What Is JML (Joiner-Mover-Leaver)?

Also called: Joiners, movers and leavers

Related problems: New hires waiting days for laptops, accounts and app access; People keeping old access after changing jobs; Former employees still able to log in to SaaS apps; Help desk buried in manual account requests

Joiner-mover-leaver (JML) is the identity lifecycle process that handles people’s access as they join an organization, move between roles and leave it. For each event, it creates, changes or removes accounts, group memberships, application access and often devices, ideally driven by the HR system as the trusted source of who works there and in what role. JML is the operational side of onboarding and offboarding, and the term is common in audit and identity governance work.

At a glance

  • Joiner: create the identity and grant the access a new person needs on day one.
  • Mover: add access for the new role and remove access that the old role no longer justifies.
  • Leaver: disable sign-in, remove access, recover devices and hand over data.
  • Works best when triggered automatically from the HR system rather than by email or ticket.
  • Often tested in audits, together with periodic access reviews.

What problem it solves

When account changes depend on someone remembering to raise a ticket, three things go wrong. New hires wait days for access and borrow colleagues’ logins in the meantime. People who change roles keep everything they ever had. And leavers keep working accounts in applications nobody remembered, especially SaaS tools bought outside IT, a form of shadow IT. Former employees with live access are a common audit finding and a real security risk.

A defined JML process makes each event predictable: who triggers it, what changes, who approves and how completion is checked. Automated well, it reduces help desk workload and the time to productivity for new staff, and it closes access when people leave.

How it works

Trusted source. The HR system, or another system of record for contractors, records the event: hire date, role, department, manager, start of leave, termination date.

Identity update. That event creates or updates the person’s identity in the directory or identity and access management (IAM) platform, often automatically through an integration.

Birthright access. Joiners receive baseline access based on attributes such as department and location, commonly through groups or role-based access control (RBAC). Extra access is requested and approved separately.

Provisioning to applications. Accounts are created in connected applications, increasingly through standards such as System for Cross-domain Identity Management (SCIM), with single sign-on (SSO) handling sign-in. Applications without automation get a ticket to their owner.

Mover changes. A role change triggers new birthright access and, ideally, removal or review of access tied to the old role. Some organizations keep old access for a short transition period with an expiry date.

Leaver steps. Central sign-in is disabled and active sessions revoked where the platforms support it, application accounts are removed or disabled, devices are recovered or wiped, licenses are reclaimed and data such as mailboxes and files is handed to a manager or retained according to policy.

Verification. Completion is tracked, and periodic access reviews catch what the process missed.

When it matters for buyers

  • When hiring is scaling fast. Manual onboarding breaks down quickly as hiring volume grows. Automating joiner steps is often the first identity project with a visible payoff.
  • After a merger, acquisition or layoff. Large numbers of movers and leavers in a short time expose gaps. Plan leaver handling before the announcement, with HR and legal.
  • When SaaS spend and sprawl grow. SaaS management platforms can find apps and accounts that the JML process doesn’t cover and reclaim unused licenses.
  • When the help desk is overloaded. Automated provisioning cuts the volume of account tickets, leaving the help desk to handle exceptions and applications without automation.

Our SaaS management platforms overview covers tools that help with SaaS discovery, provisioning and license reclamation.

Questions to ask vendors

  • Which HR systems can trigger joiner, mover and leaver events, and how quickly do changes flow through?
  • Which of our applications can you provision and deprovision automatically, and how?
  • How do you handle mover events: is old access removed or flagged automatically?
  • Can you revoke active sessions and tokens at termination, not just disable the account?
  • How do you handle contractors and other people who aren’t in the HR system?
  • What reporting shows that leaver steps were completed, and when?

How it differs from identity governance and administration (IGA)

JML is a process: the set of steps that handles each person’s access as they join, move and leave. Identity governance and administration (IGA) is the broader discipline and tool category that often automates JML, and also covers access requests, approvals, role management, policy and access certification. Many organizations run JML with an identity provider, HR integrations and tickets before they buy an IGA tool; IGA becomes more relevant as the number of applications, audit demands and access complexity grow.

Frequently Asked Questions

Who owns the JML process?
Usually it is shared. HR owns the employment event and the data, IT or identity teams own account creation and removal, and managers and application owners approve access. Problems often come from gaps between these groups, so it helps to name one owner for the process end to end.
Why are movers the hardest part?
Joiners and leavers are obvious events, but role changes often aren't reported to IT, and new access is added without old access being removed. Over time movers accumulate permissions from every job they have held, which is why access reviews keep finding them.
How fast should leaver access be removed?
As fast as your risk and obligations require. Many organizations aim to disable central sign-in at or before the moment a person leaves, especially for involuntary departures, and then clean up application accounts, devices and data. Check what your auditors, contracts and frameworks expect.
Can JML be fully automated?
Much of it can, when the HR system is the trusted source and applications support automated provisioning, for example through SCIM. Applications without connectors, physical assets and judgment calls such as data handover usually still need tickets and people.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.