All articles

IT onboarding and offboarding checklist for SMEs

2 min readWorkplace OperationsAutomationOnboarding

Somewhere between fifteen and fifty employees, onboarding stops being something one person remembers and starts being something the company gets wrong. A new hire waits two days for a laptop. A leaver keeps mailbox access for a month. A promoted colleague accumulates the permissions of every role they ever held.

None of this is a tooling problem. It is a process that was never written down.

Day minus five: before they arrive

  • Role defined, and with it the standard access package for that role.
  • Device ordered, enrolled in management before it ships, encrypted by policy.
  • Accounts created but not yet enabled, licences assigned.
  • Manager sends the first-day plan; IT confirms readiness.

The single biggest improvement most SMEs can make is deciding access by role, not by copying the permissions of whoever sits nearby. Copy-a-colleague is how privilege sprawl starts.

Day one

  • Sign-in with a guided first-run: MFA enrolment, password set, device check.
  • Access to exactly the systems the role package specifies.
  • A short orientation on how to report a security concern — a five-minute conversation that pays for itself.

Movers: the step everyone skips

When someone changes role, access should be replaced, not extended.

  • New role package applied.
  • Old role package removed, with the removal recorded.
  • Manager confirms the change.

If you only implement one improvement from this article, make it this one. Movers are where the audit findings live.

Leavers: hours, not weeks

  • Sign-in blocked and sessions revoked immediately at the agreed time.
  • Mailbox and files delegated to the manager, with a retention decision.
  • Licences reclaimed; device return tracked.
  • Third-party and SaaS accounts — the ones outside your main tenant — closed too.
  • The whole sequence logged with timestamps.

That last line matters. An offboarding you cannot evidence did not happen, as far as an auditor is concerned.

Make it a workflow, not a memory

The version of this checklist that survives contact with a busy week is the automated one: triggered by HR, executed against your identity and device platforms, with exceptions raised to a human rather than the whole process depending on one.

That is what we mean by operational automation — the routine work happens the same way every time, and your team only sees the cases that need judgement.