Skip navigation
AI Security

Identity lifecycle management needs more than tools

Identity lifecycle management governs user access from onboarding through role changes and offboarding. It sounds simple: give people the right access when they join, update access when they move, and remove access when they leave. But in a Cisco Duo survey of 680 IT and security leaders, 60% of CISOs said they lacked confidence in their joiner-mover-leaver (JML) process, and especially the leaver stage.

That is a lot. And honestly, I get it. JML is one of those things that looks fine on the dashboard until you actually run an audit on terminated accounts. Then you realize the technology is doing its job, but the humans around it are not always doing theirs.

I recently had the opportunity to sit down with a few top CISOs featured in Cisco Duo's new CISO Perspectives 2026 report: Frank Aiello at Maximus, Lock Langdon at Aprio, and David Cass at Keyrock. In candid conversations, we covered automation, manager accountability, mover privilege creep, contractors, and the regulator perspective. Different industries, different scales, different identity stacks, but a similar pattern across all three conversations: the technology rarely fails. The process around it does.

You can watch the full conversations on demand at CISO Perspectives, and read about how identity is becoming a change agent in 2026. Here's what I took away.

Why JML is harder than the dashboards suggest

The thing about JML is that the automation has actually gotten really good. Frank made this point right out of the gate when I asked him about leaver audits.

His team at Maximus runs monthly leaver reviews, which started as a response to past audit findings and has become a standing operations cadence. Frank told me the automated processes are working great, terminating accounts within hours. So where is the breakdown? Managers. Specifically, managers who do not handle terminations very often may be less familiar with the process and sometimes delay entering the termination in HR.

Frank put it plainly: the human factor, not the automated processes, is where leavers fall through the cracks.

I have heard a version of this from almost every security leader I talk to, and it is rarely a tooling gap. Instead, it is an upstream HR process gap, a manager accountability gap, or an HRIS data gap. The technical controls assume accurate inputs, so when the inputs are late or wrong, the outputs are late or wrong. Frank's team targets 24 hours from HR entry, with the actual technical termination happening within four hours once the data flows. That is a workable model for leavers, but movers create a new type of challenge.

Mover privilege creep is a quiet problem

If leavers are loud, movers are quiet. Rather than identities being terminated during a leaver process, movers have a tendency to accumulate.

This is where Lock made a point that stopped me cold:

"We've got 47 sub-departments under tax. You've got specialty tax, you've got audit, compliance, all the subcomponents. When someone moves from one team to another, there needs to be a significant decoupling of their client access, because the client may not traverse those different boundaries."

—Lock Langdon, VP of IT Operations and CISO, Aprio

Forty-seven sub-departments under tax. I would never have guessed that. For me, "tax" is April 15th paying whatever figure my accountant tells me to. For Lock, it is a complex internal boundary system where client confidentiality has to be enforced as people move between teams, sometimes within the same broad function. Most organizations do not even recognize that those boundaries exist, and the mover process silently fails.

Mandy Andress at Elastic, who I talked with separately, described the financial services version of the same problem. Before Elastic she spent 13 years at a 175-year-old financial services firm, and the access people accumulated over decades of moving between roles was something else. You could see what someone had access to, but you often did not know what that access actually let them do, and whether it was still relevant. Her team eventually shifted to a "is this access actually being used" approach; if it had not been used in three or six or twelve months, depending on the system, it got turned off.

I have a saying I started using in these conversations: people who change roles accumulate access like frequent flyer miles. It gets a laugh, but it is also exactly what is happening.

David Cass at Keyrock added the piece that ties it together. In a regulated environment, the receiving manager is the one who has to validate that a moved user's access is appropriate going forward. Security cannot make that call alone, because security does not know what the new role actually requires day-to-day. The manager owns it.

That puts the mover problem squarely in the category of business-process design, not identity tooling.

Contractors and third parties are the weakest link

If movers are the quiet problem, contractors are the structural one. Most JML programs were built around employees, while contractors got bolted on later and often with looser controls.

Mandy described how Elastic differentiates between three categories of non-employees: contractors providing services, consultants working internally on initiatives, and managed service providers handling specific functions. Each gets a distinct group structure, distinct access scopes, and distinct review cadences. That granularity is the right starting point. For example, a contractor doing six weeks of integration work should not be governed the same way as a long-term managed service provider with persistent access.

But the most direct approach I heard came from Nigel Miller, Deputy CISO at Maximus, who I also spoke with separately. Nigel's team uses a hard-line rule: if a contractor account is not reviewed within the prescribed window, it gets automatically terminated. No grace period.

That trade-off is real—you will sometimes lose access for someone who genuinely still needs it, because somebody missed a review. But you also do not have the silent drift of contractor accounts hanging around forever, which is the failure mode in most organizations. Nigel's framing is that hard lines are easier to defend to the business than fuzzy ones, as long as the business understands the trade-off going in.

David comes at this from a different angle. He is in crypto, and his framing is "I do not trust anybody." Not employees, not partners, not contractors, not vendors. Every access gets validated against a zero-trust construct, with minimum-necessary scope. That is a more aggressive posture than most industries need, but the underlying principle applies broadly: contractors should not be governed more loosely than employees just because they are contractors.

Where identity governance meets regulatory pressure

The regulatory pressure on JML is changing. David, who used to be a federal regulator overseeing cyber and IT risk for the eight largest banks in the world, made a point that I think gets missed in a lot of compliance conversations: Proportionality matters. The eight largest banks in the world are held to a different standard than a $10 to $100 million credit union. They have to be. But none of them get to skip multi-factor authentication (MFA) or single sign-on (SSO) because the basics are the basics. What scales with size and risk is the depth of controls layered on top.

Then, healthcare is its own version of this. The CISO at a healthcare network in our survey mentioned that surprise inspections from regulatory agencies now include cybersecurity, not just patient care. That was not the case a few years ago. The expectation has shifted, and identity governance is part of what gets inspected. Frank's organization at Maximus runs FedRAMP and CMMC environments, so he sees the same shift on the federal contractor side.

The takeaway is not that compliance is the reason to fix JML, but instead that JML practice is increasingly the thing regulators look at to judge whether security hygiene is real.

What mature JML programs do differently

If you are trying to figure out whether your JML program is in good shape, here is the rough shape of what I have seen work:

  1. Treat JML as a process problem first. The technology is rarely the bottleneck. Manager accountability, HRIS data quality, and review cadence are.

  2. Build manager accountability into HR workflow. Reminders, deadlines, escalation. Make termination entry as much a part of resignation processing as the exit interview.

  3. Audit movers more aggressively than leavers. Movers accumulate quietly. Leavers are loud.

  4. Standardize contractor governance with hard-line review cadences. Nigel's auto-terminate rule is a reasonable model if your business can absorb the occasional unintended access loss.

  5. Apply proportionality. The depth of your JML program should match your regulatory and risk profile, not someone else's.

None of these are heavy lifts in a tooling sense. Rather, these steps are leadership decisions about who owns what, with what accountability, on what cadence.

Watch the full CISO Perspectives conversations

If this resonates, the full interviews cover a lot more. Hear me ask CISOs for their leading perspectives on non-human identity hygiene, agentic AI risk, the future of passwords, mergers and acquisitions, and the 2026-edition identity fundamentals. Find demand recordings and the full report at duo.com/ciso.

For the platform side of this work, Cisco Identity Intelligence is identity security posture management built for tackling JML. Check out our click-through product tours to see for yourself what ISPM with Duo looks like.

About the author

Chris Anderson is Product CTO at Cisco Duo, where he helps drive Cisco's work in identity and access management (IAM) and identity security. He works at the frontier of where identity is going next: passwordless and phishing-resistant authentication, identity governance, and the new wave of non-human and agent identities that are reshaping how organizations think about access.

Chris hosts the CISO Perspectives series, sitting down with global security leaders to talk through identity sprawl, agentic AI, zero trust, and the practices that hold up at scale. He believes the next wave of identity is not just about who gets access. It is about what gets access, on whose behalf, and under what constraints.

Hear the full CISO Perspectives conversations at duo.com/ciso. Connect with Chris on LinkedIn.

Common questions about identity lifecycle management

  • What is identity lifecycle management?

    Identity lifecycle management is the set of processes and controls that govern user access from the moment a person joins an organization to the moment they leave. It typically covers account creation, role and access assignment, ongoing access reviews, role changes, and offboarding. Mature programs treat it as a joint responsibility between HR, IT, security, and individual managers.

  • What is the joiner-mover-leaver process?
  • Why do most organizations struggle with the leaver process?
  • What is mover privilege creep?
  • How is contractor identity governance different from employee identity governance?
  • What does just-in-time access mean in identity management?
  • What does good identity lifecycle management look like in practice?