Mover access drift: why role changes leave access behind
ILM Reference editors · Published 2026-06-23 · 3 minute read
TRACK: RUNNING THE PROGRAM · LESSON 11 OF 11
A mover is a person who changes role, department, manager or location. The mover event should add the access the new role needs and remove what the old role granted. In practice the removal step is the one that slips, so access accumulates over several moves. Handling movers well means a defined transition window, automatic removal where connectors exist, and a manager check for everything else.
Why is the mover stage the weakest?
Joiners have a start date and a manager waiting for the new hire to be productive. Leavers have a termination date and an audit test. Movers have neither pressure on the removal side: the person asks for new access because they need it, and nobody asks for old access to be removed because nothing breaks when it stays. The result is entitlement creep, also called privilege drift.
How do RBAC and ABAC handle movers?
With role-based access control, a mover should swap roles: lose the old role, gain the new one. That works when every piece of access sits in a role; access granted by one-off requests stays behind. With attribute-based access control, access follows HR attributes such as department, so a change of department changes access without anyone editing a role, provided the attributes are accurate and every application enforces them.
What do tools describe for movers?
Several governance platforms describe mover automation. SailPoint Identity Security Cloud automates joiner, mover and leaver events so that access is provisioned, adapted and corrected. Veza removes and adds access on role changes. C1 and Lumos trigger workflows from HR changes in role, department or manager. On the detection side, Orchid Security lists privilege drift among the issues it detects inside applications. These describe connected applications, except where a tool states otherwise.
What does a mover checklist look like?
- Trigger from HR. A change of role, department, manager or location in the HR system opens the mover process.
- Grant the new role's access on the effective date.
- Set a transition window, for example 30 days, during which the old access remains for handover. Record the end date.
- Remove the old role's access automatically at the end of the window, in every connected application.
- Send the new manager a list of remaining access in disconnected applications to confirm or revoke.
- Flag movers in the next access review so reviewers see access that came from a previous role.
How do you check it is working?
Count, per person, the entitlements that do not belong to their current role. The number should not grow with each move. A reviewer who sees old-role access flagged in a certification campaign can revoke it; one who sees an undifferentiated list usually approves it.
Sources
- NIST glossary, role-based access control
- NIST SP 800-162
- SailPoint Identity Security Cloud
- Veza lifecycle management
- C1 lifecycle
- Lumos lifecycle management
- Orchid Security
Reviewed Sep 2026