Core Concepts lessons

Core Concepts · Lesson 3

Identity Lifecycle (JML)

Joiner, mover, and leaver events — the operating model behind least privilege over time.

Identity governance is a lifecycle, not a one-time grant.

Joiner — HR or contractor systems trigger day-one access. Birthright roles should be least privilege; privileged access should be requested separately or issued as JIT.

Mover — role, department, or location changes must recalculate entitlements. Without movers, permission creep is inevitable. Good movers remove old access as aggressively as they add new access.

Leaver — terminate interactive access in minutes across IdP, SaaS, VPN, and privileged vaults. Orphaned accounts are a top audit and breach finding.

Connect JML to authoritative sources (HRIS, contractor systems) and keep a reconciliation job that finds identities that drifted from HR truth. IGA platforms turn those events into workflows with owners, SLAs, and evidence packs.

Next lesson: how humans and policies decide day-to-day grants through the access request queue.

Joiner → Mover → Review → Leaver

The identity lifecycle never really ends

The full identity journey from day-one provisioning through role changes to complete offboarding. Stages: Joiner: Access provisioned based on role at hire — least privilege from day one. Mover: Access adjusted: new rights added, obsolete rights revoked — not stacked forever. Review: Managers certify entitlements; risky or stale access is challenged. Leaver: Access revoked promptly on departure across every connected system.

  • JoinerProvision least-privilege access at hire
  • MoverRecalculate entitlements on role change
  • ReviewCertify that access is still needed
  • LeaverRevoke promptly with an audit trail

Learn more: Open related lesson →

Interactive check

No game on this lesson — try Access Request Flow or Spot the SoD Conflict.

Mark complete

Save progress on this device. Track completion unlocks badges in a later release.