Identity
A joiner, mover and leaver process that closes access gaps
How small organisations can connect employment events, approvals, accounts, devices and completion records.
Access lifecycle is a business process with technology steps. A reliable process starts from an authorised employment or contract event, assigns role-based access, separates approval from administration where practical, records completion and removes sessions, devices, groups, applications and shared secrets promptly when access ends.
Design choices that matter
- Use role templates as a starting point, then approve exceptions explicitly.
- Movers are often riskier than leavers because old access accumulates quietly.
- Shared accounts make accountability and offboarding harder; replace them where possible.
How to approach the work
- 01
Name the trigger and authority
Define who can request, approve, change and end access and how urgent terminations are communicated.
- 02
Build role templates
Map minimum groups, applications, devices, data and training for common roles.
- 03
Automate carefully
Automate repeatable provisioning only where source data, approval and failure handling are reliable.
- 04
Close every access path
Revoke sessions, disable accounts, recover devices, remove delegated and application access and rotate shared secrets.
- 05
Review evidence
Reconcile current staff, contractors, guests, privileged access and licences on a regular schedule.
What to test before handover
- Authority defined
- Role templates approved
- Exceptions recorded
- Urgent termination path tested
- Sessions and apps covered
- Shared credentials addressed
- Devices recovered
- Periodic reconciliation scheduled
Problems to catch early
- Treating an email-account disable as complete offboarding
- Copying a previous user's access without role review
- Leaving movers with their old privileges indefinitely
Useful technical references
- Microsoft Learn — Identity lifecycle management
- Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
- Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.