Identity governance is a lifecycle, not a one-time grant.
Joiner — HR or contractor systems trigger day-one access. Birthright roles should be least privilege; privileged access should be requested separately or issued as JIT.
Mover — role, department, or location changes must recalculate entitlements. Without movers, permission creep is inevitable. Good movers remove old access as aggressively as they add new access.
Leaver — terminate interactive access in minutes across IdP, SaaS, VPN, and privileged vaults. Orphaned accounts are a top audit and breach finding.
Connect JML to authoritative sources (HRIS, contractor systems) and keep a reconciliation job that finds identities that drifted from HR truth. IGA platforms turn those events into workflows with owners, SLAs, and evidence packs.
Next lesson: how humans and policies decide day-to-day grants through the access request queue.