Joiner-Mover-Leaver (JML)
Joiner-Mover-Leaver (JML) is a way of managing a person's access to systems and data across the full time they are connected to an organization. It covers three stages: joining (getting access), moving (changing access when a role changes), and leaving (removing access on departure). The goal is to make sure people have the right access when they need it and no longer have access once they should not.
JML is an identity lifecycle framework that governs the provisioning, modification, and de-provisioning of access rights as identities transition through three key stages: Joiner (initial onboarding and access grant), Mover (access recertification and adjustment following role, department, or status change), and Leaver (timely revocation of entitlements upon offboarding). It is a foundational component of an Identity and Access Management (IAM) program, often supported by automated provisioning and access governance controls to enforce least-privilege access, reduce standing entitlements, and limit the risk of orphaned or excessive access. As a governance and process control, JML defines how access changes are triggered and executed; its effectiveness depends on accurate authoritative source data (such as HR records), defined workflows, and consistent enforcement across in-scope systems. From a security leadership perspective, JML is typically addressed as an access governance concern rather than a purely technical task, and accountability for access decisions remains with the organization's identity, HR, and business owners rather than with any single tool or advisor.
Why it matters
The Joiner-Mover-Leaver model matters because access that is granted but never adjusted or revoked becomes one of the most persistent and exploitable weaknesses in an organization's security posture. When joiners receive excessive access at onboarding, movers accumulate entitlements from previous roles without shedding old ones, or leavers retain active credentials after departure, the result is standing access that no longer maps to any legitimate business need. These orphaned and excessive entitlements expand the attack surface, undermine least-privilege principles, and create audit findings that are difficult to remediate after the fact.
For security leaders, JML is significant precisely because it is a governance and process concern rather than a purely technical one. The controls depend on accurate authoritative source data, typically from HR systems, and on defined workflows that trigger access changes reliably. Where those triggers are weak or manual, the gap between an event in the real world (a role change or a resignation) and the corresponding access change in systems can leave dangerous windows of inappropriate access. A common expert correction here is that JML is not solved by buying a provisioning tool; effectiveness depends on process discipline and enforcement across in-scope systems.
A virtual or fractional CISO advising on JML generally focuses on defining the framework, workflows, and recertification cadence, and on clarifying ownership. It is important to state that accountability for access decisions remains with the organization's identity, HR, and business owners rather than with any single tool or advisor. A vCISO can direct and improve the JML program but does not typically assume liability for individual access grants.
Who it's relevant to
Inside JML
Common questions
Answers to the questions practitioners most commonly ask about JML.