I.T. Onboarding and Offboarding: When Employees Come and Go
The two most consequential I.T. events in any small business’s regular operations — and the ones most commonly handled by improvisation.
Every time someone joins or leaves your business, a sequence of I.T. tasks needs to happen. Done well, the new employee is productive on day one and the departing employee’s access is cleanly cut. Done poorly, you have one of two problems: a new hire wasting their first week chasing missing access, or a former employee with ongoing access to systems they shouldn’t have.
Most small businesses handle both events through improvisation — someone in the office or in I.T. does what they remember to do, in whatever order makes sense at the time, with no checklist and no verification.
This is what a real onboarding and offboarding process looks like, and why getting it right matters more than most owners realize.
I.T. ONBOARDING & OFFBOARDING
- Why This Process Matters
- The Onboarding Checklist
- The First-Day Experience
- The Offboarding Checklist
- The Security Dimension
- Building a Repeatable Process
Why This Process Matters
Onboarding and offboarding are not just I.T. housekeeping. They are direct contributors to two things:
- Productivity: a new employee who waits days for access burns a meaningful portion of their first week and starts behind
- Security: a former employee with ongoing access — even by accident — is one of the most common preventable risks in SMB cybersecurity
The cost of getting these processes wrong is largely invisible. Nobody invoices you for the new hire’s lost first week. Nobody alerts you when the former employee’s account stays active for months. Both costs are real.
The Onboarding Checklist
A complete I.T. onboarding for a new employee includes, at minimum:
- Microsoft 365 account creation with appropriate licenses
- Email setup with correct display name and signature
- Group memberships for relevant teams, shared mailboxes, and document libraries
- MFA configured on first sign-in
- Password manager account provisioned
- Workstation or laptop prepared with required software and security tooling
- Phone or extension configured if applicable
- Access to industry-specific applications
- Documented training plan for security awareness and software basics
- A complete record of every system the new employee has access to
Every item should be checked off by someone. The checklist itself should exist before the first new hire, not be invented during the first one.
The First-Day Experience
The new hire’s first hour with their computer should not be an obstacle course. They should sign in successfully, see their email working, access the systems they need, and be able to ask for help through a documented channel.
This is achievable with thirty minutes of preparation the day before. It is also commonly skipped in favour of “we’ll figure it out as we go,” which produces a frustrating first day for the new hire and a series of small interruptions to whoever’s helping.
A good first-day experience signals to the new employee that the business is run professionally. A bad one signals the opposite. The investment in getting it right pays back in retention as well as productivity.
The Offboarding Checklist
When an employee leaves — whether voluntarily, involuntarily, or through retirement — the I.T. offboarding includes:
- Email account disabled or converted to a shared mailbox as appropriate
- All sign-in sessions terminated across cloud applications
- Authentication tokens revoked
- Password manager access removed
- Group memberships and shared resource access revoked
- Mobile device management — corporate data wiped from any personal devices
- Workstation or laptop returned, wiped, and re-deployed or retired
- Any unique credentials (vendor accounts, social media, banking platforms) transferred
- Documentation of what was removed, when, and by whom
The timing matters. For voluntary departures, much of this happens on the last day. For involuntary departures, it happens before the conversation, not after.
The Security Dimension
Former employees with ongoing access are one of the most under-discussed risks in SMB security. The pattern: someone leaves, their email gets disabled, but their access to a CRM, a shared cloud storage account, a vendor portal, or a personal-use license persists. Sometimes for years.
Most of these orphaned access cases are benign — the former employee never logs back in, and nothing happens. But “most are benign” is not a security posture. The cases that aren’t benign include disgruntled former employees, accounts compromised through old credentials, and audit findings that affect cyber insurance and compliance.
The defense is straightforward: a complete offboarding checklist, followed every time, with verification.
Building a Repeatable Process
The right approach to onboarding and offboarding is not heroics. It’s a documented, repeatable process that doesn’t depend on remembering everything every time:
- A written checklist that lives somewhere everyone can find it
- A clear owner for the process — someone responsible for completion
- Integration with HR so I.T. is notified of new hires and departures with appropriate lead time
- Periodic review — once or twice a year, verify the checklist matches current systems and that orphaned accounts haven’t accumulated
A managed I.T. relationship makes this dramatically easier — the checklist exists, the owner exists, and the verification happens whether anyone in the business is paying close attention or not.
If your last few new hires had a frustrating first day, or you can’t immediately produce a list of former employees and confirm none of them still have access — that’s the gap.