Home » Managed IT » Onboarding & Offboarding

Managed IT — Onboarding & Offboarding

Employee IT onboarding and offboarding

New hires productive on day one, departures shut down cleanly the same day, and periodic access reviews in between — the user lifecycle run as the security control it actually is.

The riskiest account is the one nobody turned off

Offboarding gets treated as paperwork, and that is exactly backwards. A departed employee’s live account is standing access to email, files, and client data, held by someone with no remaining accountability to you — and orphaned accounts and lingering third-party logins are among the first things a security assessment finds, because they are among the first things an attacker looks for.

Onboarding carries the same weight in the other direction. A new hire staring at a dead laptop for three days learns your firm’s real standards in week one. And access granted sloppily at the start — “just copy what the last person had” — is how privilege sprawl becomes everyone’s baseline. Both halves are included in fully managed IT and run as a defined lane in co-managed engagements.

How a start works

The goal is a person who can work at 9 a.m. on day one — with exactly the access their role requires and nothing extra.

  1. Structured request

    The manager submits role, start date, and needs through the help desk — a defined form, not an email thread that forgets the monitor.

  2. Role-based access

    Access is granted from a template you approved for each role — least privilege by default. “Same as Susan” is not a template; it is how permissions metastasize.

  3. Device from the baseline

    Hardware provisioned from your hardened standard build, enrolled in management before it ships — including straight to a remote hire’s door.

  4. Identity ready before day one

    Accounts created, MFA enrolled at first sign-in, credentials delivered securely — not on a sticky note waiting on the keyboard.

  5. Day-one verification

    We confirm sign-in, email, applications, and printing work that morning, while the fix is still cheap and the first impression is still forming.

What a clean termination includes

Executed from a checklist agreed with you in advance — because the worst time to design an offboarding process is during one.

  • Timed disablement

    Accounts disabled at the moment you choose — including simultaneously with the termination conversation for involuntary exits, coordinated quietly with HR beforehand.

  • Sessions and tokens revoked

    Disabling a password is not enough. Active sessions, app passwords, and OAuth grants are revoked so that signed out actually means signed out.

  • Third-party access closed

    Line-of-business apps, SaaS tools, vendor portals — every system in the leaver’s access record gets closed. Which is why the access record has to exist before you need it.

  • Shared credentials rotated

    Anything the person knew — Wi-Fi keys, shared logins, service accounts — is rotated as a checklist step, not remembered three weeks later.

  • Mail and files handled deliberately

    Mailbox and file delegation to the manager under your retention policy: preserved and accessible, neither orphaned nor hastily deleted.

  • Devices recovered and wiped

    Hardware retrieved — including shipped back from remote staff — wiped to standard, and returned to the asset pool with the registry updated.

  • A written completion record

    A time-stamped record of every step — what an auditor, an insurer, or opposing counsel will actually ask to see.

Access reviews: the part everyone skips

Between the start and the exit, access drifts. People change roles and keep the old permissions; temporary grants become permanent because nothing expires them. We run periodic access reviews — who has access to what, certified by the owner of each system — and produce the record.

For many of our clients this is not optional diligence. NYDFS Part 500 requires covered entities to limit access privileges and review them periodically, the FTC Safeguards Rule expects access controls among its required elements, and law firms see the same questions in outside-counsel security questionnaires. An access review that happens only when someone asks for it is not a control; it is an alibi.

Common questions

How fast can you shut someone's access off?

At the time you set — for sensitive exits, during the termination meeting itself. The speed comes from preparation: because the access record already exists, the checklist runs instead of an investigation starting.

Can starts and exits be driven from our HR workflow?

Yes — requests can flow from your HR system or PEO so IT is never the last to know. The dangerous pattern is the one where offboarding depends on somebody remembering to email IT.

What about contractors and temps?

Time-boxed by default: access carries an expiration date from day one, and extensions are a deliberate decision rather than the absence of one.

We're a small firm. Is this overkill?

The checklist scales down; the risk does not. A ten-person firm is one ex-employee with a live login away from the same incident as a hundred-person firm — with less cushion to absorb it.

Is this a separate service?

No — it is part of every managed IT engagement, tied into support, device management, and identity controls under managed security.

Start people well. End access cleanly.

Ask us to walk through the termination checklist — the least glamorous document we will ever show you, and the most persuasive.