Provisioning track · 3 min
Joiner, mover, leaver: access that follows HR
Walk one person through a career and see what access should exist.
The idea
1Three moments
People join, change roles and leave. Each moment should change access, not just a spreadsheet.
2Joiners get a baseline
Access starts from the role: mail, chat and the tools the team uses, ready on day one.
3Movers are where privilege piles up
Add what the new role needs and remove what the old one gave. Skip the second half and access only grows.
4Leavers lose everything at once
When HR marks the person inactive, the change flows to every connected app.
Try it
Follow Asha
Step through her career. Then switch from HR-driven to ticket-driven access to see what gets forgotten.
This exercise needs JavaScript. Here is the answer key.
| Event | Access that should exist | Access with tickets |
|---|---|---|
| Joins Sales | Mail, CRM | Mail, CRM |
| Moves to Finance | Mail, Billing | Mail, CRM, Billing |
| Takes a Support shift | Mail, Billing, Support desk | Mail, CRM, Billing, Support desk |
| Leaves | nothing | CRM, Support desk |
Check yourself
1 of 3 Why do movers collect extra access?
2 of 3 Where should the change start?
3 of 3 What should happen at leave time?
Answer key
- Why do movers collect extra access? Old access is rarely removed. Requests add; nobody files a ticket to remove.
- Where should the change start? The HR record. Access follows the HR record, not the other way round.
- What should happen at leave time? Every connected app removes access. Provisioning carries the change.
Go deeper
Field notes
Runbooks
Offboarding checklist: joiner, mover, leaverRunbookAccess review preparationRunbookBlueprints
Joiner–Mover–LeaverBlueprintLexicon