Joiner issues are loud. A blocked new hire creates an immediate escalation, so the business feels the pain at once. Leaver and mover failures are quieter because access can remain valid long after a person leaves or changes roles. That silence is what makes them more dangerous over time, even when they create less day-to-day pressure on the help desk.
Why Joiner Fixes Get Prioritised First
Joiner problems are operationally visible: a new employee cannot work, managers escalate, and service desks feel the disruption immediately. That makes joiner handling easy to measure and easy to justify. Leaver and mover problems are harder to see because access can remain technically valid while the business impact stays hidden. NHIMG research shows only 20% of organisations have formal processes for offboarding and revoking API keys, which is a useful reminder that lifecycle control often lags behind onboarding discipline. For identity programs, that gap is not a minor maturity issue. It is a governance blind spot.
When identity teams focus mainly on first-day access, they optimise for the loudest failure mode rather than the riskiest one. Joiner speed matters, but lifecycle risk is broader: stale access, retained permissions, and role drift accumulate quietly until they are exploited. NIST Cybersecurity Framework 2.0 frames this as an ongoing identity governance concern, not a one-time provisioning task, and the same logic applies whether the identity is human or non-human. In practice, many security teams discover leaver and mover weakness only after a review, incident, or audit, rather than through intentional control design.
How Lifecycle Gaps Build Hidden Risk
Joiner workflows are usually built around a clear trigger: a hire date, a ticket, or an HR event. Leaver and mover workflows depend on less reliable signals, such as termination notices, manager updates, or role changes that are not always propagated across systems. That is why access often outlives the business need for it. The identity still exists, the permissions still work, and no one notices until a review or breach exposes the mismatch.
The practical problem is not just removal. Movers are often more complex than leavers because their old access should be reduced while their new access is added. If that update is not automated, teams tend to leave the old privileges in place to avoid breaking work. Over time, that creates privilege accumulation, orphaned access paths, and unclear ownership. For non-human identities, this is even more acute because service accounts and API keys do not self-report when their purpose changes. NHIMG’s Ultimate Guide to NHIs and 52 NHI Breaches Analysis both reflect the same pattern: weak lifecycle control creates exposure that remains invisible until something fails.
- Joiners are handled as a service desk event; leavers and movers require continuous governance.
- HR, IAM, application owners, and managers often maintain different sources of truth.
- Manual deprovisioning is slow, inconsistent, and easy to defer.
- Access reviews catch drift late, after the risk has already accumulated.
This approach breaks down most often in large, decentralised environments where role changes happen frequently and identity data is fragmented across many systems.
Why Mature Programs Shift From Onboarding to Full Lifecycle Control
Tighter access controls often increase process overhead, requiring organisations to balance fast onboarding against accurate offboarding and entitlement correction. The mature answer is to treat joiner, mover, and leaver events as one lifecycle control loop rather than separate workflows. That means automating triggers from HR or source systems, enforcing timely removal of obsolete access, and validating that role changes also remove inherited rights.
Good programs also distinguish between entitlement assignment and entitlement expiry. A joiner can be provisioned quickly with a baseline role, while higher-risk access is granted only when needed and removed when the need ends. This is where policy, ownership, and review cadence matter. NIST guidance encourages continuous monitoring of identity-related risk, and in practice that means tracking who should still have access, not just who was provisioned successfully. For identity teams, the question is no longer whether the new hire got in on day one; it is whether yesterday’s access is still valid today. NIST Cybersecurity Framework 2.0 is useful here because it reinforces ongoing governance and response, not just initial access setup.
Current guidance suggests organisations should prioritise leaver and mover controls wherever privileged access, regulated data, or non-human identities are involved. The reason is simple: these are the identities most likely to retain access after business need has changed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity lifecycle control depends on timely access provisioning and removal. |
| NIST AI RMF | Lifecycle accountability is part of governance for any identity-driven system. |
Link joiner, mover, and leaver workflows to PR.AC-1 so access changes are executed and validated consistently.
Related resources from NHI Mgmt Group
- How should security teams implement joiner mover leaver access workflows without creating delays or privilege creep?
- What do security teams get wrong when they treat privileged account management as one control instead of separate account, user, and identity problems?
- What do teams get wrong about joiner, mover, and leaver automation?
- What breaks when identity detection does not see joiner, mover, and leaver state?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org