Skip to content

Decision guide · Joiner-mover-leaver governance

Offboarding is where identity governance gets tested for real.

Granting access on day one is easy to remember. Removing it completely when someone changes roles or leaves is where most organizations quietly lose track.

Every joiner-mover-leaver gap is really an ownership gap wearing an HR label.

A new hire's access usually gets set up by whoever is available, copying whatever template is closest to their role. A role change adds new access without necessarily removing the old - so people accumulate permissions from every job they've held, not just the one they're doing now. A departure depends on HR remembering to tell IT, which depends on a manager remembering to tell HR, a chain that reliably fails during a fast or contentious exit.

Treating this as an HR checklist misses the actual decision: who triggers the process, who confirms it's genuinely complete, and how access accumulation gets caught before someone tests it - deliberately or otherwise.

It connects directly to two other decisions already on this site: identity governance, which owns the exception rules access has to follow, and key-person risk, which is exactly what's exposed when a departure reveals how much only one person could actually do.

Boundary

This is ownership and process-design advisory. The actual provisioning and de-provisioning of accounts is day-to-day administration, separately scoped from this decision.

Lifecycle stages

Four moments, each with its own failure pattern.

Joiner

Grant exactly what the role needs

A template speeds things up; nobody should assume it stays accurate forever.

Mover

Remove old access when new access is granted

A role change without a matching removal is exactly where accumulation starts.

Leaver

Confirm every access point is closed

Shared accounts, vendor portals, and forwarding rules are the ones that get missed.

Audit

Periodically check access against the org chart

The only way accumulation gets caught before the wrong person tests it.

Decision lenses

Six questions before the next hire, move, or exit.

  • Trigger ownershipWho is responsible for telling IT the moment a change happens - reliably, not by memory?
  • Completion confirmationWho confirms the process actually finished, rather than assuming it did?
  • Access accumulationDoes a role change remove old access, or only add new access on top?
  • Shared & vendor accountsAre portal logins and shared mailboxes covered, or only the obvious ones?
  • High-risk departuresIs there a faster path for a contentious or immediate exit?
  • Periodic reconciliationHow often is total access compared against who's actually still employed, in what role?

Working process

Name the trigger and the confirmation, not just the checklist.

  1. Map every system a person can touch

    Not just email and file storage - vendor portals, shared logins, and forwarding rules too.

  2. Name who triggers and who confirms

    Two distinct roles: one starts the process, another verifies it actually finished.

  3. Set a faster path for high-risk exits

    A contentious departure shouldn't wait for the standard weekly cycle.

  4. Schedule a periodic reconciliation

    Compare total access against the current org chart on a real cadence, not only when something goes wrong.

A single departure often reveals a key-person gap at the same time

Orphaned Teams sites and shared drives are a common leftover this decision should catch

Hypothetical pattern

A departed contractor's access, found eight months later

A contractor's engagement ends. Email is disabled the same day - that part goes smoothly. A shared file-sync login and two vendor portal accounts are never revisited, because offboarding only ever covered the obvious systems. They surface eight months later during an unrelated review. The useful decision isn't a longer checklist; it's one owned process that's confirmed complete, not assumed complete.

See how exception and access ownership gets decided

Next step

Bring the offboarding process nobody has actually tested.

A focused brief can turn an assumed checklist into a named trigger, a confirmed completion, and a reconciliation cadence.