Process family
Access governance process: joiner, request, mover and leaver templates
The access governance family: user provisioning, access request, employee access request and access removal as one lifecycle, with the ISO 27001 Annex A.5.15 control and the data access request as parallel routes.
Access governance is the lifecycle of a person's entitlements. An HR event creates an identity, a request grants access to a system once the line manager and the system owner have approved it, a move removes what the old role no longer needs, and a leaver event revokes everything and reclaims the licenses. The four sequence templates are those events; the two beside them draw the same loop as an ISO 27001 control and for a single dataset.
The sequence is driven by HR events, not IT tickets. A joiner event creates the identity in the directory, issues credentials with MFA and derives the role entitlement bundle in user provisioning; anything outside the standard bundle waits for the entitlement owner. Access beyond the bundle goes through the access request: line manager, then system owner, a segregation-of-duties check, security approval for privileged access, least-privilege provisioning, an entry in the access register. A move runs the employee access request, which lists the previous role's access first and closes only when it has been removed.
A leaver, contract end or review finding runs access removal: cut all access within the hour or schedule it for the effective date, rotate shared credentials, disable or delete, transfer mailbox and file ownership, reclaim licenses, capture evidence of each revocation. The failures an auditor finds are familiar: access granted on a manager's word alone, movers who keep every past role's entitlements, leavers whose accounts outlive them, reviews nobody can evidence. Each template puts the control at that point: the system owner's approval after the manager's, the old-role removal step, the immediate-revocation branch, the evidence capture.
Recertification is the closing step of four members, provisioning, the access request, the ISO control and the data access request, and there is no standalone access review campaign template yet. The ISO 27001 Annex A.5.15 flowchart draws request, business approval, least-privilege provisioning, periodic owner attestation and revocation as one control for an audit. The data access request is its twin for a dataset: the purpose is stated, the catalog classification read, the data owner decides, personal data goes through privacy review and a DPIA, and every grant carries an expiry date.
HR owns the triggers, so this family is the IT lane of the Employee lifecycle: onboarding feeds provisioning, offboarding feeds removal, and the two lists should be reconciled against each other rather than trusted separately. Which datasets are catalogued, how they are classified and who owns them comes from Data governance, where the data access request template also lives. The immediate-revocation branch of access removal is used outside the HR calendar by security incident response when an account is compromised; the phishing template's password reset and session revocation is the same step, taken by the SOC instead of the service desk.
The sequence
Step 1: User provisioning process flowchart (joiner, mover, leaver)
User provisioning process flowchart: HR event, identity created in the directory, credentials and MFA, role entitlement bundle, owner approval for privileged access, downstream accounts, verification and recertification.
Step 2: Access request process flowchart
Access request process flowchart: role-based request, line manager and system owner approval, segregation of duties check, provisioning and recertification.
Step 3: Employee access request process flowchart (joiner and mover)
Employee access request process flowchart for joiners and movers: HR-triggered request, role access profile, manager and owner approval, old-role removal.
Step 4: User access removal process flowchart (deprovisioning)
User access removal process flowchart: leaver and role-change triggers, immediate revocation branch, shared accounts, licence reclaim and audit evidence.
Also part of this family
- ISO 27001 access control flowchart (Annex A.5.15) — An audit-ready ISO 27001 access control process flowchart aligned to Annex A.5.15. Documents request, business approval, technical provisioning, periodic review, and revocation with version control and approval workflow.
- Data access request process flowchart (request to revocation) — Data access request process flowchart: state the purpose, read the dataset's classification, let the data owner decide, run the personal-data checks, grant time-boxed access, then recertify or revoke.
Used in these industries
Related guides
- How to create a workflow diagram — How to create a workflow diagram: model the request, the approval gates, the work itself and the review that closes the loop, with each state owned by a role. With a live access-request example.