Because they are moments when access exists in motion, not yet fully normalised or removed. Privileges can be granted faster than they are reviewed, and revoked slower than attackers or internal mistakes can exploit. Identity teams should treat these transitions as controlled risk states, not routine administration.
Why onboarding and offboarding are not ordinary admin tasks
Onboarding and offboarding are the two points in the identity lifecycle where risk changes fastest. During onboarding, access is being created before the full picture of role, need, and segregation is stable. During offboarding, access should disappear quickly, but delays in revocation, inventory, or ownership leave a short window where old access still works.
That is why these transitions deserve tighter controls than steady-state access. The issue is not just volume, it is timing: joiner and leaver events are exactly where privilege can outpace review, and where stale access can persist after the business thinks it is gone.
What makes the risk disproportionate
The risk is disproportionate because these moments combine change, urgency, and incomplete information. Onboarding often starts from a job title, manager, or ticket, not from a fully validated access model, so people are granted the minimum they need late, or too much too early. Offboarding works in reverse: access may be partially revoked, but the long tail of entitlements, tokens, sessions, and shared credentials can remain live unless every dependency is found and closed.
These are also high-trust moments. Teams assume the request is legitimate, the role is correct, and downstream systems will catch up. In practice, that assumption fails more often than in steady-state operation because the process itself is moving faster than normal governance.
How identity teams should treat the lifecycle boundary
Onboarding and offboarding should be managed as controlled risk states with explicit ownership, timing, and evidence. The most useful lens is whether access has been fully normalised or fully removed. If not, the identity is still in a transitional condition and needs active follow-up, not passive queue handling.
Practitioners should also separate access creation from access validation. A request can be operationally complete and still be identity-risk incomplete if reviews, approvals, recertification, or deprovisioning checks are deferred. The controls that matter most are the ones that reduce exposure during the gap between business intent and actual system state.
For a deeper treatment of the lifecycle mechanics, see the NHI Lifecycle Management Guide and the Joiner-Mover-Leaver (JML) Guide, which both frame provisioning and deprovisioning as governance events rather than simple admin actions.
Risk and Threat Considerations
These lifecycle transitions create concentrated exposure because they are the easiest place for excess privilege, orphaned access, and delayed revocation to slip through. Attackers and careless insiders both benefit from the same weakness: access that is valid in one system but no longer justified by the person’s current role or employment state.
Failure mechanism: Provisioning can race ahead of validation, leaving excessive access in place, while offboarding can miss dormant accounts, long-lived secrets, active sessions, or delegated access that was never explicitly removed.
Impact: The result can be unauthorized access, privilege abuse, lateral movement, data exposure, or continued system access after the business believes the identity is gone. In severe cases, a single missed revocation becomes a persistent foothold rather than a temporary control gap.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Directly covers access that remains after deprovisioning should have occurred. |
| NHI-07 — Long-Lived Secrets | Transitional identities are risky when secrets outlive the onboarding or offboarding event. | |
| NHI-05 — Overprivileged NHI | Onboarding often grants too much access before steady-state review catches up. | |
| Recommendation — Remove credentials, sessions, and entitlements immediately when an identity leaves. Rotate or expire secrets so lifecycle changes cannot leave durable access behind. Enforce least privilege at provisioning and tighten excess access during review. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account creation, review, and deprovisioning are core account-management controls. |
| Recommendation — Centralize account lifecycle handling and revoke access on termination. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Lifecycle risk often persists through unmanaged credentials, tokens, and secrets. |
| Recommendation — Track, rotate, and revoke authenticators when lifecycle state changes. | ||
Practitioner Guidance
What to prioritise: Focus first on the access paths that can still do damage if the transition is incomplete, especially privileged roles, tokens, keys, federated access, and shared accounts. If the identity can reach production or sensitive data, treat the transition as incomplete until those paths are confirmed closed.
What to verify: Confirm that the authoritative source of truth, the directory or IAM workflow, and the target systems all reflect the same state. For onboarding, verify that the granted access matches the current role and manager approval; for offboarding, verify that revocation includes sessions, secrets, and any non-obvious downstream entitlements.
Common mistake: Teams often measure success by whether the ticket was processed, not whether effective access changed. The safer question is whether the person or process can still authenticate, authorize, or act in any system that matters after the transition is supposed to be finished.
Practitioner takeaway: The real control objective is not faster onboarding or cleaner offboarding in isolation, it is shrinking the time when access and business state are out of sync.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org