Managed IT — Onboarding & Offboarding
Employee IT onboarding and offboarding
New hires productive on day one, departures shut down cleanly the same day, and periodic access reviews in between — the user lifecycle run as the security control it actually is.
The riskiest account is the one nobody turned off
Offboarding gets treated as paperwork, and that is exactly backwards. A departed employee’s live account is standing access to email, files, and client data, held by someone with no remaining accountability to you — and orphaned accounts and lingering third-party logins are among the first things a security assessment finds, because they are among the first things an attacker looks for.
Onboarding carries the same weight in the other direction. A new hire staring at a dead laptop for three days learns your firm’s real standards in week one. And access granted sloppily at the start — “just copy what the last person had” — is how privilege sprawl becomes everyone’s baseline. Both halves are included in fully managed IT and run as a defined lane in co-managed engagements.
How a start works
The goal is a person who can work at 9 a.m. on day one — with exactly the access their role requires and nothing extra.
Structured request
The manager submits role, start date, and needs through the help desk — a defined form, not an email thread that forgets the monitor.
Role-based access
Access is granted from a template you approved for each role — least privilege by default. “Same as Susan” is not a template; it is how permissions metastasize.
Device from the baseline
Hardware provisioned from your hardened standard build, enrolled in management before it ships — including straight to a remote hire’s door.
Identity ready before day one
Accounts created, MFA enrolled at first sign-in, credentials delivered securely — not on a sticky note waiting on the keyboard.
Day-one verification
We confirm sign-in, email, applications, and printing work that morning, while the fix is still cheap and the first impression is still forming.
What a clean termination includes
Executed from a checklist agreed with you in advance — because the worst time to design an offboarding process is during one.
Timed disablement
Accounts disabled at the moment you choose — including simultaneously with the termination conversation for involuntary exits, coordinated quietly with HR beforehand.
Sessions and tokens revoked
Disabling a password is not enough. Active sessions, app passwords, and OAuth grants are revoked so that signed out actually means signed out.
Third-party access closed
Line-of-business apps, SaaS tools, vendor portals — every system in the leaver’s access record gets closed. Which is why the access record has to exist before you need it.
Shared credentials rotated
Anything the person knew — Wi-Fi keys, shared logins, service accounts — is rotated as a checklist step, not remembered three weeks later.
Mail and files handled deliberately
Mailbox and file delegation to the manager under your retention policy: preserved and accessible, neither orphaned nor hastily deleted.
Devices recovered and wiped
Hardware retrieved — including shipped back from remote staff — wiped to standard, and returned to the asset pool with the registry updated.
A written completion record
A time-stamped record of every step — what an auditor, an insurer, or opposing counsel will actually ask to see.
Access reviews: the part everyone skips
Between the start and the exit, access drifts. People change roles and keep the old permissions; temporary grants become permanent because nothing expires them. We run periodic access reviews — who has access to what, certified by the owner of each system — and produce the record.
For many of our clients this is not optional diligence. NYDFS Part 500 requires covered entities to limit access privileges and review them periodically, the FTC Safeguards Rule expects access controls among its required elements, and law firms see the same questions in outside-counsel security questionnaires. An access review that happens only when someone asks for it is not a control; it is an alibi.
Common questions
How fast can you shut someone's access off?
At the time you set — for sensitive exits, during the termination meeting itself. The speed comes from preparation: because the access record already exists, the checklist runs instead of an investigation starting.
Can starts and exits be driven from our HR workflow?
Yes — requests can flow from your HR system or PEO so IT is never the last to know. The dangerous pattern is the one where offboarding depends on somebody remembering to email IT.
What about contractors and temps?
Time-boxed by default: access carries an expiration date from day one, and extensions are a deliberate decision rather than the absence of one.
We're a small firm. Is this overkill?
The checklist scales down; the risk does not. A ten-person firm is one ex-employee with a live login away from the same incident as a hundred-person firm — with less cushion to absorb it.
Is this a separate service?
No — it is part of every managed IT engagement, tied into support, device management, and identity controls under managed security.
Start people well. End access cleanly.
Ask us to walk through the termination checklist — the least glamorous document we will ever show you, and the most persuasive.