for keeping the record current, who resolves mismatches, and who can prove that access changed when the person changed.
For human identities, that usually means binding the workflow to HR events such as hire, transfer, leave, contractor end date, or termination. For NHIs, the same principle applies but the sources differ: application owners, platform teams, and automation owners must define who owns the service account, token, certificate, or secret. NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks highlights how poorly controlled lifecycle data leaves secrets exposed long after they should have been revoked. A mature program typically uses:
- Authoritative source mapping for each identity type and business process.
- Workflow approvals tied to role, manager, and application ownership.
- Automatic deprovisioning or entitlement review on leaver and mover events.
- Escalation when approvals or source data are missing or inconsistent.
- Periodic recertification to catch drift that event-based workflows miss.
The practical goal is to make access changes automatic where possible and accountable where automation stops. That usually requires evidence trails, exception handling, and clear service-level expectations for response times. These controls tend to break down in matrix organisations with outsourced operations and no single owner for the authoritative people or application data.
Common Variations and Edge Cases
Tighter lifecycle control often increases coordination overhead, requiring organisations to balance speed against assurance. That tradeoff becomes visible in environments with contractors, federated HR systems, or heavily delegated business units, where one team cannot fully validate the other team’s data. There is no universal standard for this yet, but current guidance suggests the accountable party should be the one best positioned to correct the source record, not merely the one executing the workflow.
Edge cases are common. For example, a manager may approve access for a temporary project move while HR still shows the employee in the old role. In those cases, identity governance should treat the manager’s approval as a trigger, not a substitute for source-of-truth reconciliation. The same applies to service accounts and automation identities: a developer leaving a team does not automatically invalidate an API key unless ownership, rotation, and offboarding are tracked to the application or platform owner. NHIMG’s 52 NHI Breaches Analysis and Microsoft SAS Key Breach show how quickly weak ownership turns into exposure when lifecycle controls are incomplete. The practical test is simple: if no one can name the accountable owner for a stale entitlement within minutes, the process is already failing.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Joiner mover leaver control depends on managing access permissions over time. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Lifecycle mismanagement is a core NHI risk when ownership and revocation are unclear. |
| NIST SP 800-63 | IAL | Identity proofing and lifecycle integrity rely on trustworthy source data. |
| NIST AI RMF | AI governance principles support accountability for automated identity decisions. | |
| CSA MAESTRO | Agentic or automated workloads need explicit ownership across lifecycle events. |
Map each autonomous workload to an owner responsible for access changes and offboarding.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org