Joiners, Movers, Leavers: Where Access Actually Goes Wrong
When people think about identity security, they usually picture the extremes: a new hire getting their first login, or a departing employee being locked out. Those moments matter, but in my experience they aren’t where most access risk builds up. The real problem usually sits in the middle.
Joiners: start with the right baseline
A new employee should arrive with the access their role requires on day one and nothing more. The cleanest way to do that is birthright access tied to role and department, driven by the HR system as the source of truth. When provisioning depends on manual tickets and copy-the-access-of-a-coworker requests, new hires inherit permissions nobody can explain six months later.
Movers: the risk nobody watches
Movers are the most overlooked part of the lifecycle. When someone changes teams, they usually get the new access they need, but their old access often stays. Repeat that over a few role changes and you get privilege creep: a long-tenured employee who can reach systems from three previous jobs.
A move should be treated as a governance event, not just a provisioning request. That means:
- Granting the new role’s access
- Flagging or removing access tied to the old role
- Triggering a manager review of anything left over
Leavers: speed and completeness
Deprovisioning has two requirements: it has to be fast, and it has to be complete. Disabling a primary directory account isn’t enough if the person still has active local accounts in applications, standing privileged access, or tokens that outlive their login. Orphaned accounts are one of the most common findings in access audits because they’re easy to miss and quiet once they exist.
Access reviews are the backstop, not the strategy
Periodic certifications matter, but they shouldn’t be the primary control. If reviewers are approving hundreds of entitlements they don’t understand, the review becomes a rubber stamp. Strong lifecycle automation means reviews catch the exceptions instead of cleaning up the whole mess.
The takeaway
Good identity governance isn’t one big control. It’s a system where access is granted with a reason, adjusted when circumstances change, and removed when that reason no longer exists. Getting the movers right is usually what separates a governance program that works from one that only looks good during audits.
Leave a Reply