HireFly Blog

Joiner-Mover-Leaver Access Controls for HR and IT

Joiner-mover-leaver controls give people the access needed for their work, change it when responsibilities move and remove it promptly when the relationship ends. HR supplies authoritative workforce events; managers, identity teams, application owners and security convert those events into appropriate access.

Build an access catalogue

Map systems, role profiles, data sensitivity, standard entitlements, approver, fulfilment team, licence need and removal method. Separate birthright access from privileged or exceptional access. Avoid copying a previous employees account because the job title looks similar.

Joiners: prepare without opening risk

The approved hire event should identify person, entity, worker type, role, manager, location and start date. Provision accounts at the right time, use secure identity verification and deliver credentials separately from devices. Access should become active when authorised, not weeks early for convenience.

Managers select job-specific needs from defined profiles and justify exceptions. Application owners confirm high-risk rights. Before day one, test that core access works without giving HR broad administrator rights to solve every failure.

Movers: treat additions and removals together

A transfer, promotion, secondment, leave or acting assignment may change manager, location, duties and data scope. Review existing access against the new role and remove incompatible rights, not merely add more. Set expiry for temporary access and delegations.

Consider toxic combinations, such as creating and approving the same transaction, and access inherited through groups. A mover is a common source of privilege accumulation because old rights appear harmless individually.

Leavers: use risk-based timing

The authorised end event should reach identity and application owners with effective time, departure type and special handling. Coordinate account disablement, sessions, remote access, badges, devices, shared credentials, data ownership, mailboxes and third parties. Managers should preserve business records through approved transfer, not by keeping an account active.

Handle urgent departures

Define who can trigger immediate containment, which evidence is required and how HR, security, legal and management coordinate. Restrict details to those who need them. An urgent disablement should still create an auditable record and later reconciliation.

Control non-employees

Contractors, interns, agency staff, consultants and vendors need a sponsor, purpose, start, end and periodic confirmation. Do not rely on the supplier to notify every departure. Expire access automatically where possible and require deliberate renewal.

Connect source systems and monitor failures

Interfaces should validate required fields, effective dates, duplicates and failed transactions. Queue errors to named owners and reconcile workforce events with the identity platform. Automation speeds a good rule and scales a bad mapping.

Review access periodically

Managers and application owners should confirm that users and entitlements remain necessary, with additional scrutiny for privileged and sensitive access. Give reviewers understandable role information; a list of technical group codes encourages automatic approval.

Preserve privacy and separation of duties

HR should provide only event data needed for access action. IT should not receive confidential departure reasons unless operationally necessary. Administrators must not approve their own privileged access, and emergency elevation needs expiry and review.

Measure control performance

Track ready-on-start access, provisioning failures, mover removals, leaver disablement against authorised timing, expired exceptions, orphan accounts and review completion. Pair speed with sampled correctness.

Protect service and shared accounts

Assign a named owner, purpose, credential control, permitted users and review date. Do not transfer a departed employees password or leave integration accounts tied to personal email. Rotate secrets when authorised users change and preserve operational logs.

Govern privileged access

Administrator, payroll, security and sensitive-case rights require stronger approval, authentication, logging and review. Use time-bound elevation for emergency work where possible. Monitor unusual access without treating the control as permission for unrelated employee surveillance.

Test the process end to end

Sample joiners, movers and leavers from the HR event through every critical application. Include future-dated changes, withdrawn hires, rehires, extended contracts and failed interfaces. Compare the intended entitlement with the actual result rather than relying on closed tickets.

Example: internal move

An analyst moves from payroll to workforce planning. The event adds analytics tools, removes payroll transaction rights, changes data groups and ends a temporary approval delegation. HR, the manager and application owners verify the combined result rather than closing separate tickets independently.

Written by

Hariprasad Chandramangalath