Joiner Mover Leaver controls are the lifecycle checks that adjust access when people enter, change roles, or leave an organisation. They prevent excessive access, privilege creep, and orphaned accounts by triggering approvals, revocations, and evidence capture whenever employment or assignment status changes.
Expanded Definition
Joiner Mover Leaver controls are a lifecycle governance pattern for identity and access management that ensures access is created, adjusted, and removed when a person joins, changes role, or exits. In NHI-adjacent environments, the same discipline is increasingly applied to service accounts, shared automation identities, and delegated operator access because missed transitions create persistent risk. The term is broader than basic provisioning: it includes approvals, entitlement recalculation, evidence capture, and deprovisioning triggers tied to authoritative sources such as HR, contractor systems, or assignment records. Guidance varies across vendors, but the core objective remains consistent: make access state follow business state, not manual memory. This aligns closely with lifecycle governance concepts in the NIST Cybersecurity Framework 2.0 and the operational framing in Ultimate Guide to NHIs — Standards. The most common misapplication is treating leaver offboarding as a one-time checklist, which occurs when access changes are not continuously reconciled against authoritative lifecycle events.
Examples and Use Cases
Implementing Joiner Mover Leaver controls rigorously often introduces workflow and data-quality overhead, requiring organisations to weigh automation speed against governance accuracy.
- A new employee is onboarded with role-based access, and the identity system grants only the minimum set of applications approved by the hiring manager and app owner.
- An engineer transfers to a different team, triggering removal of previous environment access, updated group membership, and a fresh approval for elevated tools.
- A contractor reaches end date, and the access management platform revokes badge-linked systems, SaaS access, VPN privileges, and any related secrets or tokens.
- A privileged service account tied to a project is revalidated when ownership changes, ensuring the account does not remain with outdated permissions after the team reorganises.
- A merger or department restructure causes bulk entitlement review, where access recertification confirms whether inherited rights still match the person’s new function.
These workflows are most effective when tied to authoritative event sources and audited against the control expectations described in Ultimate Guide to NHIs — Standards and lifecycle principles reflected in NIST Cybersecurity Framework 2.0.
Why It Matters in NHI Security
Joiner Mover Leaver controls matter in NHI security because excessive standing access is one of the fastest ways for automation identities to become enduring attack paths. NHIMG reports that only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotation, which shows how often lifecycle discipline breaks down when credentials are non-human. That gap matters because a forgotten service account, stale token, or orphaned integration can survive long after the business event that justified it. The result is privilege creep, dormant access, failed audits, and expanded blast radius when an identity is compromised. For governance teams, the real issue is not only whether access was granted correctly, but whether every lifecycle change reliably forces removal, downgrade, or reapproval. In NHI programs, this control is a core part of preventing hidden persistence across human and machine identities alike. Organisations typically encounter the consequences only after a departure, reorganisation, or breach investigation reveals access that should have disappeared, at which point Joiner Mover Leaver controls become operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Covers lifecycle governance and preventing orphaned or excessive NHI access. |
| NIST CSF 2.0 | PR.AC-1 | Access is managed through approved processes and lifecycle-based authorization. |
| NIST Zero Trust (SP 800-207) | AC-3 | Zero Trust requires dynamic access decisions that reflect current identity state. |
| NIST SP 800-63 | IAL2 | Identity lifecycle assurance depends on reliable proofing and change handling. |
| OWASP Agentic AI Top 10 | AGENT-06 | Agent and tool access must be revoked when operational context changes. |
Tie identity changes to automated review, revocation, and evidence capture at every lifecycle event.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org