Every joiner-mover-leaver gap is really an ownership gap wearing an HR label.
A new hire's access usually gets set up by whoever is available, copying whatever template is closest to their role. A role change adds new access without necessarily removing the old - so people accumulate permissions from every job they've held, not just the one they're doing now. A departure depends on HR remembering to tell IT, which depends on a manager remembering to tell HR, a chain that reliably fails during a fast or contentious exit.
Treating this as an HR checklist misses the actual decision: who triggers the process, who confirms it's genuinely complete, and how access accumulation gets caught before someone tests it - deliberately or otherwise.
It connects directly to two other decisions already on this site: identity governance, which owns the exception rules access has to follow, and key-person risk, which is exactly what's exposed when a departure reveals how much only one person could actually do.