Skip to main content

Joiner, Mover, and Leaver Lifecycle

Create, change, and remove identity and access state when a person or workload enters, changes, or leaves a role.

Control objective

Joiner, mover, and leaver processes keep identity and authority aligned with the current relationship and function. A joiner receives required accounts and narrow access. A mover receives new access and loses obsolete access. A leaver loses active sessions, authenticators, accounts, delegated authority, and recovery paths within the required time.

Event-to-control flow

Define the authoritative lifecycle event, effective time, target systems, approval, provisioning action, access review, session action, evidence, and exception handling. Use stable identifiers. Make operations repeatable so retries do not create duplicate accounts or restore removed access.

Movers are high risk

Role changes often accumulate authority because the new grant is easy and the old removal is unclear. Compute the required end state instead of only adding differences. Review direct grants, group membership, service credentials, ownership, emergency roles, and delegated access.

Failure and residual risk

Delayed source events, disconnected applications, stale group caches, long-lived sessions, and unmanaged local accounts extend access. A leaver can still act through shared credentials or delegated service authority. Immediate removal can also interrupt ownership and recovery if transfer was not planned.

Pomerium boundary

Pomerium route policy can reflect identity-provider groups and other context. Effective removal depends on source updates, context refresh, session behavior, and application access. Operators must measure the full revocation path instead of assuming that one directory update ends all access.

Evaluation checklist

  • Which authoritative event starts each joiner, mover, or leaver action?
  • Does the process compute the required end state and remove obsolete access?
  • Are sessions, authenticators, recovery paths, local accounts, and delegated authority covered?
  • Is the maximum completion and revocation time measured?
  • Are exceptions, failed updates, and ownership transfer reviewed?

Sources and further reading

Keep learning

Identity and AuthenticationStandards and Protocols

SCIM Provisioning

Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Drift

Authorization drift is the gap that develops when effective access no longer matches intended access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo