Identity

A joiner, mover and leaver process that closes access gaps

How small organisations can connect employment events, approvals, accounts, devices and completion records.

Access lifecycle is a business process with technology steps. A reliable process starts from an authorised employment or contract event, assigns role-based access, separates approval from administration where practical, records completion and removes sessions, devices, groups, applications and shared secrets promptly when access ends.

Design choices that matter

  • Use role templates as a starting point, then approve exceptions explicitly.
  • Movers are often riskier than leavers because old access accumulates quietly.
  • Shared accounts make accountability and offboarding harder; replace them where possible.

How to approach the work

  1. 01

    Name the trigger and authority

    Define who can request, approve, change and end access and how urgent terminations are communicated.

  2. 02

    Build role templates

    Map minimum groups, applications, devices, data and training for common roles.

  3. 03

    Automate carefully

    Automate repeatable provisioning only where source data, approval and failure handling are reliable.

  4. 04

    Close every access path

    Revoke sessions, disable accounts, recover devices, remove delegated and application access and rotate shared secrets.

  5. 05

    Review evidence

    Reconcile current staff, contractors, guests, privileged access and licences on a regular schedule.

What to test before handover

  • Authority defined
  • Role templates approved
  • Exceptions recorded
  • Urgent termination path tested
  • Sessions and apps covered
  • Shared credentials addressed
  • Devices recovered
  • Periodic reconciliation scheduled

Problems to catch early

  • Treating an email-account disable as complete offboarding
  • Copying a previous user's access without role review
  • Leaving movers with their old privileges indefinitely

Useful technical references

  1. Microsoft Learn — Identity lifecycle management
  2. Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
  3. Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide

Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.

A practical next step

Apply the guidance to the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.