Guide

Onboarding and offboarding staff securely

Joiners need the right access on day one. Leavers need to lose it on their last day. A simple process gets both right every time.

By the Astrizon team3 min read

New employee receiving a laptop

Few moments matter more for IT than when people join and leave. A new starter without working access wastes their first week. A leaver who keeps access to email, files or customer systems is a serious security risk. Both problems are common, and both are easy to prevent with a simple, repeatable process.

Onboarding: ready on day one

  • Agree the start date, role and manager as early as possible, so IT has time to prepare.
  • Create accounts based on a standard role template, rather than copying a colleague's access.
  • Prepare and configure the laptop and phone in advance, with security software and updates applied.
  • Set up multi-factor login during the first session, with someone on hand to help.
  • Share a short welcome guide covering systems, support contacts and security basics.

Least privilege from the start

Give people the access they need for their role and nothing more. Role templates make this easy and consistent. When someone needs extra access, grant it through a simple request that is approved and recorded.

Role changes count too

When people move teams or get promoted, they often gain new access but keep the old. Over time this access builds up, increasing risk. Review access whenever someone changes role, and remove what they no longer need.

Offboarding: closed on the last day

  • Disable accounts at the agreed time, not weeks later.
  • Revoke access to shared passwords, cloud apps and remote access tools.
  • Transfer ownership of files, mailboxes and shared documents to a manager.
  • Collect laptops, phones, security keys and access cards.
  • Remove company data from personal devices where these were used.
  • Update emergency contact lists and any supplier portals the person managed.

Plan for urgent departures

Sometimes people leave unexpectedly. Agree in advance who can trigger an immediate offboarding, and make sure IT can disable all access quickly, ideally from a single central identity system.

Use a checklist and a single source of truth

Keep joiner, mover and leaver checklists that HR and IT both follow. Better still, connect your HR system to your identity system so that changes flow automatically. Record every step, so you can show auditors and clients that access is controlled.

Review regularly

Once a quarter, ask managers to confirm who in their team should have access to key systems. These reviews regularly uncover forgotten accounts, contractors who left long ago and access that was never removed.

Contractors and temporary staff

Contractors, interns and agency staff often slip through formal processes. Give them accounts with an expiry date set from the start, limit their access to what their project needs, and assign each one a named sponsor who confirms when the work ends. Avoid shared logins, because they make it impossible to see who did what or to remove one person's access without disrupting everyone else. The same checklists should apply to them as to permanent employees.

Why it matters

A smooth first day shows new people that the business is well run. A clean exit protects your data, your clients and your reputation.

Our Managed IT Services include standard onboarding and offboarding, so every joiner and leaver is handled consistently.

Keep reading

More from the blog

All articles

Get answers to your questions

Tell us what you are working on and the right person from our team will get back to you.

How we use your information

  • What we collect: your name, email, organisation, phone number, region, enquiry type and message, plus your IP address and browser details for security.
  • Why: only to reply to your enquiry and discuss our services, and to protect this form from spam.
  • How long: up to 24 months after our last contact.
  • Your choices: you can withdraw consent, or access, correct or erase your data at any time, and complain to the Data Protection Board of India.

Full details are in our privacy policy.