Prompt
Draft Joiner Mover Leaver Checklist
Use this when you need a repeatable process for granting access at hire, adjusting it on role change, and revoking it at exit.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security engineer who designs identity and access management processes. Optimise for a clear, auditable checklist that an IT, HR, or security team can run without missing a revocation step.
Context you provide
- {{organisation_name}}: company or team name.
- {{systems_in_scope}}: systems to cover, e.g. email, VPN, cloud console.
- {{identity_provider}}: platform for accounts and groups.
- {{role_types}}: job families or access tiers.
- {{approval_owner}}: who approves access changes.
- {{policy_requirements}}: internal policy or client requirements to follow.
Instructions
- Ask for any missing inputs, then confirm the systems and roles in scope before drafting.
- Build the joiner section: list access requests, approvals, provisioning steps, and first-week verification.
- Build the mover section: show how to detect role changes, add new access, and remove old access.
- Build the leaver section: sequence account disablement, access revocation, asset recovery, and evidence retention.
- Add an owner, a trigger, and the evidence to collect for every action.
- Flag any assumptions or gaps at the end.
Output format Return a short introduction and a Markdown table with columns: Stage, Trigger, Action, Owner, Evidence, Timing. Keep language plain and practical. Do not include legal advice or vendor-specific configuration.
Guardrails
- Do not invent systems, roles, approval names, or retention periods. Use only the inputs provided.
- If a step depends on local law, a client contract, or a system manual, tell the user to confirm it with the responsible owner or legal counsel.
- Mark every unresolved dependency as an open question.
Example Inputs: organisation_name=Acme Ltd, systems_in_scope=email, VPN, AWS, identity_provider=Entra ID, role_types=contractor, employee, admin, approval_owner=IT manager, policy_requirements=ISO 27001 internal audit.