Joiners, movers and leavers: getting IT onboarding and offboarding right
Most IT onboarding gets attention because a new starter needs to be productive on day one. Offboarding gets far less attention — and it's usually the more dangerous half of the process.
The joiner-mover-leaver model ties access decisions to real HR events: someone starts, someone changes role, someone leaves. Done well, it turns provisioning and deprovisioning into a consistent, repeatable workflow rather than a set of disconnected manual tasks handled differently every time.
Joiners: productive on day one, not over-provisioned
Good onboarding starts from a defined role, not a blank slate copied from whoever sits nearby. A new starter gets exactly the access their role requires from day one — enough to be productive immediately, without the habit of "just give them what the last person had" quietly expanding access over time.
Movers: the step everyone forgets
When someone changes role, adding the new access is the easy part. Removing the old access is the part that gets skipped — and skipping it repeatedly across a growing team is exactly how privilege creep builds up: people accumulating access to systems they haven't touched in years, simply because nobody ever took it away.
Leavers: where the real risk sits
Delayed offboarding is one of the most common, and most avoidable, causes of credential-based security incidents. An account that stays active after someone leaves — whether the departure was routine or not — is a door nobody's watching. The standard is straightforward: access disabled the moment a departure is confirmed, company devices and credentials recovered, and revocation confirmed and documented, not assumed.
Why manual processes break down
Spreadsheets and email threads work while a team is small. As headcount and the number of systems grow, manual JML becomes the source of exactly the orphaned accounts and inconsistent access it's meant to prevent — not because anyone's careless, but because tracking dozens of systems by memory doesn't scale.
What a properly run process looks like
Standard access bundles tied to role, not to precedent. Access changes for movers handled as a single event — grant and revoke together, not grant now and revoke "eventually." And leaver deprovisioning treated as immediate and non-negotiable, with a documented record of exactly what was removed and when, so an audit or an incident review has something concrete to point to.