Movers are risky because they often keep access from their previous job while also receiving new entitlements. That combination creates privilege creep, expands the attack surface, and can violate segregation of duties. If old permissions are not removed promptly, a routine role change can leave a user with access that no longer matches business need or current responsibility.
Why Delayed Access Updates Create Business Risk
When an employee changes roles, access should change with the job, not lag behind it. The risk is not only excess permission; it is the period where old access and new access overlap, creating privilege creep and possible segregation of duties violations. That gap matters because most organisations still rely on manual reviews that are slower than the business change they are supposed to govern. NHI Management Group’s Ultimate Guide to NHIs shows how quickly unmanaged entitlements become a security problem, and the same lifecycle discipline applies to people access. The control issue is not theoretical: stale permissions can be used for inappropriate file access, approval abuse, or lateral movement if a compromised account is repurposed. The practical failure is often administrative delay, not a sophisticated attack. In practice, many security teams encounter this only after a routine transfer has already left a user with access no longer matched to their current responsibility.
How Timely Deprovisioning and Reprovisioning Should Work
Best practice is to treat role changes as an access lifecycle event, not an HR notification. The access review should happen at the point of change, with old entitlements removed first or in the same workflow that grants new ones. That order matters because it reduces the overlap window where a mover can exercise both sets of permissions.
Effective programs usually combine identity governance, manager approval, and role-based access control with periodic certification. NIST guidance on access control and the NIST Cybersecurity Framework 2.0 both support least privilege, while the OWASP Non-Human Identity Top 10 is useful for understanding how entitlement sprawl becomes operationally dangerous across identities of all types. For human users, the same principle is straightforward: access should be tied to current duty, not historical need.
- Remove access that no longer maps to the new role before or at the time new access is granted.
- Use role mining or predefined job profiles so movers inherit only the minimum required entitlements.
- Log the change as a single lifecycle event so reviewers can see both what was removed and what was added.
- Flag exceptions for privileged, financial, production, or sensitive records access for manual review.
When this is handled well, access changes are fast enough to support business continuity but strict enough to prevent privilege creep. These controls tend to break down in large organisations with many bespoke roles, because exceptions accumulate faster than the access model can be kept current.
Common Exceptions, Failure Modes, and Practical Tradeoffs
Tighter access change controls often increase operational overhead, requiring organisations to balance speed against review accuracy. That tradeoff is most visible in mergers, matrix organisations, and teams with many temporary project assignments, where a mover may legitimately need transitional access while a formal role change is still being processed.
There is no universal standard for timing, but current guidance suggests that the shorter the overlap window, the lower the risk of privilege creep. The challenge is that some environments cannot remove access instantly without breaking workflows. Finance closes, incident response, and regulated approval chains may require short-lived exceptions, but those exceptions should be time-bound and reviewed.
Another common failure mode is assuming RBAC alone solves the problem. RBAC helps only if job roles are accurate, maintained, and mapped cleanly to entitlements. Where roles are overloaded or outdated, movers inherit excess access even when the policy appears sound on paper. Security teams should therefore validate not just the ticketing workflow but the underlying role catalogue and entitlement hygiene. In practice, access drift is usually discovered during an audit, after a complaint, or after a misuse event exposes how long stale permissions were left in place.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Role changes require prompt least-privilege access updates. |
| NIST SP 800-63 | Identity proofing and lifecycle management support accurate access reassignment. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | Entitlement sprawl and stale access mirror NHI lifecycle mismanagement. |
Tie mover workflows to verified identity records and timely account lifecycle updates.
Related resources from NHI Mgmt Group
- Why do traditional VPN-based access models increase risk for employees who only need a few web apps?
- Why do AI agents and copilots create more risk when they inherit broad enterprise permissions?
- Why does unsecured document retrieval create risk in AI assistants that serve different user roles?
- Why do shared vaults create risk when organisations rely on standing credentials for privileged access?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org