Lifecycle Management

Prioritizing Joiners, Movers, and Leavers: By Risk, By Urgency, By Rollout, and By Ease, Ranked

Aditi Sharma
Director, Strategy & GTM
Last Updated
July 17, 2026
8 MIn read

Ready to secure your identity surface?

About the author

Aditi leads Go-to-Market (GTM) and Business Strategy at Zluri, where she helps mid-market organizations modernize their identity governance and access management practices. Prior to Zluri, she was a Management Consultant at McKinsey & Company advising large enterprises on digital transformation, and part of the enterprise software investment team at B Capital. She holds an engineering degree from IIT Kharagpur and an MBA from Harvard Business School.

Ask three people on the same identity team which JML phase deserves priority and you'll get three confident, conflicting answers. All three might be right, because "which comes first" isn't one question. It's at least four: which carries the most risk, which is the most urgent problem today, which order the automation should be built in, and which delivers the easiest win first. The rankings don't match, and pretending they do is where the arguments come from.

Every identity team eventually faces the resource question: joiners, movers, and leavers all need attention, and there isn't enough attention for all three at once. The instinct is to look for the answer, a single, universal priority order.

There isn't one, and the search for it is what keeps teams stuck. What exists instead is a small set of honest rankings, each answering a different question, each correct within its lens. Name the question first, and the priority argument mostly resolves itself.

The foundation all three lenses share is the failure-mode table:

Same three phases, wildly different failure shapes. Now run the three lenses across them.

Lens 1: Priority by Risk

The question this lens answers: where does the danger actually concentrate?

The ranking: leavers, then movers, then joiners.

Leavers take the top slot because the exposure is active from the moment offboarding is missed. A departed employee's live account is a standing credential attached to nobody's accountability, invisible to daily operations, and precisely the entry path that dominates real-world breach patterns: valid access, no exploit required. The volume math seals it: hundreds of multi-system manual revocations a year means some fraction will be missed, and the only question is whether an auditor or an attacker finds them first.

Movers rank second, and they're the underrated entry on the whole board. When a role change adds new access without removing the old, nothing breaks and nobody is blocked, so nothing gets reported. Repeat across every transfer and promotion in a career, and least privilege erodes not through bad grants but through unremoved ones. Movers are also where access reviews quietly lose their meaning: a reviewer looking at a tenured employee's accumulated access has no signal separating current-role access from every-previous-role residue, so plausible-looking entries get approved wholesale.

Joiners rank third by risk, not because they don't matter, but because their failures can't hide. The system that detects a joiner failure is the human being blocked, and that detection is instant, free, and impossible to ignore. Whatever else goes wrong in your identity program, joiner gaps will never quietly persist for a year.

Under the risk lens, priority runs inverse to failure visibility: the phase whose failures nobody ever reports needs your attention most.

Lens 2: Priority by Urgency

The question this lens answers: what is the immediate, visible problem hurting the business today?

The ranking: joiners, then leavers, then movers.

This lens inverts the first one, and it isn't wrong, it's answering a different question. A blocked new hire is a paid employee who can't work, a manager escalating, a help desk queue growing, right now, this morning. Slow joiner handling also trains the workaround culture, shared credentials, shadow tools, that becomes everyone's security problem later. If the question is "what pain is the organization feeling today," joiners win, and nothing else is close.

Leavers rank second under urgency only when something forces the issue: an approaching audit, a security review, an incident at a peer company. Absent a forcing event, leaver problems generate zero urgency, which is exactly what makes them dangerous under the risk lens.

Movers rank last under urgency because mover problems never present as problems at all. Nobody has ever filed a ticket saying "my old access wasn't removed."

The trap in this lens is mistaking it for the risk lens. Urgency measures noise. Risk measures danger. Joiner pain is loud and bounded; leaver and mover risk is silent and serious. The classic prioritization mistake, in identity as everywhere else, is letting the urgent permanently crowd out the important:

The bottom two rows are where identity programs quietly fail: important, never urgent, therefore never scheduled.

Lens 3: Priority by Rollout Sequence

The question this lens answers: if we're automating the lifecycle, what order do we build in?

The ranking: leavers and joiners together first, movers last.

This lens produces a third ordering because it's constrained by dependencies and momentum, not just risk or noise:

  • Leaver automation goes early for the risk case. It's the argument that justifies the program to security and compliance, and completeness is the bar: offboarding that reaches 100 percent of systems in a day beats offboarding that reaches 70 percent in an hour, because the 30 percent is where the risk lives.
  • Joiner automation goes early for the goodwill case. Day-one access is the improvement HR, managers, and new hires all experience personally, and that fast, visible win buys the patience and budget the harder work needs. It also exercises the same HR-triggered plumbing leaver automation runs on, so the two build each other.
  • Mover automation goes last, not because it matters least but because it depends on the most. You can only automate "remove the old role's access" once roles are defined well enough to know what the old role's access was. Mover automation built on immature role definitions automates the add and fumbles the remove, which recreates the original problem with extra confidence.

Run in that order, each phase funds the next. Run in reverse, the program spends its first two quarters on the hardest, least visible problem and stalls before anyone sees value.

Lens 4: Priority by Ease

The question this lens answers: what can we ship first, fastest, to build momentum for the project?

The ranking: joiners, then leavers, then movers.

This is the project-management lens, and it's more legitimate than it sounds. Identity programs die from stalling more often than from mis-prioritizing: a program that spends two quarters on its hardest problem with nothing visible to show loses budget, patience, and its champion's credibility, regardless of how correctly the risk was ranked. Sequencing by ease is how a program stays alive long enough to do the important work.

The ease ranking follows the implementation reality of each phase:

  • Joiners are the easiest build. The trigger is clean (a new-hire event from HR), the action is add-only (nothing to untangle first), and the win is instantly visible to the most people. A working joiner flow can ship in weeks and every stakeholder feels it personally.
  • Leavers are moderately easy. The trigger is equally clean (a termination event), but the bar is completeness, and reaching the unfederated apps beyond SSO is where the work gets real. Shippable early, but "done" is harder than it looks.
  • Movers are the hardest build, for the dependency reason from Lens 3: the remove side requires role definitions mature enough to know what to remove. There is no easy version of mover automation.

The trap in this lens is the same as the urgency trap: stopping. Ease-first is a sequencing strategy, not a scope. The failure pattern is shipping the joiner flow, collecting the applause, and letting the momentum dissipate before the harder phases ship, which leaves the program with its most visible problem solved and its most dangerous ones untouched. Momentum is the means; the risk lens is still the destination.

The Four Rankings, Side by Side

Four defensible rankings, four different questions. The practical use of this table isn't picking a winner. It's diagnosing your team's disagreements: when one person argues joiners-first and another argues leavers-first, they're almost always running different lenses without naming them. Name the lens, and the argument usually converts into agreement about sequencing.

And one pattern holds across all four lenses: movers never rank first, and always matter more than their ranking suggests. Never urgent, second by risk, last by ease and by rollout dependency, movers are the phase every lens permits you to defer and no lens permits you to skip. The teams that get JML right are the ones that schedule mover work deliberately, precisely because nothing will ever force it onto the calendar.

For the operational detail of what each phase involves, the workflows, edge cases, and automation triggers, see the complete guide to joiners, movers, and leavers. This piece is the prioritization framework; that one is the execution manual.

Frequently Asked Questions

So which JML phase should our team actually prioritize?

Answer the lens question first. If you're allocating security attention and audit preparation, use the risk ranking: leavers, movers, joiners. If you're triaging this quarter's operational pain, the urgency ranking explains what's on fire: joiners. If you're sequencing a rollout with everything weighed, build leavers and joiners together, then movers. And if the program's survival depends on showing value fast, the ease ranking says ship the joiner flow first and bank the momentum. Most teams need all four answers at different moments; the mistake is using one lens for every decision.

Why do most teams end up joiner-focused by default?

Because organizations allocate attention by noise, and joiner failures are the only ones that generate any. A blocked new hire produces an escalation within hours; a missed offboarding produces silence for months; an unremoved old-role grant produces silence forever. Without a deliberate framework, the urgent lens wins every allocation by default, which is precisely how the important-but-silent phases accumulate risk.

Why not fix movers through access reviews instead of automation?

Because reviews inherit the mover problem rather than solving it. A reviewer looking at accumulated access has no signal separating current-role entries from historical residue, so everything plausible gets approved. Removing old access at the moment of the role change, when the context is fresh and the trigger is unambiguous, is the only point in the lifecycle where the decision is easy. Reviews then verify a clean state instead of excavating a historical one.

How do contractors and vendors fit these rankings?

They intensify the risk lens. Non-employee populations churn faster than employees, frequently skip the HR events that trigger automation, and concentrate in exactly the leaver failure mode: engagements that end without any system event announcing it. The practical fix is time-bound access, expiration attached at grant time, which converts the leaver problem for this population from "someone must remember" to "the access ends itself."

Do the rankings change for smaller companies?

The lenses and their orderings hold; the volumes shrink. A 200-person company has fewer departures and moves, but also less slack for manual work and typically nobody whose job includes reconciling access history. Smaller teams arguably benefit most from leading with leaver automation, since a single missed offboarding represents a proportionally larger share of their total risk surface.

Ready to secure your identity surface?