Identity & Access · Chapter 3
The lifecycle — joiner, mover, leaver
The least fashionable part of identity and the source of the most real exposure.
Identity governance lives or dies on one asymmetry: granting access is easy, automated and welcomed, while removing it is manual, invisible and nobody's priority.
Where each stage actually fails
| Stage | The real failure | What to check |
|---|---|---|
| Joiner | Access copied from a colleague — “give them what Priya has” | Are grants role-derived, or cloned from a person? |
| Mover | The old access is never removed | Does a role change trigger revocation, or only addition? |
| Leaver | HR termination does not reach every system | Time from termination to last access revoked, measured |
| Contractors | No HR record, so no lifecycle at all | Who owns non-employee identities? Is there an end date? |
| Service accounts | No owner, no expiry, no review | Can you name a human owner for each one? |
The contractor and service-account rows are where audits find the worst material. Both sit outside the HR-driven process that the rest of the lifecycle depends on, so both accumulate silently and neither appears in the metrics anyone reports.
Why access reviews fail, and what to do instead
The standard control is a periodic access review: send managers a list, ask them to confirm. It fails predictably, because a manager facing 400 entitlements with cryptic technical names and a deadline will approve all of them. This is rubber-stamping, and a rubber-stamped review is worse than none because it produces evidence of a control that is not operating.
- Review by exception — show what changed and what is unused, not the full list.
- Lead with usage data. “These 40 entitlements have not been used in 180 days” is a decision a manager can actually make.
- Make revocation the default for unused access, with a simple path to reclaim it.
- Prefer time-bounded grants so access expires without anyone having to decide — which converts an unreliable human control into an automatic one.