PAFTAK
← All insights

The joiner–mover–leaver problem nobody automates

Every identity program automates the joiner path early, because it's visible: a new hire shows up on day one with no access, and that's an obvious, fundable problem to fix. What gets left as a spreadsheet and a Slack message is the mover — someone changing teams — and the leaver.

Movers are the harder case, because the correct outcome isn't 'add access' or 'remove access,' it's both, and the removal is the part that keeps getting skipped. Someone moves from finance to engineering and picks up new entitlements immediately, because the new team needs them productive. Nobody circles back to pull the finance-system access, because no one is blocked by them still having it. Eighteen months later that person is an access-review finding titled 'unexplained entitlement,' and nobody remembers why they have it either.

The leaver path fails differently: it's usually automated for the primary directory and forgotten everywhere else — the SaaS tool procured directly by a team, the shared credential in a vault, the standing SSH key. A joiner-mover-leaver program is only as strong as its least-integrated system.

If we had to pick one lever: instrument the mover path first. It's the one that silently produces the access sprawl a real audit eventually finds.

Related practice area: Identity & Access Management