TechKnowSurge
NIST 800-53 PS-4 NIST 800-53 PS-5 NIST 800-53 AC-2 NIST CSF GV.RR-04
InteractiveSecurityFree

Joiner–Mover–Leaver

Follow one employee from hiring to leaving and decide what access to grant, keep, or remove at every career event, while a privilege creep meter shows what you forgot to take away.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're seeing: a career timeline for one employee, Maya Torres at TechKnowDJ, with six events from her first day to her last. At each one you see her current access list and decide what to grant, keep, or remove, and a privilege creep meter shows any access her current job no longer needs. Why it matters: the lesson's people life cycle is onboarding, role changes, and offboarding, and each one is a moment when access should change. People who move around a company without anyone removing their old access slowly collect far more than any one job needs, and an account left active after someone leaves is an easy way in. How to use it: read each event, set every item on her list, and apply. Read the feedback on anything marked wrong, because whatever you leave in place follows her to the next event. The final screen shows her whole access history.

How to play

Follow Maya Torres through six events at TechKnowDJ: hired, promoted, transferred, a temporary project, the project ending, and leaving.

At each event, set every item on her access list, then press Apply changes:

  • Grant / Keep anything her job after this event needs.
  • Remove / Don’t grant anything it doesn’t, even if someone asks for it.
  • At onboarding, decide on security awareness training. At offboarding, answer two questions about timing.

Whatever you leave in place follows her to the next event. The privilege creep meter counts access she holds that her current job doesn’t need.

Only the changes each event actually calls for count toward your score. Granting access the job doesn’t need costs the most; removing access it does need also costs points. Score 80% or more to pass. Reset replays from her first day.

What you'll learn

Aligned to

NIST 800-53
PS-4 Personnel Termination
PS-5 Personnel Transfer
AC-2 Account Management
NIST CSF
GV.RR-04 Cybersecurity is included in human resources practices.

Key terms

Personnel Lifecycle
The full span of an employee's relationship with an organization, encompassing onboarding, role transitions, and offboarding, each of which carries distinct cybersecurity implications.
Onboarding
The process of integrating a new employee into an organization, including provisioning system access, assigning permissions, and providing security awareness training.
Offboarding
The process of revoking a departing or transitioning employee's system access and decommissioning their accounts to prevent unauthorized access.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.
Identity and Access Management
IAM
A framework of policies and technologies that ensures the right users have appropriate access to resources.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.

Topics

Personnel Lifecycle Onboarding Offboarding Least Privilege Access Management

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →