What it is
A written list of everything an employee receives based on their role, applied on arrival, revised when the role changes, and run in reverse on departure.
IT support
A poorly prepared arrival costs a new employee a full day of work. A poorly closed departure leaves an access open for months. This page describes the IT onboarding and offboarding procedure we set up in a small business, what it contains, and what it prevents.
Onboarding and offboarding are the same process, run in both directions. What is given must be able to be taken back, and what has not been written down somewhere will never be removed. With a written list per role, the new employee is working within the first hour, and a departed person’s account is closed the same day, with proof.
In brief
Onboarding and offboarding are the same process, run in both directions. What is given must be able to be taken back, and what has not been written down somewhere will never be removed.
A written list of everything an employee receives based on their role, applied on arrival, revised when the role changes, and run in reverse on departure.
Small businesses that hire, replace or lose staff several times a year, and those whose accounts are created as requests come in, with no register.
The new employee is working within the first hour, and the account of a person who has left is closed the same day, with written proof that it has been done.
The context
In most small businesses, an account is created because someone asked for it, often the day before the arrival. Rights are copied from a colleague in a similar role, an access is added mid-year to help someone out, then another for a project. Nobody keeps a register, because nobody was tasked with it.
On departure, what gets closed is what is remembered: the Windows session and the email. What stays open are the accesses that were forgotten because they were never written down anywhere. The accounting software, the vendor portal, the phone system account, the remote access created during the pandemic, the file share with a client, the licence paid every month for a person who no longer works here.
A cybersecurity audit almost always finds these accounts. They are a risk because nobody is monitoring them, and an expense because they keep being billed. The fix is not a tool: it is a list, kept up to date, and a person responsible for applying it.
Onboarding
The goal is that on arrival, the person sits down and works. Everything that follows is prepared before the start date, based on the role rather than on the name of a colleague.
Offboarding
Offboarding runs in reverse of onboarding, in a defined order, and it must leave a written trace. Here are the six areas, including the ones most often forgotten.
What we do. The account is blocked and open sessions are revoked, on every device. Changing the password is not enough: a session already open on a phone keeps working.
Why. This is the action that must happen at the agreed time, not the next morning.
What we do. The mailbox is kept according to the rule the organization decided, and incoming messages are redirected to the person taking over the file, with an auto-reply if needed.
Why. Deleting a mailbox too quickly loses ongoing files and evidence that may be required later.
What we do. The contents of the personal cloud space are transferred to the manager before the account is deleted, and work documents are moved back into team spaces.
Why. Without that transfer, corporate documents disappear with the account, often without anyone noticing for months.
What we do. Laptop, phone, screens, access keys and tokens are collected and logged in the register. The device is wiped and reset, or only the professional part is wiped if it is a personal device.
Why. An unreturned device stays an access point to the company’s data and a paid asset no one is using.
What we do. Vendor portals, business software, phone system, social media accounts, remote accesses, shares with clients: everything the register ties to the person is removed.
Why. This is where orphan accesses live, because they are not in the main portal.
What we do. Licences are released or reassigned, and a written record logs what was closed, when, and by whom.
Why. That record is what lets you answer an insurer, a client or the Commission d’accès à l’information if the question comes up later.
What it prevents
These situations are routine in an organization without a procedure, and almost all of them stop as soon as the list exists and someone is responsible for it.
Where this sits
Employee onboarding is part of our managed IT services: workstations prepared, accounts created, access revoked on departure. It goes hand in hand with secure remote work and with a three-year IT plan that budgets hardware replacement instead of improvising it.
This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it. See Trois-Rivières, the Mauricie, Montreal and Quebec City.
Further reading: the IT onboarding checklist, managing your passwords and creating a signature in Outlook.
Questions and answers
We build the list of roles, what each one receives, and who does what on arrival and departure. Then we apply it to every staff change, with a written record every time.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.