Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

IT support

Onboarding and offboarding an employee, on the IT side

A poorly prepared arrival costs a new employee a full day of work. A poorly closed departure leaves an access open for months. This page describes the IT onboarding and offboarding procedure we set up in a small business, what it contains, and what it prevents.

Onboarding and offboarding are the same process, run in both directions. What is given must be able to be taken back, and what has not been written down somewhere will never be removed. With a written list per role, the new employee is working within the first hour, and a departed person’s account is closed the same day, with proof.

Setting up a new employee’s workstation with keyboard, tablet and secured cloud access

In brief

Onboarding and offboarding in three points

Onboarding and offboarding are the same process, run in both directions. What is given must be able to be taken back, and what has not been written down somewhere will never be removed.

What it is

A written list of everything an employee receives based on their role, applied on arrival, revised when the role changes, and run in reverse on departure.

Who it is for

Small businesses that hire, replace or lose staff several times a year, and those whose accounts are created as requests come in, with no register.

What it changes

The new employee is working within the first hour, and the account of a person who has left is closed the same day, with written proof that it has been done.

The context

Why orphan accesses pile up in a small business

In most small businesses, an account is created because someone asked for it, often the day before the arrival. Rights are copied from a colleague in a similar role, an access is added mid-year to help someone out, then another for a project. Nobody keeps a register, because nobody was tasked with it.

On departure, what gets closed is what is remembered: the Windows session and the email. What stays open are the accesses that were forgotten because they were never written down anywhere. The accounting software, the vendor portal, the phone system account, the remote access created during the pandemic, the file share with a client, the licence paid every month for a person who no longer works here.

Replacing an employee’s workstation and taking back IT equipment

A cybersecurity audit almost always finds these accounts. They are a risk because nobody is monitoring them, and an expense because they keep being billed. The fix is not a tool: it is a list, kept up to date, and a person responsible for applying it.

Onboarding

What happens before a new employee’s first day

The goal is that on arrival, the person sits down and works. Everything that follows is prepared before the start date, based on the role rather than on the name of a colleague.

  1. Receive the request with the right informationName, start date, position, manager, work location, required hardware and role template. The role triggers everything else: two people in the same position receive exactly the same setup, with no case-by-case discussion.
  2. Prepare the account and accessesCreation of the account, the email address, the groups and shares that fit the role, assignment of the right licence, activation of multi-factor authentication, entry in the access register.
  3. Prepare the deviceWorkstation enrolled in central management, disk encryption, protection installed, role-specific software deployed, printers and peripherals configured, device tested with the real account before delivery.
  4. Deliver and welcomeHandover of the hardware, guided first sign-in, second-factor configuration, explanation of how support works and how to ask for help. It is also when to pass on the internal rules on passwords and personal devices.
  5. Check back after a few daysA short follow-up to catch what is still missing: access to a business application, a network share, an approval right. These gaps always exist, and fixing them right away keeps them from becoming permanent exceptions.

Offboarding

What needs to be closed when an employee leaves

Offboarding runs in reverse of onboarding, in a defined order, and it must leave a written trace. Here are the six areas, including the ones most often forgotten.

Cut the access, not just the password

What we do. The account is blocked and open sessions are revoked, on every device. Changing the password is not enough: a session already open on a phone keeps working.

Why. This is the action that must happen at the agreed time, not the next morning.

Redirect and keep the email

What we do. The mailbox is kept according to the rule the organization decided, and incoming messages are redirected to the person taking over the file, with an auto-reply if needed.

Why. Deleting a mailbox too quickly loses ongoing files and evidence that may be required later.

Recover the person’s files

What we do. The contents of the personal cloud space are transferred to the manager before the account is deleted, and work documents are moved back into team spaces.

Why. Without that transfer, corporate documents disappear with the account, often without anyone noticing for months.

Take back the hardware

What we do. Laptop, phone, screens, access keys and tokens are collected and logged in the register. The device is wiped and reset, or only the professional part is wiped if it is a personal device.

Why. An unreturned device stays an access point to the company’s data and a paid asset no one is using.

Close external accesses

What we do. Vendor portals, business software, phone system, social media accounts, remote accesses, shares with clients: everything the register ties to the person is removed.

Why. This is where orphan accesses live, because they are not in the main portal.

Reclaim licences and write the record

What we do. Licences are released or reassigned, and a written record logs what was closed, when, and by whom.

Why. That record is what lets you answer an insurer, a client or the Commission d’accès à l’information if the question comes up later.

What it prevents

What a written procedure makes disappear

These situations are routine in an organization without a procedure, and almost all of them stop as soon as the list exists and someone is responsible for it.

  • A new employee spending their first day waiting for an account or a computer
  • Rights copied from a colleague, giving a person accesses that have nothing to do with their role
  • A former employee’s account still active, discovered months later during an audit
  • Licences paid every month for people who no longer work at the organization
  • Documents lost with the deletion of a personal cloud account

Where this sits

Part of a managed engagement

Employee onboarding is part of our managed IT services: workstations prepared, accounts created, access revoked on departure. It goes hand in hand with secure remote work and with a three-year IT plan that budgets hardware replacement instead of improvising it.

This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it. See Trois-Rivières, the Mauricie, Montreal and Quebec City.

  • A laptop never collected, still connected to the company’s data
  • No written proof that a person’s accesses were properly closed

Further reading: the IT onboarding checklist, managing your passwords and creating a signature in Outlook.

Questions and answers

Frequently asked questions about onboarding and offboarding

How much notice do we need to give to prepare an arrival?
With hardware on hand, 5 business days is enough. If the equipment has to be ordered, count 10 to 15 business days. The deciding factor is hardware lead time: an account and its accesses can be prepared quickly, an ordered laptop does not materialize the day before.
What do we do during a conflicted departure?
Closing the accesses is planned in advance with leadership and executed at a precise time, often during the exit meeting. Open sessions are revoked, devices are locked remotely, and the written record is produced the same day. This scenario must be prepared before it is needed, not improvised the morning of.
Should we delete the mailbox of a departed employee?
Not immediately. The usual practice is to block access, redirect incoming messages to the person who takes over the file, then keep the mailbox for a period decided by the organization before closing it. Deleting right away loses ongoing files and items that may be required later.
Can we recover the Microsoft 365 licence of someone who has left?
Yes. The licence is released and reassigned to the next person, or removed from the subscription. It is one of the easiest savings in a small business: licences paid for former employees pile up quietly, because nothing flags them. See our Microsoft 365 management.
How do we handle an employee who moves to a new role internally?
Like a departure followed by an arrival. You remove the accesses of the previous role before adding those of the new one, rather than stacking them. A person who changes roles three times in the same organization would otherwise end up with more rights than leadership, without anyone deciding it.
Does this apply to contractors and interns?
Yes, and this is often where the problem is largest, because the end date is known in advance yet rarely applied. A time-limited access that expires on its own on the scheduled date solves most of these cases.
How can we tell how many orphan accesses we already have?
Through an inventory of accounts and accesses. It is one of the six areas covered by our cybersecurity audit. Once the cleanup is done, the onboarding and offboarding procedure keeps the situation from coming back. See also our pages on secure remote work and our managed IT services.

Set the procedure up at your organization

We build the list of roles, what each one receives, and who does what on arrival and departure. Then we apply it to every staff change, with a written record every time.