Onboarding and offboarding are the identity lifecycle processes for granting and removing access as people join, change roles, or leave an organisation. They must be tightly governed because delays or manual steps can create overprovisioning, orphaned access, and operational friction. Effective lifecycle control reduces both risk and administrative burden.
Expanded Definition
Onboarding and offboarding are not just HR handoffs. In NHI and IAM operations, they are the control points that create, modify, and retire access tied to a person, workload, or agent lifecycle. The term covers approvals, entitlement assignment, credential issuance, role changes, revocation, and evidence that the change actually took effect. For human identities, this often aligns with joiner-mover-leaver processes; for NHIs, it extends to service accounts, API keys, certificates, tokens, and automation bindings that may outlive the original business need.
Definitions vary across vendors when onboarding includes only initial provisioning or also downstream secret distribution, vault registration, and policy binding. NHI Management Group treats the broader lifecycle as the security-relevant scope, because a successful access grant is incomplete if key rotation, secret storage, and revocation tracking are not included. Guidance in the NHI Lifecycle Management Guide and the broader Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs reflects that wider operational reality, while FATF Recommendations reinforces the same lifecycle discipline in regulated identity workflows. The most common misapplication is treating offboarding as an HR notification task, which occurs when access owners assume deprovisioning happens automatically after employment status changes.
Examples and Use Cases
Implementing onboarding and offboarding rigorously often introduces process overhead, requiring organisations to balance faster delivery against tighter control verification.
- A developer joins a platform team and receives a role, SSO access, and a scoped API token on day one. If the token is also written to chat or a ticket, the onboarding process has created exposure before the first deployment.
- An engineer moves from application support to infrastructure. The mover event should remove prior entitlements and add only the new ones, rather than accumulating access across both roles.
- A contractor completes a project and leaves, but their CI/CD credential remains active in a vault. The Top 10 NHI Issues highlights this as a common control failure because lifecycle drift is easy to miss once teams separate ownership from execution.
- A service account is created for an integration, then registered in a secrets manager, tagged with an owner, and scheduled for rotation. This is a stronger onboarding pattern than issuing a secret directly from a script or code repository.
- A production incident reveals that a former employee token still works. The offboarding step should include explicit verification of revocation, not just a request to disable access, a failure pattern also seen in public breach analysis such as the Coupang Signing Key Breach.
Why It Matters in NHI Security
Onboarding and offboarding are where identity governance becomes measurable. If access is granted without ownership, expiry, or review, NHIs can be overused, duplicated, and left exposed long after the need has ended. NHI Management Group’s research shows that 91% of former employee tokens remain active after offboarding, and that 73% of vaults are misconfigured, which means the lifecycle process is often the only reliable place to stop privilege from becoming permanent. The same research also reports that only 20% of organisations have formal processes for offboarding and revoking API keys, underscoring how often lifecycle control is assumed rather than enforced.
Good lifecycle governance reduces orphaned access, narrows blast radius, and creates evidence for audits and incident response. It also supports Zero Trust by ensuring that identity state, not just authentication, determines continued access. Organisations typically encounter the consequences only after a breach, audit finding, or failed decommissioning event, at which point onboarding and offboarding become operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Lifecycle governance governs provisioning and deprovisioning of NHIs and their credentials. |
| NIST CSF 2.0 | PR.AC-1 | Access permissions should be issued, changed, and removed based on approved identity state. |
| NIST Zero Trust (SP 800-207) | PL-1 | Zero Trust requires continuous identity state validation across the access lifecycle. |
| NIST SP 800-63 | IAL2 | Identity proofing and lifecycle changes must preserve assurance during issuance and revocation. |
| NIST AI RMF | AI risk management includes lifecycle controls for systems and identities that operate them. |
Govern access changes as part of AI system lifecycle risk controls and documented accountability.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org