Jason Edwards
This chapter explains the operational reality of identity lifecycle control and why Joiner Mover Leaver execution determines whether access aligns to business intent or quietly drifts into risk. It clarifies how joiner events must be driven by validated identity attributes and sequencing, how mover events create privilege creep unless re authorization is enforced, and why leaver actions must go beyond directory disablement to include session revocation, token handling, and downstream cleanup. Throughout, the focus stays on predictable workflows, verification, and evidence capture that hold up under incident pressure. The chapter then drills into provisioning workflows and approval chains, showing how access requests must be complete enough to drive deterministic decisions and how approval authority must align to risk and resource boundaries. It highlights the operational failures that occur when bypass paths are tolerated, when nested groups hide transitive permissions, and when verification is skipped so teams cannot prove what was actually granted. Special attention is given to managing contractors, vendors, and temporary access through internal sponsorship, time bounded enablement, and affirmative renewal so external access does not become a long lived backdoor. Finally, the chapter covers identity hygiene and outcome driven access reviews as the mechanisms that reduce stale access and turn governance into measurable change. It defines how ownership models make identity processes durable by separating responsibility for identity attributes from responsibility for access outcomes, and it shows how AI assistance can safely improve prioritization, outlier detection, and evidence assembly when human accountability and auditability remain explicit. The result is a practical approach to identity governance that improves security posture while keeping operations predictable, explainable, and resilient.