Hello there!

Need Help? We are right here!

miniOrange Support Chat - Get Help and Support
miniOrange Email Support
Success Checkmark - Form Submitted Successfully

Thanks for your Enquiry.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to igasupport@xecurify.com

Search Results:

×

Joiner Mover Leaver (JML) Automation

Every HR change should create the right access action. miniOrange IGA turns trusted workforce updates into governed JML automation that prepares new hires, updates permissions when people move, and removes access when they leave.

  HR-driven provisioning for approved employment events

  Least privilege through role-based access changes

  Clear audit trails from trigger to completion

Request a Demo Get a Free Quote
Joiner Mover Leaver (JML) Automation

Workforce Changes Can Leave Access Exposed

Employment changes happen every day. Access often depends on tickets, spreadsheets, and follow-ups that create delays and security risks.


New Hires Wait for Access

Manual onboarding delays accounts, applications, and group membership needed for a productive first day.

Transfers Keep Old Permissions

Promotions and department moves can add entitlements while former access remains, creating privilege creep.

Exits Leave Access Active

A disabled account may not remove access to SaaS applications, VPNs, directories, or business tools.

Audit Evidence Stays Scattered

HR, IT, security, and application owners struggle to trace approvals, access changes, and unresolved offboarding actions.


What Is JML Automation?

Joiner Mover Leaver (JML) automation manages digital identities as people join, change roles, or leave. A trusted HR system or directory starts the relevant JML workflow. miniOrange IGA then creates, updates, or removes access through a defined JML process that supports identity and access management (IAM).

Simplify Access Management Across the Employee Lifecycle

Automatically give, update, remove access based on user lifecycle changes.


Joiner

Joiner

A hire event creates an identity, assigns birthright access, and provisions approved accounts and applications.


Mover

Mover

A role change reviews existing permissions, removes outdated access, and adds entitlements for new responsibilities.


Leaver

Leaver

An exit event starts automated deprovisioning to disable accounts and complete timely access removal.


One Workforce Event Creates the Right Access Decision

miniOrange IGA evaluates policies and approvals to determine who gets access, what they get, and when access changes.

Source

Source

Start with an authoritative identity source such as an HR system, Active Directory, or Microsoft Entra ID.

Decide

Decide

Match user attributes to roles, access policies, approval paths, and least privilege requirements.

Act

Act

Create accounts, provision applications, update entitlements, manage group membership, and revoke obsolete access.

Govern

Govern

Route sensitive requests through access approvals, time limits, policy checks, and access review workflows.

Prove

Prove

Record each lifecycle event, decision, approval, action, exception, and outcome in a searchable audit trail.

Core JML Workflows for Every Workforce Change

Each lifecycle event should result in access that fits the worker’s current role and business need.


Joiner Automation

Joiner Automation

A confirmed hire starts joiner automation and employee onboarding automation. miniOrange IGA creates or matches the identity, applies HR-driven provisioning, assigns approved birthright access, and provisions required accounts. Non-standard requests follow the right approval path.


Mover Automation

Mover Automation

A new job title, department, manager, location, or employment type starts mover automation. The workflow reviews role change access, retains justified permissions, removes previous-role entitlements, and grants access required for the worker’s new responsibilities.


Leaver Automation

Leaver Automation

A termination date or urgent departure begins leaver automation and the offboarding process. Automated provisioning and deprovisioning remove accounts, applications, groups, and entitlements to help reduce lingering orphaned accounts.


Role and Policy-Driven Access

Role and Policy-Driven Access

Role-Based Access Control (RBAC) maps approved workforce roles to standard access. Policy-based provisioning applies consistent permissions while elevated access stays outside the default package until it receives approval.


Segregation of Duties (SoDs) During Moves

Segregation of Duties (SoDs) During Moves

SoD checks assess access combinations during role changes. This helps identify toxic access before conflicting permissions are granted in finance, procurement, or operations.


Approvals and Exceptions

Approvals and Exceptions

Standard permissions follow the approved policy. Elevated, unusual, or out-of-role access follows an access-approval workflow with the appropriate manager, application owner, or control owner. Temporary access can include a fixed expiry date.


SCIM, API, Webhook, and Connector Provisioning

SCIM, API, Webhook, and Connector Provisioning

Prebuilt app connectors, SCIM provisioning, APIs, webhooks, Active Directory, and LDAP integrations carry approved lifecycle actions into SaaS, cloud, directory, and on-premises applications.


Access Reviews After Lifecycle Events

Access Reviews After Lifecycle Events

Access certification confirms whether sensitive or exceptional permissions remain appropriate after a lifecycle change. Periodic recertification helps security teams identify stale access that needs human review.


Audit Logs and Lifecycle Reporting

Audit Logs and Lifecycle Reporting

Detailed lifecycle reporting records provisioning, approvals, entitlement updates, deprovisioning, failures, and remediation actions. Teams gain reliable evidence of compliance for investigations and audits.


A Mover Needs Access Recalculation

A role change should review existing access before new permissions follow the employee.

1 Step

Keep

Retain email, collaboration applications, and baseline corporate access that remain justified by policy or the new role.

2 Step

Remove

Remove CRM editor rights, prior department groups, and shared-resource access tied only to the previous role.

3 Step

Add

Assign the ERP role, reporting group, and business applications required for the employee’s new responsibilities.

4 Step

Review

Route temporary cross-team access to an approver and apply an expiry date for the handover period.

Turn Workforce Updates Into Timely Access Actions

Prepare employees for day one, control permissions through role changes, and close leaver access without relying on manual follow-ups.

Talk with our team about HR-driven JML automation, role changes, and offboarding workflows.

How miniOrange IGA Works

Trusted workforce information follows a clear path from lifecycle event to governed access action.

1
Step 01

Connect Data

HR systems and directories provide hire dates, job details, manager data, employment updates, and termination events.

2
Step 02

Map Rules

Roles, departments, locations, and employment types map to access packages, approvals, RBAC, and SoD policy enforcement.

3
Step 03

Detect Events

A hire, promotion, transfer, manager change, contract end date, or exit starts the relevant JML lifecycle workflow.

4
Step 04

Calculate Access

miniOrange IGA determines which accounts and entitlements to create, retain, change, remove, expire, or review.

5
Step 05

Apply Changes

Connectors, APIs, webhooks, and SCIM 2.0 carry approved access changes into relevant applications and directories.

How miniOrange IGA Works

JML Automation Use Cases for Workforce Change

Routine workforce events should lead to timely access decisions, not delayed tickets or untracked follow-ups.

Prepare New Hires Before Day One

Reassess Access After Transfers

Complete Employee Offboarding Reliably

Control Contractor and Vendor Access

Protect Sensitive Business Transitions

Manage Temporary Cross-Team Access

Standardize Organizational Change

Prepare New Hires Before Day One

An approved future hire record can start preboarding before the new employee begins work. This gives IT time to prepare the required digital identity and baseline access.

  • Create accounts from HR data
  • Apply approved birthright access
  • Add required group memberships
  • Route exceptions for approval


Measure Lifecycle Governance and Access Readiness

Track how quickly workforce updates become accurate access actions and identify where manual intervention is still required.

Joiner Readiness
Mover Residual Access
Leaver Deprovisioning Time
Automation Rate
Workflow Exceptions
Orphaned Access
Audit Completeness

Joiner Readiness

  • Measure the time between an approved HR record and the completion of required access provisioning.
  • Check HR data, role rules, and access policies
  • Confirm clear owners for approvals and exceptions
  • Identify gaps before they delay a new starter

Mover Residual Access

  • Identify previous-role entitlements that remain after a transfer, promotion, or department change.
  • Detect access creep after workforce role changes
  • Prevent privilege accumulation from old permissions
  • Maintain the Principle of Least Privilege (PoLP)

Leaver Deprovisioning Time

  • Track the time from an exit event to completed access removal across relevant applications and directories.
  • Prioritize immediate removal for involuntary terminations
  • Complete standard offboarding by the final working day
  • Trigger automatic expiry for contractor and vendor access

Automation Rate

  • Measure the percentage of standard joiner-mover-leaver automation events completed without manual tickets.
  • Track zero-touch provisioning, changes, and deprovisioning
  • Monitor automated access reviews and compliance checks
  • Compare results with an 80% to 85% automation target

Workflow Exceptions

  • Monitor lifecycle events that need a policy decision, manual review, remediation, or further approval.
  • Escalate or reject requests after an approval timeout
  • Retry provisioning failures or route them to IT
  • Send policy and SoD violations for risk review

Orphaned Access

  • Identify accounts or entitlements without an active identity, accountable owner, or current business purpose.
  • Reconcile application entitlements with authoritative HR sources
  • Trigger automated deprovisioning after a termination event
  • Run access certification campaigns to confirm ownership

Audit Completeness

  • Confirm that every lifecycle action has a recorded trigger, decision, approval where required, and outcome.
  • Cover employees, contractors, service accounts, bots, and API keys
  • Include nested groups, application roles, and cloud permissions
  • Keep all active applications and user populations in scope

Support Compliance Through Governed Access Records

Documented access decisions, approval records, reviews, and lifecycle activity can support audit readiness across regulated environments.

View Compliance Frameworks
GDPR
GDPR

Data Privacy

PCI DSS
PCI DSS

Payment Card Data

ISO/IEC 27001
ISO/IEC 27001

ISMS

HIPAA
HIPAA

Healthcare Privacy

SOC 2
SOC 2

Type II

NIST Cybersecurity Framework
NIST Cybersecurity Framework

Cybersecurity

DPDP Act 2023
DPDP Act 2023

Data Protection

RBI Cybersecurity Framework
RBI Cybersecurity Framework

Banking

SAMA Cybersecurity Framework
SAMA Cybersecurity Framework

Saudi Finance

Saudi Arabia NCA Frameworks
Saudi Arabia NCA Frameworks

National Cybersecurity

Why Teams Choose miniOrange for JML Automation

Unified IGA Platform

Joiner-mover-leaver automation works alongside access requests, access reviews, roles, SoD controls, and reporting within miniOrange IGA.

Broad Integration Coverage

HR platforms, directories, SaaS applications, cloud services, and on-premises environments can connect through flexible provisioning methods.

Role-Focused Governance

Access follows the employee’s current role. Previous-role permissions can be removed before unnecessary access becomes a security concern.

Policy-Led Decisions

Approved rules guide standard changes. Exceptions move through defined approvals, expiry controls, and governance checks.

Practical Deployment Support

miniOrange helps teams connect identity data, map access rules, configure lifecycle workflows, and prepare for evolving access requirements.

24/7 Technical Support

miniOrange offers support plans with 24/7 availability options for customers who need technical assistance during deployment and ongoing operations.

FAQs

Contact us

What is Joiner Mover Leaver (JML) automation?

It is a structured identity lifecycle management process that creates, changes, and removes user access when people join, change roles, or leave an organization.

How is JML automation different from user provisioning?

User provisioning creates or updates accounts. JML automation determines when access should change, what permissions fit the role, and whether approval is required.

What should be the source of truth for a JML workflow?

For employees, an HR system often serves as the authoritative identity source because it stores job details, manager information, employment status, start dates, and exit dates.

Can joiner automation begin before a new employee starts?

Yes, an approved future hire date can begin preboarding. This helps ensure required accounts and approved access are ready before the employee’s first day.

What happens to old access after a role change?

Mover automation checks what access remains appropriate. It can retain valid permissions, remove outdated access, add new entitlements, or send exceptions for review.

How does leaver automation work?

A termination event or planned exit date starts the leaver process. The workflow can disable accounts, revoke permissions, remove groups, and record each deprovisioning action.

Can contractors and vendors follow JML workflows?

Yes, contractors, vendors, interns, and seasonal staff can receive sponsor-based time-bound access with a defined start date, end date, and offboarding workflow.

How are sensitive access requests handled?

Elevated or unusual requests follow an access approval workflow. Managers, application owners, or control owners can review the request before access is granted.



Want To Schedule A Demo?

Request a Demo