See AI-powered security on full display at GSX 2025 | Sept 29 – Oct 1  Learn More >>

EN

Blog /

July 15, 2026

The Joiner-Mover-Leaver Process: How Identity Lifecycle Management Extends to Physical Access

Every identity in the enterprise moves through three events: it joins, it changes, it leaves. The joiner-mover-leaver (JML) process is how identity teams turn those events into access decisions.

This post covers what the joiner mover leaver process is, how each stage works, why the process is incomplete while it stops at the digital perimeter, and how SailPoint customers extend it to badges, facilities, and physical credentials.

01

What Is the Joiner-Mover-Leaver Process?

The joiner mover leaver process is the operational core of identity lifecycle management: the workflows that grant, adjust, and revoke access as a person’s relationship with the organization changes.

A hire event triggers access provisioning. A transfer adjusts entitlements to the new role. A termination revokes everything. Done well, the whole cycle runs on automated provisioning from authoritative HR data. The Workday or SuccessFactors event drives the access change directly, with no lag between the identity’s status and the access it holds.

The process applies to every identity type, not just employees. Contractors, vendors, students, volunteers all join, change, and leave, often on faster cycles and with weaker oversight.

02

The Three Stages of the Joiner Mover Leaver Process

Joiner: Birthright Access and Automated Provisioning

On day one, a new hire needs a working set of access without filing a single request. Birthright access defines that baseline, the entitlements every person in a given role, department, or location receives automatically. A staff nurse gets the clinical systems and the unit doors. A finance analyst gets the ERP modules and the office floor. Nobody has to remember to ask.

Automated user provisioning delivers this from the HR record: the hire event creates the identity, and access provisioning follows the defined policy. Time-to-productivity drops from weeks to day one, and the access granted matches exactly what the role justifies.

Mover: Access That Follows the Role

A mover gains the entitlements of the new role and, in manual processes, keeps the old ones for months, sometimes for a career. The pattern is known as privilege creep, and it is one of the most common audit findings in access reviews.

Effective JML subtracts as well as adds. The transfer event grants the new role’s baseline and removes what the previous role justified, in the same automated action. The mover stage is the hardest to run manually and the stage where automation delivers the most value.

Leaver: Deprovisioning Without Delay

Deprovisioning is the stage with the least tolerance for latency. Every hour between termination and revocation is exposure. And involuntary terminations, where the risk is highest, are exactly the cases where manual processes are slowest and most error-prone.

Complete deprovisioning removes everything: accounts, entitlements, credentials, and assets, in one action triggered by the HR event itself. If any access right requires a separate ticket, a phone call, or a weekly batch job, the leaver stage has a gap. In most organizations, that gap is the badge.

03

Where the JML Process Breaks: The Physical Perimeter

In most enterprises, provisioning and deprovisioning cover applications, infrastructure, and cloud. They do not cover physical access.

Physical access runs on a parallel, manual track. The joiner’s badge is issued at a front desk on a different day by a different team, from a request the hiring manager remembered to send, or didn’t. The mover keeps facility access from two roles ago because no transfer event ever reaches the badge system. The leaver’s accounts are disabled within hours while the badge keeps opening doors for days or weeks.

Every organization that manages physical access manually has these cases on file: the employee who changed departments and kept access to the previous unit, the contractor whose engagement ended a quarter ago and still holds an active badge. A JML process that stops at the digital perimeter governs half the identity.

04

The Missing Layer: PIAM, and What Unified JML Looks Like

The layer that extends lifecycle automation to the physical world is Physical Identity and Access Management (PIAM): the discipline of managing physical identities, credentials, and facility access through the same identity-centric processes used for digital access. PIAM sits above the access control hardware – the PACS decides whether a badge opens a door, while PIAM decides whether the person should hold the badge, based on the same lifecycle events that drive their accounts.

When JML spans both domains through PIAM, the result is unified identity governance in lifecycle form: a single set of joiner-mover-leaver events keeps every access point, digital and physical, aligned with the identity’s current status automatically.

05

Extending JML with SailPoint

SailPoint provisioning already automates the digital half of the lifecycle for more than 3,100 enterprises. The certified Alert Enterprise Guardian for SailPoint integration extends the same JML events to physical access:

Contractors and the Non-Employee Lifecycle

The extension matters most for the population JML programs handle worst. Contractors and vendors join, move, and leave on engagement timelines HR systems often don’t track, and their physical access is where the gaps show most: badges issued with minimal verification, never time-bound, and active long after the work ends.

Running non-employee identities through the same joiner mover leaver process, access scoped to the engagement, expiring with it, revoked across both domains when it ends, closes one of the most commonly exploited gaps in enterprise access.

06

Automation Is the Start. Governance Is the Test.

A complete joiner mover leaver process must hold up under audit as well as in daily operation. Once physical access follows the same lifecycle as digital access, it also becomes certifiable in the same campaigns: managers review facility access alongside application entitlements, revocations execute automatically, and evidence is generated in real time.

How certifications and access reviews extend to physical access for SailPoint customers is covered in our companion guide. JML automates the access changes; governance proves they were the right ones.

07

Best Practices for Extending the JML Process

08

What Complete Identity Lifecycle Management Delivers

09

Frequently Asked Questions

01

What does joiner mover leaver mean?

The three identity lifecycle events, joining the organization, moving roles within it, and leaving it, and the access workflows each one triggers.

02

What is birthright access?

The baseline access that is automatically granted to every identity in a given role, department, or location at the joiner stage, before any individual request.

03

What is the difference between provisioning and deprovisioning?

Provisioning grants access in response to a lifecycle event; deprovisioning revokes it. A complete JML process automates both, across digital and physical access.

04

What is PIAM?

Physical Identity and Access Management, the discipline of managing physical identities, credentials, and facility access through identity-centric lifecycle and governance processes.

05

Does SailPoint handle physical access provisioning?

Not natively. SailPoint lifecycle events extend to badges and facilities through certified integrations such as Alert Enterprise Guardian for SailPoint.

06

Does the JML process apply to contractors?

Yes, and it matters most there. Contractors join, move, and leave on engagement timelines, and their access should be scoped to the engagement, time-bound, and revoked across both domains when it ends.

en_USEnglish