---
title: "Joiner / Mover / Leaver — Identity Glossary | IDSync"
description: "Joiner / Mover / Leaver (JML) is the operational model for managing identity through the employee lifecycle — granting access on hire, changing it on role…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Joiner / Mover / Leaver",
          "item": "https://idsync.com/glossary/joiner-mover-leaver"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/joiner-mover-leaver",
      "name": "Joiner / Mover / Leaver",
      "alternateName": [
        "JML",
        "JML",
        "Lifecycle management",
        "Employee lifecycle"
      ],
      "description": "Joiner / Mover / Leaver (JML) is the operational model for managing identity through the employee lifecycle — granting access on hire, changing it on role change, and removing it on exit — typically driven from an HR system through the IdP and into downstream apps via SCIM.",
      "url": "https://idsync.com/glossary/joiner-mover-leaver",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is JML the same as IGA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "JML is the lifecycle pattern. [IGA](/glossary/iga) is the platform category that automates it (along with access reviews, SoD, and governance)."
          }
        },
        {
          "@type": "Question",
          "name": "What if I don't have an HRIS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Smaller orgs use the IdP itself (Okta, Google Workspace, Microsoft 365) as the source of truth. That works up to a point, then HR-driven becomes necessary."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Joiner / Mover / Leaver 

Provisioning

# Joiner / Mover / Leaver (JML)

Joiner / Mover / Leaver (JML) is the operational model for managing identity through the employee lifecycle — granting access on hire, changing it on role change, and removing it on exit — typically driven from an HR system through the IdP and into downstream apps via SCIM.

Last reviewed 3 months ago

Key points

-   JML is the lifecycle model behind every modern provisioning workflow.
-   Joiner: birthright access provisioned on day one based on role/department.
-   Mover: access updated (added and removed) when the employee changes role.
-   Leaver: access fully revoked on exit — the part most organizations get wrong.
-   Drives from HR (Workday, BambooHR, Rippling, Hibob) → IdP (Okta, Entra) → apps (via SCIM).

## What is Joiner / Mover / Leaver?

Joiner / Mover / Leaver (JML) is the operational model for managing identity across the full employee lifecycle. Every modern identity program is structured around the same three events:

1.  **Joiner** — a new employee starts. They need an IdP account, an email, a laptop, and access to the apps their role requires, ideally on day one.
2.  **Mover** — an employee changes role, team, or location. They need new access _and_ the old access they no longer need has to be removed (the most-skipped part).
3.  **Leaver** — an employee leaves (voluntary, involuntary, or contract end). Every account, every session, every API token tied to them needs to be killed within hours, ideally minutes.

## The typical JML chain

The cleanest pattern flows from a single source of truth:

\`\``text HR system → Identity provider → Downstream apps (Workday) (Okta / Entra ID) (via SCIM / native)` \`\`

-   HR is the authoritative record (hire date, term date, manager, department).
-   The IdP imports those records and assigns the user to groups based on role.
-   Groups drive both [SSO](/glossary/single-sign-on) access and [SCIM](/glossary/scim) provisioning into downstream apps.
-   A termination in HR cascades within minutes to IdP suspension, SCIM-driven account disable, session revocation, and device wipe.

## Why JML matters

-   **Day-one productivity** — new hires staring at a blank screen for a week is a brutal first impression and an expensive one.
-   **Security** — orphaned accounts after layoffs or terminations are the single most common audit finding.
-   **Compliance** — SOC 2, ISO 27001, SOX, HIPAA, and most regulators expect documented, automated JML.
-   **Cost** — paying for SaaS seats nobody is using because nobody deprovisioned them.

## Common pitfalls

-   **HR doesn't sync to IdP in real time.** Leavers stay active until the next nightly sync.
-   **Movers are ignored.** Joiners are easy, leavers are increasingly automated, movers are where stale access accumulates.
-   **Birthright over-grant.** Day-one access is too broad, then never trimmed.
-   **Apps without SCIM.** Manual deprovisioning never gets done consistently.
-   **No emergency offboarding path.** Hostile termination requires a same-minute kill, not a same-day kill.

## How to fix JML at scale

-   Make HR the unambiguous source of truth.
-   Define **birthright access** by role/department, not by manual ticket.
-   Drive [SCIM](/glossary/scim) everywhere you can; manually deprovision the rest with checklists.
-   Implement **emergency offboarding** as a single button that kills IdP session, SCIM-deactivates, revokes OAuth grants, and rotates shared secrets.
-   Measure mean-time-to-deprovision and report on it.

## FAQ

### Is JML the same as IGA?

JML is the lifecycle pattern. [IGA](/glossary/iga) is the platform category that automates it (along with access reviews, SoD, and governance).

### What if I don't have an HRIS?

Smaller orgs use the IdP itself (Okta, Google Workspace, Microsoft 365) as the source of truth. That works up to a point, then HR-driven becomes necessary.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[scim](/directory/category/scim)[iga](/directory/category/iga)[iam platforms](/directory/category/iam-platforms)

### Related terms

[scim](/glossary/scim)[iga](/glossary/iga)[rbac](/glossary/rbac)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the scim category.

[Explore tools](/directory/category/scim)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.