CMDLAB logoCMDLABBook a consultation
← BLOG
Identity21 May 2026 · 8 min read

Automating joiner, mover, leaver without breaking the business

JML automation fails when it is built on entitlements instead of roles. Sequence the work in this order and it holds.

MR
Marcus Reid
Principal Consultant, IAM
access review dashboard screenshot

Everyone agrees leaver access should be revoked the same day. The projects that deliver it reliably share one trait: they fix the role model before they touch automation.

Audit before you design

Start with what exists. Every account, group, licence and entitlement across the directory and the SaaS estate. This exercise almost always finds orphaned accounts, standing privilege that should have been temporary, and licences billed for people who left last year.

Design roles with the business, not for it

A role model written by IT alone will be wrong in the details that matter. Sit with each function, agree the access package a new starter genuinely needs, and treat anything outside it as an exception requiring approval.

Automate the events, keep humans on exceptions

HR joiner event provisions the role package automatically
Mover events add and, critically, remove access
Leaver events revoke on the effective date without a ticket
Anything outside the role model routes to a named approver

The measure of a JML process is not how fast it grants access. It is whether removal happens without anyone remembering to ask.

Add quarterly reviews on top and the audit question — who has access to what, and why — becomes a report rather than a project.

Want this reviewed against your estate?
A 30-minute consultation, no obligation. We'll tell you where the avoidable cost is.
Book a consultation
BOOK A CONSULTATION

Tell us what the estate looks like.

Send the form and it routes straight to query@cmdlab.eu. We reply within one business day with two proposed times.

COVERAGE
18 EU countries · UK · remote-first with dispatched engineers
Request a consultation
Fields marked * are required.
Submissions are delivered to query@cmdlab.eu. We store enquiry data only to answer your request — see our privacy notice.