Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do manual joiner, mover, and leaver workflows…
Governance, Ownership & Risk

Why do manual joiner, mover, and leaver workflows increase the risk of privilege creep and dormant accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Governance, Ownership & Risk

Manual JML workflows are error-prone because identity changes happen faster than humans can consistently update every system. When access is not synchronized with onboarding, transfers, and exits, users keep permissions they no longer need, and old accounts may stay active after departure. That widens the attack surface, complicates audits, and creates easy paths for unauthorized access if credentials are later abused.

Why manual JML workflows create privilege creep

Joiner, mover, and leaver events are the moments when access should be smallest, cleanest, and most current. Manual handling slows that correction loop, so permissions added for a past role or temporary project often remain after the need has passed. That is how excess access accumulates: not through a single failure, but through repeated missed revocations, missed downgrades, and inconsistent approvals.

In practice, movers are the most common source of drift because role changes rarely map neatly to one system. A manager may approve a new entitlement, but the old entitlement is not removed everywhere else. Over time, the account ends up with a union of past access instead of the current minimum required to do the job.

This is especially visible in environments where access decisions are spread across HR, IAM, application owners, and local admins. Each team may update its own system correctly, yet no one sees the full entitlement picture. The result is a permission set that looks justified in isolation but becomes over-privileged in aggregate. The lifecycle issue is why access governance and recertification matter as much as initial provisioning, as reflected in NHIMG’s NHI Lifecycle Management Guide and the broader lifecycle section in Ultimate Guide to NHIs.

Why manual leaver handling leaves dormant accounts behind

Leaver workflows are time-sensitive because the security value of an account changes the moment employment ends or a relationship closes. Manual offboarding depends on people noticing the exit, finding every place the account exists, and revoking access consistently. That is difficult to do fast enough across directories, SaaS apps, VPNs, shared tools, and legacy systems, so stale accounts linger and sometimes retain valid credentials long after they should have been removed.

Dormant accounts are risky because they preserve a path back into the environment even when no one is actively using them. If passwords, tokens, keys, or sessions are still valid, an attacker who finds them later can abuse access that appears forgotten rather than actively monitored. The issue is not only whether the account is logged into today, but whether it can still authenticate tomorrow.

Manual processes also create audit blind spots. If revocation is handled by email, spreadsheets, or ticket handoffs, it becomes hard to prove that access was actually removed, which systems were updated, and when the final shutdown occurred. That is why lifecycle visibility and offboarding controls are central to the problem, not just administrative conveniences. NHIMG’s Top 10 NHI Issues is useful here because it highlights inactive accounts, excessive permissions, and visibility gaps as linked failure modes.

Risk and Threat Considerations

Privilege creep and dormant accounts create a larger attack surface than organisations usually intend. Excess access increases the chance that one compromised account can reach more systems than necessary, while forgotten accounts give attackers a low-friction path to persist or re-enter after a user has moved on. The strongest internal warning signs are stale entitlements, delayed deprovisioning, and account inventories that no longer match reality.

Failure mechanism: Manual JML steps fail when identity state changes faster than updates across directories, applications, and privileged systems, leaving unnecessary permissions in place or leaving terminated accounts active with valid authentication material.

Impact: The organisation inherits unnecessary trust relationships, higher audit burden, and a materially easier route to unauthorized access if old credentials, tokens, or sessions are later abused. For a concrete example of offboarding failure turning into exposure, see Coupang Signing Key Breach.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Lifecycle and OffboardingManual JML directly affects access revocation, rotation, and offboarding for identity-bearing material.
NHI-03 — Overprivileged Non-Human IdentitiesPrivilege creep is the core overprivilege failure mode this question describes.
Recommendation — Automate offboarding and entitlement removal to prevent stale access and dormant identity material. Review and reduce permissions so accounts retain only current, necessary access.
NIST CSF 2.0PR.AC — Access ControlJML workflows are the operational path for enforcing least privilege and timely revocation.
Recommendation — Apply access control processes that remove unneeded access as roles and employment status change.
CIS Controls v86 — Access Control ManagementPrescriptive safeguard for provisioning, review, and removal of access as people change roles or leave.
Recommendation — Centralise access management and remove stale accounts and excess privileges promptly.
MITRE ATT&CKT1078 — Valid AccountsDormant accounts with valid credentials are attractive persistence and re-entry paths for attackers.
Recommendation — Detect and disable unused valid accounts before they become an attacker foothold.

Practitioner Guidance

What to verify: Treat joiner, mover, and leaver controls as an entitlement integrity problem, not just an HR handoff. Verify that every role change triggers both positive access grants and explicit access removals, and that the final state is checked against current job function rather than against the last approved ticket.

What to prioritise: Focus first on systems where access can persist outside the main directory, especially admin tools, SaaS platforms, shared environments, and anything that stores long-lived secrets. Those are the places where a manual miss is most likely to become a durable security gap.

Practitioner takeaway: The real test of JML control is not whether access was once approved, but whether the current identity state and the current privilege state still match after every move or exit.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org