The short answer
What should the process cover?
Onboarding should document the employee, start date, manager, role, computer, email, productivity suite, applications, shared files, VPN, MFA, phone or extension, printers, security groups, distribution lists, software licenses, equipment, approvals, and completion sign-off.
Offboarding should document the departure date and timing, account disablement, session revocation where appropriate, VPN and application removal, MFA or token handling, shared-access review, email and file ownership transfer, equipment return, license recovery, authorized remote wipe when applicable, required credential changes, and final verification that access has been removed.
Why onboarding and offboarding should be repeatable
Small businesses often divide employee setup among a manager, office administrator, outside IT provider, and application owners. Without one record, each person may complete their part while assuming someone else handled email, a shared drive, VPN, phone, or equipment.
A repeatable process connects the request, approval, action, and verification. It also creates a useful history when access needs to be explained later. Keep the document focused on IT systems, accounts, and equipment; employment decisions and legal requirements belong with the organization’s HR and legal processes.
Start with a complete onboarding request
Begin before the employee’s first day. Record the employee’s preferred display name, start date, manager, role, department, work location, employment or contractor classification as supplied by the business, and the date equipment and access must be ready.
Access should be based on an approved role or a clearly identified comparison user rather than a vague request to give the new employee everything another person has. The manager and application owners should approve sensitive access before IT assigns it.
- Employee name, start date, manager, role, department, location, and requestor
- Required completion date, working arrangement, special equipment, and accessibility needs provided by the business
- Approved role, access profile, comparison user, exceptions, and approving manager
- Assigned technician or provider, status, completion date, and unresolved items
Create accounts, email, and application access
Create the primary identity first, then connect the services that depend on it. Record the email address, Microsoft 365 or Google Workspace license where applicable, directory groups, shared mailboxes, distribution lists, shared drives, file permissions, line-of-business applications, printer access, and phone or extension.
Document the role and ownership of each account without storing the employee’s password. Temporary credentials should be delivered through an approved secure method and changed as required. MFA enrollment should be completed with the employee, and recovery should be owned by the business through an appropriate secure process.
- Email, productivity suite, directory account, display name, aliases, and assigned license
- Applications, SaaS services, shared mailboxes, distribution lists, and security groups
- Shared-drive and file permissions, department resources, printer access, and collaboration tools
- VPN, remote access, MFA enrollment, device compliance, and approved support method
- Phone, extension, voicemail, mobile application, or company phone where applicable
Assign, configure, and hand off equipment
Connect every issued item to the asset inventory. Record the computer, dock, monitor, phone, charger, adapter, headset, keys, tokens, and other equipment provided. Include asset IDs, serial numbers, condition, location, accessories, and the person responsible for return.
Configuration should reflect the approved role: operating-system updates, encryption, endpoint management, security software, applications, printers, VPN, and backup or cloud-file configuration. Confirm that the user can sign in and reach the resources they need before marking the request complete.
- Computer and accessory asset IDs, serial numbers, condition, assignment, and location
- Operating system, updates, encryption, management enrollment, endpoint security, and naming
- Required software, licenses, browser configuration, printers, VPN, and shared resources
- Employee acknowledgement, acceptable-use or equipment receipt handled by the business, and IT completion sign-off
Instead of writing “laptop ready,” record the assigned asset, applications installed, groups applied, MFA enrollment completed, VPN verified, accessories issued, employee receipt, and any access still awaiting an application owner.
Coordinate offboarding timing and responsibility
The business should provide the departure date, effective access-removal time, manager, affected locations, and special instructions through its authorized process. IT should not guess whether access should end immediately, at the close of business, or after a planned transition.
Assign each system to a responsible person. The primary directory or email account may be handled centrally, while payroll, banking, CRM, vendor portals, social accounts, building access, and specialty applications may have separate owners.
- Employee, manager, departure date, effective time, requestor, approver, and assigned technician
- Known accounts, locations, devices, applications, shared resources, and external services
- Required preservation, ownership transfer, email handling, and customer or vendor continuity
- Exceptions, delayed removals, responsible owner, deadline, and final verifier
Disable accounts and remove active access
Disable or remove access according to the approved timing. Address the primary identity, email, productivity suite, VPN, remote desktop, applications, shared drives, administrative roles, cloud platforms, phone services, and third-party portals. Recover licenses that can be reassigned.
Where supported and appropriate, revoke active sessions, application tokens, mobile sessions, and remembered devices so an account is not merely blocked from the next password entry. Review shared accounts and change credentials only when the departing person actually knew or controlled them.
- Directory, email, Microsoft 365 or Google Workspace, VPN, and remote-access status
- Application, SaaS, shared-drive, security-group, distribution-list, and administrator removal
- Session, token, app-password, API access, and MFA method addressed where appropriate
- Shared-account exposure reviewed and credential changes assigned where genuinely required
- License recovery, support ownership, forwarding or delegation, and retention handled by approved owners
Transfer business information and recover equipment
Transfer ownership of business files, shared folders, mailboxes, calendars, cloud resources, automation, vendor accounts, documentation, and application data to the manager or designated owner. Avoid broadly copying personal or unrelated information; follow the business’s authorized process.
Record every returned device and accessory, its condition, date, recipient, and next action. An authorized remote wipe may be appropriate for a lost or company-owned remote device, but it should be approved, scoped, and documented. Do not imply permission to erase a personally owned device.
- File, mailbox, calendar, cloud resource, automation, and vendor-account ownership transferred
- Laptop, desktop, phone, tablet, token, charger, dock, monitor, keys, and accessories returned
- Condition, missing items, asset status, data preservation, wipe authorization, and reissue or disposal plan
- Software licenses, phone numbers, subscriptions, and support relationships recovered or reassigned
Complete final verification and preserve the record
A second person or responsible owner should review the checklist and verify that critical access is removed, ownership transfers are complete, equipment status is updated, licenses are recovered, and unresolved exceptions are visible. Do not close the record simply because the primary email account was disabled.
Keep the completed IT record according to the business’s retention practices, with sensitive details restricted appropriately. The record should show who requested, approved, completed, and verified each action without containing passwords, recovery codes, private keys, payment information, or other secrets.
Quality-control review
Common omissions and mistakes
- Starting onboarding on the employee’s first morning with no approved access profile or equipment plan
- Copying another employee’s permissions without confirming role differences and exceptions
- Marking setup complete before MFA, VPN, shared files, applications, printers, or equipment are verified
- Disabling email during offboarding while leaving VPN, SaaS, shared-drive, mobile, or administrator access active
- Failing to transfer ownership of business files, mailboxes, automations, or vendor accounts
- Changing every shared credential automatically rather than identifying which secrets were actually exposed
- Remotely wiping a device without confirming ownership, authorization, preservation needs, and scope
- Closing the request without final verification, license recovery, or asset-inventory updates
Make the process repeatable
Use a consistent documentation system.
Reusable onboarding and offboarding records give managers, office staff, internal IT, MSPs, and application owners a single process for requests, approvals, equipment, account access, removal, and verification. That consistency reduces missed steps without turning the checklist into a place to store secrets.
View Small Business IT Documentation Pack
Start a conversation