Control objective
Joiner, mover, and leaver processes keep identity and authority aligned with the current relationship and function. A joiner receives required accounts and narrow access. A mover receives new access and loses obsolete access. A leaver loses active sessions, authenticators, accounts, delegated authority, and recovery paths within the required time.
Event-to-control flow
Define the authoritative lifecycle event, effective time, target systems, approval, provisioning action, access review, session action, evidence, and exception handling. Use stable identifiers. Make operations repeatable so retries do not create duplicate accounts or restore removed access.
Movers are high risk
Role changes often accumulate authority because the new grant is easy and the old removal is unclear. Compute the required end state instead of only adding differences. Review direct grants, group membership, service credentials, ownership, emergency roles, and delegated access.
Failure and residual risk
Delayed source events, disconnected applications, stale group caches, long-lived sessions, and unmanaged local accounts extend access. A leaver can still act through shared credentials or delegated service authority. Immediate removal can also interrupt ownership and recovery if transfer was not planned.
Pomerium boundary
Pomerium route policy can reflect identity-provider groups and other context. Effective removal depends on source updates, context refresh, session behavior, and application access. Operators must measure the full revocation path instead of assuming that one directory update ends all access.
Evaluation checklist
- Which authoritative event starts each joiner, mover, or leaver action?
- Does the process compute the required end state and remove obsolete access?
- Are sessions, authenticators, recovery paths, local accounts, and delegated authority covered?
- Is the maximum completion and revocation time measured?
- Are exceptions, failed updates, and ownership transfer reviewed?
