Joiner-mover-leaver
The joiner-mover-leaver process: joiners, movers and leavers
Joiner-mover-leaver, JML for short, is the lifecycle of every employee as IT sees it: someone arrives, someone changes, someone goes. It sounds simple, and it is the part of IT management where most access risks start.
The short answer
The joiner-mover-leaver process (JML) describes what happens to accounts and access at the three moments in an employee's career. Joiner: someone starts and gets the access that fits their role. Mover: someone changes role or department, gets the new access and loses the old. Leaver: someone leaves and loses all access on their last day. Automating JML means the HR system starts each of those moments.
Joiner: the right access from day one
On their first day a joiner needs an account, a licence, their department's groups and Teams and access to the applications for their role. What they do not need is a copy of a colleague's permissions. With roles based on job title, department and location, they get exactly what fits their work.
Mover: the moment that goes wrong most often
When someone changes role they almost always gain access, and almost never lose any. There is no ticket for it, because nobody is waiting. After a few roles, someone has access to everything they ever worked on.
That is the access an access review later flags as a deviation, and the reason a good JML process takes the mover just as seriously as the joiner and the leaver.
Leaver: everything closed on the last day
With a leaver it is about being complete. The account, the sessions, the groups, the licence, the mailbox and the accounts in applications outside Microsoft: everything has to be closed or handed over, on the last working day. A forgotten step stays open until someone finds it.
Automating JML with HR as the source
The HR system is the first to know when someone starts, changes or leaves. With Joinly, that record starts the process. Roles decide the access, workflows carry out the steps and every change goes into the audit log, with the reason.
For an MSP, that means the same process at all your clients, each with their own HR system, roles and conventions, from one login.

The three moments side by side
What has to happen at each moment, and what sets it off.
Moment
What has to happen
Trigger with Joinly
- Joiner
- What has to happen: Account, licence, groups, Teams and applications that fit the role
- Trigger with Joinly: New employee in HR
- Mover
- What has to happen: New access added, old access removed
- Trigger with Joinly: Job title, department or location changed in HR
- Leaver
- What has to happen: Account, sessions, groups and licence closed, mailbox handed over
- Trigger with Joinly: End date in HR
Joiner-mover-leaver
Frequently asked questions
What is JML?
JML stands for joiner-mover-leaver: the three moments when an employee's accounts and access change. In Dutch it is also called instroom, doorstroom and uitstroom.
What is the difference between JML and IAM?
IAM, identity and access management, is the whole field of identities and access. JML is the process within it that handles the employee lifecycle.
Why does the mover go wrong most often?
Because a role change adds access and rarely removes any. There is no ticket for it, and after a few roles someone has far more access than their work needs.
How do you automate the JML process?
By letting the HR system give the signal and letting roles decide the access. Joinly does that from 78 HR systems to Microsoft Entra ID, Active Directory and your applications.
What role does HR play in JML?
HR is the first to know when someone starts, changes role or leaves. Once HR is the source, IT no longer lags behind what is really happening.
- Joinly for MSPsFor an MSP, every joiner and leaver at a client is a ticket, a checklist and work that is hard to bill for. Joinly picks up those changes from your client's HR system and handles accounts, groups, licences and access automatically. For all your clients, from one login, with each client in its own environment.
- Onboarding and offboardingAn onboarding checklist per client and an offboarding ticket that arrives too late: for most MSPs, that is the work that comes back most often. With Joinly it starts as soon as your client records an employee in HR, and it follows the whole lifecycle.
- IT onboarding checklistA new employee knows on their first morning whether IT was on time. This checklist goes through the steps that takes, and shows for each step what Joinly does as soon as the employee is in HR.
- IT offboarding checklistWhen someone leaves, IT has one question to answer: can this person still get into anything after their last day? This checklist goes through the steps that takes, and shows for each step what Joinly does as soon as the end date is in HR.
Account management for your clients as a standard service?
In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.
Book an introduction