Manual JML workflows are error-prone because identity changes happen faster than humans can consistently update every system. When access is not synchronized with onboarding, transfers, and exits, users keep permissions they no longer need, and old accounts may stay active after departure. That widens the attack surface, complicates audits, and creates easy paths for unauthorized access if credentials are later abused.
Why manual JML workflows create privilege creep
Joiner, mover, and leaver events are the moments when access should be smallest, cleanest, and most current. Manual handling slows that correction loop, so permissions added for a past role or temporary project often remain after the need has passed. That is how excess access accumulates: not through a single failure, but through repeated missed revocations, missed downgrades, and inconsistent approvals.
In practice, movers are the most common source of drift because role changes rarely map neatly to one system. A manager may approve a new entitlement, but the old entitlement is not removed everywhere else. Over time, the account ends up with a union of past access instead of the current minimum required to do the job.
This is especially visible in environments where access decisions are spread across HR, IAM, application owners, and local admins. Each team may update its own system correctly, yet no one sees the full entitlement picture. The result is a permission set that looks justified in isolation but becomes over-privileged in aggregate. The lifecycle issue is why access governance and recertification matter as much as initial provisioning, as reflected in NHIMG’s NHI Lifecycle Management Guide and the broader lifecycle section in Ultimate Guide to NHIs.
Why manual leaver handling leaves dormant accounts behind
Leaver workflows are time-sensitive because the security value of an account changes the moment employment ends or a relationship closes. Manual offboarding depends on people noticing the exit, finding every place the account exists, and revoking access consistently. That is difficult to do fast enough across directories, SaaS apps, VPNs, shared tools, and legacy systems, so stale accounts linger and sometimes retain valid credentials long after they should have been removed.
Dormant accounts are risky because they preserve a path back into the environment even when no one is actively using them. If passwords, tokens, keys, or sessions are still valid, an attacker who finds them later can abuse access that appears forgotten rather than actively monitored. The issue is not only whether the account is logged into today, but whether it can still authenticate tomorrow.
Manual processes also create audit blind spots. If revocation is handled by email, spreadsheets, or ticket handoffs, it becomes hard to prove that access was actually removed, which systems were updated, and when the final shutdown occurred. That is why lifecycle visibility and offboarding controls are central to the problem, not just administrative conveniences. NHIMG’s Top 10 NHI Issues is useful here because it highlights inactive accounts, excessive permissions, and visibility gaps as linked failure modes.
Risk and Threat Considerations
Privilege creep and dormant accounts create a larger attack surface than organisations usually intend. Excess access increases the chance that one compromised account can reach more systems than necessary, while forgotten accounts give attackers a low-friction path to persist or re-enter after a user has moved on. The strongest internal warning signs are stale entitlements, delayed deprovisioning, and account inventories that no longer match reality.
Failure mechanism: Manual JML steps fail when identity state changes faster than updates across directories, applications, and privileged systems, leaving unnecessary permissions in place or leaving terminated accounts active with valid authentication material.
Impact: The organisation inherits unnecessary trust relationships, higher audit burden, and a materially easier route to unauthorized access if old credentials, tokens, or sessions are later abused. For a concrete example of offboarding failure turning into exposure, see Coupang Signing Key Breach.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Lifecycle and Offboarding | Manual JML directly affects access revocation, rotation, and offboarding for identity-bearing material. |
| NHI-03 — Overprivileged Non-Human Identities | Privilege creep is the core overprivilege failure mode this question describes. | |
| Recommendation — Automate offboarding and entitlement removal to prevent stale access and dormant identity material. Review and reduce permissions so accounts retain only current, necessary access. | ||
| NIST CSF 2.0 | PR.AC — Access Control | JML workflows are the operational path for enforcing least privilege and timely revocation. |
| Recommendation — Apply access control processes that remove unneeded access as roles and employment status change. | ||
| CIS Controls v8 | 6 — Access Control Management | Prescriptive safeguard for provisioning, review, and removal of access as people change roles or leave. |
| Recommendation — Centralise access management and remove stale accounts and excess privileges promptly. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Dormant accounts with valid credentials are attractive persistence and re-entry paths for attackers. |
| Recommendation — Detect and disable unused valid accounts before they become an attacker foothold. | ||
Practitioner Guidance
What to verify: Treat joiner, mover, and leaver controls as an entitlement integrity problem, not just an HR handoff. Verify that every role change triggers both positive access grants and explicit access removals, and that the final state is checked against current job function rather than against the last approved ticket.
What to prioritise: Focus first on systems where access can persist outside the main directory, especially admin tools, SaaS platforms, shared environments, and anything that stores long-lived secrets. Those are the places where a manual miss is most likely to become a durable security gap.
Practitioner takeaway: The real test of JML control is not whether access was once approved, but whether the current identity state and the current privilege state still match after every move or exit.
Related resources from NHI Mgmt Group
- How should security teams implement joiner mover leaver access workflows without creating delays or privilege creep?
- What breaks when joiner-mover-leaver workflows are mostly manual?
- Why do dormant accounts and privilege drift increase governance risk?
- How do organisations reduce manual provisioning errors across joiner, mover, and leaver workflows?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org