← All articles

JML Done Properly: Architecting the Joiner-Mover-Leaver Lifecycle

16 March 2026· 6 min read· IGA· JML· Workday· ServiceNow
JML Done Properly: Architecting the Joiner-Mover-Leaver Lifecycle
Figure - JML as event-driven architecture from authoritative source to guaranteed outcomes.Download diagram (SVG)

Ask an auditor where access risk comes from and they will show you leavers with live accounts and movers with five jobs’ worth of accumulated entitlements. JML - joiner, mover, leaver - is where identity governance is won or lost, and it is fundamentally an architecture problem: most organisations try to fix it with process documents when the process has no engine to run on.

Start from the authoritative source

The HR platform - Workday in many of my engagements - is the authoritative source for workforce identity. Not IT, not the directory, not a spreadsheet of contractors. That means every worker type must exist in the source, including the awkward ones: contractors, agency staff, external partners, even long-lived guests. If a population is not in the authoritative source, design a governed satellite source with an owner and a review cadence - do not let it leak in through the directory back door.

Joiners: birthright is a design decision

Birthright access - what you get for simply being a certain kind of worker in a certain place - should be minimal, computed from attributes, and delivered automatically before day one. Everything beyond birthright is requestable through the access request channel (ServiceNow in front, IGA engine behind), approvable, time-bound where sensible, and certifiable. The design test: a new joiner is productive on day one with zero manual provisioning tickets, and holds nothing that their attributes do not justify.

Movers: the forgotten lifecycle event

Movers are where entitlement creep is manufactured. A move event from the source must trigger recomputation of birthright, automatic removal of access tied to the old position, and a targeted certification of anything requested historically. “Add the new, keep the old” is not a transition - it is a toxic combination generator, and it is the default behaviour of every ticket-driven process I have ever assessed.

Leavers: guarantees, not intentions

Leaver processing needs hard guarantees: sessions revoked and sign-in blocked within minutes of the trigger, credentials and tokens invalidated, delegations and ownerships transferred, and non-human identities owned by the leaver flagged for re-parenting. Measure the interval between HR event and access termination as an SLO. If your answer is “by end of day”, your answer is no.

Automation with an audit trail

The whole lifecycle should be event-driven from the source, orchestrated by the IGA platform, and fully evidenced - every grant traceable to an event, a policy, or an approved request. When JML runs on that architecture, certification campaigns stop being archaeology and start being confirmation.

Have an identity challenge worth solving?

I take a small number of freelance and contract engagements each year.

Start a conversation