Skip to main content
Category: Identity & Access Management

Joiner-Mover-Leaver (JML)

Also known as: JML, Joiner, Mover, Leaver, Joiners, Movers, and Leavers, JML process, JML model
Simply put

Joiner-Mover-Leaver (JML) is a way of managing a person's access to systems and data across the full time they are connected to an organization. It covers three stages: joining (getting access), moving (changing access when a role changes), and leaving (removing access on departure). The goal is to make sure people have the right access when they need it and no longer have access once they should not.

Formal definition

JML is an identity lifecycle framework that governs the provisioning, modification, and de-provisioning of access rights as identities transition through three key stages: Joiner (initial onboarding and access grant), Mover (access recertification and adjustment following role, department, or status change), and Leaver (timely revocation of entitlements upon offboarding). It is a foundational component of an Identity and Access Management (IAM) program, often supported by automated provisioning and access governance controls to enforce least-privilege access, reduce standing entitlements, and limit the risk of orphaned or excessive access. As a governance and process control, JML defines how access changes are triggered and executed; its effectiveness depends on accurate authoritative source data (such as HR records), defined workflows, and consistent enforcement across in-scope systems. From a security leadership perspective, JML is typically addressed as an access governance concern rather than a purely technical task, and accountability for access decisions remains with the organization's identity, HR, and business owners rather than with any single tool or advisor.

Why it matters

The Joiner-Mover-Leaver model matters because access that is granted but never adjusted or revoked becomes one of the most persistent and exploitable weaknesses in an organization's security posture. When joiners receive excessive access at onboarding, movers accumulate entitlements from previous roles without shedding old ones, or leavers retain active credentials after departure, the result is standing access that no longer maps to any legitimate business need. These orphaned and excessive entitlements expand the attack surface, undermine least-privilege principles, and create audit findings that are difficult to remediate after the fact.

For security leaders, JML is significant precisely because it is a governance and process concern rather than a purely technical one. The controls depend on accurate authoritative source data, typically from HR systems, and on defined workflows that trigger access changes reliably. Where those triggers are weak or manual, the gap between an event in the real world (a role change or a resignation) and the corresponding access change in systems can leave dangerous windows of inappropriate access. A common expert correction here is that JML is not solved by buying a provisioning tool; effectiveness depends on process discipline and enforcement across in-scope systems.

A virtual or fractional CISO advising on JML generally focuses on defining the framework, workflows, and recertification cadence, and on clarifying ownership. It is important to state that accountability for access decisions remains with the organization's identity, HR, and business owners rather than with any single tool or advisor. A vCISO can direct and improve the JML program but does not typically assume liability for individual access grants.

Who it's relevant to

Virtual and fractional CISOs
Security leaders engaged on a part-time or shared basis often address JML as an access governance priority, helping define the lifecycle framework, recertification cadence, and workflow triggers. Their role is typically to advise and direct rather than to administer provisioning tools or make individual access decisions, with accountability remaining with the client's identity, HR, and business owners.
IAM and identity teams
Teams responsible for provisioning, modification, and de-provisioning implement and operate the JML process across in-scope systems. They depend on accurate authoritative source data and defined workflows to enforce least-privilege access and reduce standing entitlements, and they own the day-to-day execution that JML governance defines.
HR and business owners
Because HR records frequently serve as the authoritative source that triggers joiner, mover, and leaver events, HR and business managers play a direct role in JML effectiveness. Timely and accurate updates to role, department, and employment status are essential, and business owners typically retain accountability for approving and recertifying access appropriate to each role.
Compliance, audit, and risk functions
These stakeholders rely on JML controls to demonstrate that access maps to legitimate need and is revoked when no longer required. A well-defined JML process supports access recertification and least-privilege enforcement, which are commonly examined during audits, though the process supports readiness rather than guaranteeing any specific certification outcome.

Inside JML

Joiner Process
The set of provisioning activities triggered when a person enters an organization or changes into a role requiring access. It typically covers identity creation, assignment of access rights aligned to the role, and enrollment in relevant security controls. A virtual CISO generally advises on the governance and policy design for this process rather than executing the provisioning tasks directly.
Mover Process
The re-provisioning and de-provisioning activities that occur when an individual changes roles, departments, or responsibilities. A common concern here is access accumulation, where old entitlements are not removed as new ones are granted. Governance of this process often falls within the strategic scope a vCISO helps define.
Leaver Process
The de-provisioning activities that occur when a person departs the organization, including revocation of access, recovery of assets, and disabling of accounts. Timeliness is frequently a control objective, though the operational execution typically sits with IT or HR teams rather than the vCISO.
Identity Lifecycle Governance
The overarching policy, ownership, and oversight structure that ties joiner, mover, and leaver events to defined controls. This governance layer is where security leadership, including a virtual CISO, typically contributes by advising on policy, accountability assignment, and alignment with risk objectives.
Access Reviews and Attestation
Periodic verification that access rights remain appropriate to current roles, often used to detect gaps left by incomplete mover or leaver handling. These reviews support control frameworks and audit readiness rather than guaranteeing any particular certification outcome.
Cross-Functional Ownership
JML processes typically span HR, IT, and security functions, requiring coordination across teams. Effective operation depends on defined ownership and stakeholder cooperation, and the value of security leadership guidance here varies with organizational maturity.

Common questions

Answers to the questions practitioners most commonly ask about JML.

Is Joiner-Mover-Leaver just an IT or HR provisioning task rather than a security concern?
It is a common mistake to treat JML as a purely administrative provisioning workflow. While HR and IT execute much of the day-to-day activity, JML is fundamentally an access governance and identity lifecycle control that directly affects an organization's risk posture. Gaps in the leaver process in particular can leave orphaned accounts and standing access that create real exposure. A virtual CISO typically advises on the governance, policy, and risk aspects of JML rather than administering the accounts, and accountability for the process usually remains with the client organization.
Does having a JML process guarantee that access is always correct and that no unauthorized access can occur?
No. A JML process reduces the likelihood of inappropriate access but does not guarantee it. Its effectiveness depends heavily on organizational maturity, the accuracy of source-of-truth systems such as HR records, timely notification of moves and departures, and consistent execution. Manual or poorly integrated JML processes often lag reality, and the 'mover' stage in particular frequently leaves residual access from prior roles. JML supports least-privilege and access hygiene objectives; it does not by itself assure them.
What role does a virtual CISO typically play in JML compared with the operational teams?
In many engagements a virtual CISO focuses on governance-level work: defining access lifecycle policy, establishing role and entitlement standards, setting expectations for timeliness, and helping align JML with frameworks the organization is pursuing. Hands-on account creation, modification, and deprovisioning are generally out of scope and remain with IT or identity operations teams unless explicitly contracted. The vCISO advises and directs, while responsibility for execution and accountability for outcomes typically stay with the client.
Which stage of JML tends to create the most risk, and how should it be prioritized?
The mover and leaver stages are often where the greatest residual risk accumulates. Movers frequently retain access from prior roles because additions are prioritized over removals, leading to privilege creep. Leavers can result in orphaned or unrevoked accounts if departures are not communicated promptly to identity teams. Many organizations prioritize tightening the leaver process first for immediate risk reduction, then addressing mover access reviews. Prioritization may vary by an organization's risk profile and existing maturity.
How can JML be tied to compliance and audit expectations?
JML processes often support access control expectations found in frameworks and standards such as NIST CSF, ISO 27001, SOC 2, and others, which commonly call for timely provisioning, periodic access reviews, and prompt deprovisioning. A virtual CISO can help map JML controls to these expectations and support audit readiness, but supporting readiness is not the same as guaranteeing certification or a passed audit. Auditable evidence, such as timestamps and access review records, typically strengthens the case, and outcomes depend on how consistently the process is followed.
What dependencies determine whether a JML process actually works in practice?
JML effectiveness typically depends on a reliable authoritative source of identity data, timely notifications from HR and managers about hires, role changes, and departures, defined roles and entitlements, and cooperation across HR, IT, and business units. Integration between HR systems and identity tooling can reduce lag and manual error, though many organizations still rely partly on manual steps. Without stakeholder cooperation and clear ownership, even a well-designed JML process may fail to keep access aligned with current roles.

Common misconceptions

A virtual CISO who oversees JML governance also performs the account provisioning and de-provisioning tasks.
A vCISO typically advises on policy, control design, and accountability for JML processes but generally does not execute hands-on provisioning, de-provisioning, or account administration unless that operational work is explicitly contracted. Those tasks usually remain with IT or identity management teams.
Implementing a JML process guarantees compliance with frameworks such as ISO 27001, SOC 2, or HIPAA.
A well-governed JML process can support readiness for access control expectations within these frameworks, but it does not by itself assert certification or guarantee compliance. Certification and compliance depend on broader controls, evidence, and formal assessment, and a vCISO engagement supports readiness rather than guaranteeing outcomes.
JML is a purely technical, IT-owned function.
JML is a governance and business risk function as much as a technical one, typically spanning HR, IT, and security. Accountability for access decisions usually remains with the client organization and its officers, while a vCISO advises and directs the governance design.

Best practices

Assign clear cross-functional ownership across HR, IT, and security for each stage of the joiner, mover, and leaver process so that no handoff is left undefined.
Define timeliness objectives for de-provisioning during leaver events, and treat prompt access revocation as a measurable control rather than an informal expectation.
Address access accumulation in mover scenarios by requiring removal of outdated entitlements when new role-based access is granted.
Establish periodic access reviews and attestation to detect gaps left by incomplete mover or leaver handling and to support audit readiness.
Keep the vCISO scope focused on governance, policy, and oversight of JML, and explicitly document when operational provisioning tasks are or are not included in the engagement.
Recognize that JML effectiveness depends on organizational maturity, stakeholder cooperation, and defined scope, and tailor recommendations accordingly rather than assuming a uniform approach.