Skip to main content
Joinly by KoppelHet

Joiner-mover-leaver

The joiner-mover-leaver process: joiners, movers and leavers

Joiner-mover-leaver, JML for short, is the lifecycle of every employee as IT sees it: someone arrives, someone changes, someone goes. It sounds simple, and it is the part of IT management where most access risks start.

The short answer

The joiner-mover-leaver process (JML) describes what happens to accounts and access at the three moments in an employee's career. Joiner: someone starts and gets the access that fits their role. Mover: someone changes role or department, gets the new access and loses the old. Leaver: someone leaves and loses all access on their last day. Automating JML means the HR system starts each of those moments.

Joiner: the right access from day one

On their first day a joiner needs an account, a licence, their department's groups and Teams and access to the applications for their role. What they do not need is a copy of a colleague's permissions. With roles based on job title, department and location, they get exactly what fits their work.

Mover: the moment that goes wrong most often

When someone changes role they almost always gain access, and almost never lose any. There is no ticket for it, because nobody is waiting. After a few roles, someone has access to everything they ever worked on.

That is the access an access review later flags as a deviation, and the reason a good JML process takes the mover just as seriously as the joiner and the leaver.

Leaver: everything closed on the last day

With a leaver it is about being complete. The account, the sessions, the groups, the licence, the mailbox and the accounts in applications outside Microsoft: everything has to be closed or handed over, on the last working day. A forgotten step stays open until someone finds it.

Automating JML with HR as the source

The HR system is the first to know when someone starts, changes or leaves. With Joinly, that record starts the process. Roles decide the access, workflows carry out the steps and every change goes into the audit log, with the reason.

For an MSP, that means the same process at all your clients, each with their own HR system, roles and conventions, from one login.

Het lifecycle-overzicht in Joinly: accounts die elke HR-mutatie automatisch volgen

The three moments side by side

What has to happen at each moment, and what sets it off.

Joiner
What has to happen: Account, licence, groups, Teams and applications that fit the role
Trigger with Joinly: New employee in HR
Mover
What has to happen: New access added, old access removed
Trigger with Joinly: Job title, department or location changed in HR
Leaver
What has to happen: Account, sessions, groups and licence closed, mailbox handed over
Trigger with Joinly: End date in HR

Joiner-mover-leaver

Frequently asked questions

  • What is JML?

    JML stands for joiner-mover-leaver: the three moments when an employee's accounts and access change. In Dutch it is also called instroom, doorstroom and uitstroom.

  • What is the difference between JML and IAM?

    IAM, identity and access management, is the whole field of identities and access. JML is the process within it that handles the employee lifecycle.

  • Why does the mover go wrong most often?

    Because a role change adds access and rarely removes any. There is no ticket for it, and after a few roles someone has far more access than their work needs.

  • How do you automate the JML process?

    By letting the HR system give the signal and letting roles decide the access. Joinly does that from 78 HR systems to Microsoft Entra ID, Active Directory and your applications.

  • What role does HR play in JML?

    HR is the first to know when someone starts, changes role or leaves. Once HR is the source, IT no longer lags behind what is really happening.

Account management for your clients as a standard service?

In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.

Book an introduction