Joiner-mover-leaver (JML) is the identity lifecycle process that handles people’s access as they join an organization, move between roles and leave it. For each event, it creates, changes or removes accounts, group memberships, application access and often devices, ideally driven by the HR system as the trusted source of who works there and in what role. JML is the operational side of onboarding and offboarding, and the term is common in audit and identity governance work.
At a glance
- Joiner: create the identity and grant the access a new person needs on day one.
- Mover: add access for the new role and remove access that the old role no longer justifies.
- Leaver: disable sign-in, remove access, recover devices and hand over data.
- Works best when triggered automatically from the HR system rather than by email or ticket.
- Often tested in audits, together with periodic access reviews.
What problem it solves
When account changes depend on someone remembering to raise a ticket, three things go wrong. New hires wait days for access and borrow colleagues’ logins in the meantime. People who change roles keep everything they ever had. And leavers keep working accounts in applications nobody remembered, especially SaaS tools bought outside IT, a form of shadow IT. Former employees with live access are a common audit finding and a real security risk.
A defined JML process makes each event predictable: who triggers it, what changes, who approves and how completion is checked. Automated well, it reduces help desk workload and the time to productivity for new staff, and it closes access when people leave.
How it works
Trusted source. The HR system, or another system of record for contractors, records the event: hire date, role, department, manager, start of leave, termination date.
Identity update. That event creates or updates the person’s identity in the directory or identity and access management (IAM) platform, often automatically through an integration.
Birthright access. Joiners receive baseline access based on attributes such as department and location, commonly through groups or role-based access control (RBAC). Extra access is requested and approved separately.
Provisioning to applications. Accounts are created in connected applications, increasingly through standards such as System for Cross-domain Identity Management (SCIM), with single sign-on (SSO) handling sign-in. Applications without automation get a ticket to their owner.
Mover changes. A role change triggers new birthright access and, ideally, removal or review of access tied to the old role. Some organizations keep old access for a short transition period with an expiry date.
Leaver steps. Central sign-in is disabled and active sessions revoked where the platforms support it, application accounts are removed or disabled, devices are recovered or wiped, licenses are reclaimed and data such as mailboxes and files is handed to a manager or retained according to policy.
Verification. Completion is tracked, and periodic access reviews catch what the process missed.
When it matters for buyers
- When hiring is scaling fast. Manual onboarding breaks down quickly as hiring volume grows. Automating joiner steps is often the first identity project with a visible payoff.
- After a merger, acquisition or layoff. Large numbers of movers and leavers in a short time expose gaps. Plan leaver handling before the announcement, with HR and legal.
- When SaaS spend and sprawl grow. SaaS management platforms can find apps and accounts that the JML process doesn’t cover and reclaim unused licenses.
- When the help desk is overloaded. Automated provisioning cuts the volume of account tickets, leaving the help desk to handle exceptions and applications without automation.
Our SaaS management platforms overview covers tools that help with SaaS discovery, provisioning and license reclamation.
Questions to ask vendors
- Which HR systems can trigger joiner, mover and leaver events, and how quickly do changes flow through?
- Which of our applications can you provision and deprovision automatically, and how?
- How do you handle mover events: is old access removed or flagged automatically?
- Can you revoke active sessions and tokens at termination, not just disable the account?
- How do you handle contractors and other people who aren’t in the HR system?
- What reporting shows that leaver steps were completed, and when?
How it differs from identity governance and administration (IGA)
JML is a process: the set of steps that handles each person’s access as they join, move and leave. Identity governance and administration (IGA) is the broader discipline and tool category that often automates JML, and also covers access requests, approvals, role management, policy and access certification. Many organizations run JML with an identity provider, HR integrations and tickets before they buy an IGA tool; IGA becomes more relevant as the number of applications, audit demands and access complexity grow.
