IT onboarding and offboarding checklist for SMEs
Somewhere between fifteen and fifty employees, onboarding stops being something one person remembers and starts being something the company gets wrong. A new hire waits two days for a laptop. A leaver keeps mailbox access for a month. A promoted colleague accumulates the permissions of every role they ever held.
None of this is a tooling problem. It is a process that was never written down.
Day minus five: before they arrive
- Role defined, and with it the standard access package for that role.
- Device ordered, enrolled in management before it ships, encrypted by policy.
- Accounts created but not yet enabled, licences assigned.
- Manager sends the first-day plan; IT confirms readiness.
The single biggest improvement most SMEs can make is deciding access by role, not by copying the permissions of whoever sits nearby. Copy-a-colleague is how privilege sprawl starts.
Day one
- Sign-in with a guided first-run: MFA enrolment, password set, device check.
- Access to exactly the systems the role package specifies.
- A short orientation on how to report a security concern — a five-minute conversation that pays for itself.
Movers: the step everyone skips
When someone changes role, access should be replaced, not extended.
- New role package applied.
- Old role package removed, with the removal recorded.
- Manager confirms the change.
If you only implement one improvement from this article, make it this one. Movers are where the audit findings live.
Leavers: hours, not weeks
- Sign-in blocked and sessions revoked immediately at the agreed time.
- Mailbox and files delegated to the manager, with a retention decision.
- Licences reclaimed; device return tracked.
- Third-party and SaaS accounts — the ones outside your main tenant — closed too.
- The whole sequence logged with timestamps.
That last line matters. An offboarding you cannot evidence did not happen, as far as an auditor is concerned.
Make it a workflow, not a memory
The version of this checklist that survives contact with a busy week is the automated one: triggered by HR, executed against your identity and device platforms, with exceptions raised to a human rather than the whole process depending on one.
That is what we mean by operational automation — the routine work happens the same way every time, and your team only sees the cases that need judgement.