IT CanvassTalk to an advisor
Development · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · intermediate

Joiner, mover, leaver

Lifecycle events automate access when someone joins, changes role or leaves, driven by authoritative HR data.

Quick answer

Lifecycle events are triggers IdentityIQ fires when an identity changes state, a joiner appears, a mover changes department, or a leaver is terminated. Each event runs configured logic, such as provisioning birthright access for joiners or disabling all accounts for leavers.

Key takeaways
  • Events fire on identity state changes from HR data
  • Joiner: provision birthright access automatically
  • Mover: add new-role access, remove old access
  • Leaver: disable or delete all accounts promptly
  • Reduces manual tickets and closes security gaps

Lifecycle events (and, in Identity Security Cloud, lifecycle states) are how IdentityIQ automates the joiner, mover and leaver process, reacting to changes in the authoritative source to grant, adjust and revoke access automatically. They are the mechanism that makes the identity lifecycle real.

Joiner, mover, leaver

  • Joiner, on hire, create the identity and provision birthright access.
  • Mover, on department/role change, grant new access and remove old.
  • Leaver, on termination, disable immediately then fully deprovision.

How events fire

When the authoritative source changes an attribute (hire, transfer, termination), aggregation brings the change in, identity refresh detects it, and the matching lifecycle event fires the appropriate provisioning. Clean authoritative data and a reliable refresh cadence are prerequisites, events are only as timely as the HR feed.

Why movers matter most for hygiene

Joiner and leaver get the attention, but the mover event is where privilege creep is either reversed or accelerated. A mover that only adds new access, without removing the old, quietly builds the over-privilege that certifications later have to clean up. Design movers to revoke as well as grant.

Common pitfalls

  • Movers that only add access, never removing the old.
  • Late or wrong HR data firing events at the wrong time.
  • Slow leaver processing leaving orphaned access.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Lifecycle events are triggered by?

Frequently asked questions

What does the term lifecycle events refer to in SailPoint?
Lifecycle events (and, in Identity Security Cloud, lifecycle states) are how IdentityIQ automates the joiner, mover and leaver process, reacting to changes in the authoritative source to grant, adjust and revoke access automatically. They are the mechanism that makes the identity lifecycle real.
What is another point to note about lifecycle events?
When the authoritative source changes an attribute (hire, transfer, termination), aggregation brings the change in, identity refresh detects it, and the matching lifecycle event fires the appropriate provisioning.
What else is worth knowing about lifecycle events?
Clean authoritative data and a reliable refresh cadence are prerequisites, events are only as timely as the HR feed.
What tends to go wrong with lifecycle events?
Movers that only add access, never removing the old. Late or wrong HR data firing events at the wrong time. Slow leaver processing leaving orphaned access.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support