IT onboarding and offboarding checklist work is the least glamorous job on any technology team’s list, and the one that quietly decides how much risk a business carries. Nobody is promoted for provisioning a laptop on time. Nobody is thanked for disabling an account at five o’clock on a Friday. Yet the firms that get breached through a dormant login, or that lose a fortnight of a new hire’s productivity waiting for access, almost always share one root cause: joiners and leavers handled by memory rather than by process.
The pattern is remarkably consistent. HR runs a polished programme covering contracts, inductions and first-week introductions. IT finds out on the Monday morning. Somebody builds a laptop in a hurry, copies the permissions of whoever sits nearby, and the new starter inherits access to three systems they will never open and one they should never see. Eighteen months later that person resigns, their manager tells HR, HR tells payroll, and nobody tells IT at all. Without an IT onboarding and offboarding checklist, nothing in that chain catches the omission.
This guide is a complete IT onboarding and offboarding checklist for UK businesses of roughly ten to three hundred staff. It runs from offer acceptance through day one, the first month, internal role changes, the four hours after somebody resigns, the systems your identity provider cannot see, and the audit evidence that proves the whole thing actually ran. Firms already working with a managed IT services partner will recognise the sequencing; teams handling it in-house will find it most useful read as a set of triggers rather than a set of tasks.
One framing point before the detail. Treat joiners, movers and leavers as a single controlled process with an owner, a trigger and an evidence trail, not as three unrelated favours IT does for HR. Every item in the IT onboarding and offboarding checklist below assumes that framing, because a checklist nobody is accountable for is just a document.
Table of contents
- Why an IT onboarding and offboarding checklist beats the HR version
- Before day one: the IT onboarding and offboarding checklist starts at offer acceptance
- Day one on the IT onboarding and offboarding checklist: accounts and access
- The first 30 days: training, review and probation checkpoints
- Movers: the step most checklists forget entirely
- Offboarding: the first four hours after notice
- Beyond the obvious: SaaS, shadow IT and forgotten credentials
- Compliance and audit: proving the IT onboarding and offboarding checklist ran
- Automating the IT onboarding and offboarding checklist
- Putting the IT onboarding and offboarding checklist into practice
Why an IT onboarding and offboarding checklist beats the HR version
HR onboarding and IT onboarding look similar on a project plan and behave nothing alike. One is about welcoming a person. The other is about granting a set of keys to your business, and later taking every one of them back.
The joiners, movers and leavers problem in plain terms
Identity teams call it JML: joiners, movers and leavers. The joiner half gets attention because a new starter with no laptop complains loudly on day one. The leaver half gets neglected because a departed employee with a live account complains about nothing at all. The mover half — internal promotions and transfers — is usually not handled anywhere, which is why a good IT onboarding and offboarding checklist treats all three as the same process with different triggers.
What an unmanaged leaver actually costs
The obvious cost is licensing: unused seats for Microsoft 365, your CRM, your design tools and a dozen smaller subscriptions, billed monthly to nobody’s budget in particular. A hundred-person business typically finds between eight and fifteen per cent of its seats assigned to people who have left. The less obvious cost is the security exposure. A live account belonging to someone with no reason to log in is the single most attractive target in your estate, because nobody notices unusual behaviour on it.
Where the process usually breaks
It breaks at the handover between systems, not inside them. HR knows the leave date but has no way to act on it. IT can act but does not know. The manager knows both and assumes somebody else is handling it. Add a notice period served on garden leave, a contractor whose end date moves twice, and a resignation over a bank holiday, and the gaps become predictable rather than unlucky. An IT onboarding and offboarding checklist exists precisely to make those handovers explicit.
Who owns the checklist
One named person owns the process end to end, and it is not the line manager. They need the authority to refuse a start date when nothing has been requested and the diary time to run monthly reviews. Where there is no internal IT lead, buy the role in explicitly. An IT onboarding and offboarding checklist without a single accountable owner quietly becomes four partial checklists held by four people who each assume the others are covering the rest.
Before day one: the IT onboarding and offboarding checklist starts at offer acceptance
The most expensive onboarding failures are all lead-time failures. They happen because the request arrived on the Thursday before a Monday start, not because anybody did their job badly.
The trigger that starts everything
The trigger is offer acceptance, not the start date and certainly not the first day. The moment a signed contract comes back, HR should raise a single request carrying the start date, the job title, the line manager, the location and the working pattern. Everything else in the IT onboarding and offboarding checklist derives from those five fields. A request form with free-text “please set up a new user” is not a trigger; it is the beginning of a conversation that will take three days.
Role-based access profiles beat copying a colleague
“Copy Sarah’s access” is the most common instruction in IT and the most damaging. Sarah has been here six years, covered two maternity leaves and helped with a system migration, and her permissions reflect all of it. Define a small number of role profiles instead — finance, sales, operations, engineering, contractor — each listing the applications, groups and data a person in that role receives by default. Ten profiles cover most businesses, and anything outside them becomes a deliberate exception with an approver, which is exactly the behaviour you want.
Hardware lead times and the build queue
Laptops are not always available at short notice, and a specified machine with a docking station and a second monitor can take two to four weeks. Hold a small buffer of pre-built stock sized to your hiring rate, and track every device against a person in a register. Businesses running proper IT asset management can answer “who has that laptop” in seconds; everyone else runs a spreadsheet that was accurate last quarter. Hardware sits early on the IT onboarding and offboarding checklist for exactly this reason.
Licences, seats and the cost of guessing
Check licence availability at the point of request rather than at the point of provisioning. Some subscriptions add a seat instantly, some require an annual commitment change, and a few need a purchase order that takes a week. Recording licence type against each role profile turns this into a lookup rather than an investigation, and it gives finance a headcount-linked forecast instead of a surprise. Licence checks belong in the request stage of the IT onboarding and offboarding checklist, not the provisioning stage.
The pre-start security baseline
Before the account is handed over, it should already have multi-factor authentication enforced, conditional access applied, disk encryption on, endpoint protection reporting and the correct data retention policy attached. Doing this at build time costs minutes. Retrofitting it across a hundred devices costs a project. The pre-start block of the IT onboarding and offboarding checklist is where security posture is genuinely decided.
Day one on the IT onboarding and offboarding checklist: accounts and access
Day one is a test the business either passes or fails within an hour, and staff remember the result for a surprisingly long time. It is also the moment least-privilege is easiest to enforce, because nobody has accumulated anything yet.
Identity first, everything else after
Create the identity in one authoritative directory and let every other system consume it through single sign-on. A user account that exists independently in six applications is six accounts to find later, and the leaver half of your process will miss at least one. Where single sign-on is genuinely unavailable, record that application on a manual list attached to the IT onboarding and offboarding checklist, because it will not disable itself.
Device enrolment and the state a laptop should arrive in
A laptop should arrive enrolled, encrypted, patched, named to a convention and carrying the applications the role profile specifies. The new starter signs in and finds their email, files and printers already configured. Where device management is properly deployed this is the default outcome rather than an achievement, and the same tooling later gives you a remote wipe you can rely on. The NCSC’s device security guidance is the sensible baseline for what that build should enforce.
Multi-factor authentication before the first login
Register MFA during handover, in person or on a supervised video call, and never by emailing a setup link to an unverified address. The first login is the only moment you can be reasonably certain the person typing is the person you hired. Attackers know this window exists, and enrolment fraud against new starters is now a routine part of business email compromise. Treat supervised MFA registration as a non-negotiable line on the IT onboarding and offboarding checklist rather than a self-service convenience.
Least privilege, groups and shared drives
Grant access through groups tied to role profiles, never to individuals directly, and never at the root of a file share. The principle of least privilege is easy to state and hard to retrofit, which is why the IT onboarding and offboarding checklist applies it at the only cheap moment. Direct individual permissions are invisible to every audit tool you own and they are precisely what survives a leaver process.
Telephony, and the small things staff notice
Extension numbers, call groups, shared mailboxes, distribution lists, the intranet profile and the door fob all sit outside the identity platform in most businesses. None of them are technically difficult and all of them are noticed immediately when missing. Put them on the day-one page of the IT onboarding and offboarding checklist so they are somebody’s job rather than everybody’s assumption.
The first 30 days: training, review and probation checkpoints
Onboarding does not finish when the laptop works. The first month is where good habits are set and where the access you granted in a hurry gets a second look.
Security awareness training that changes behaviour
Deliver awareness training in the first week, while attention is high and habits are unformed. Cover phishing, the specific ways your finance approvals can be socially engineered, password manager use, and how to report something suspicious without embarrassment. Effective cybersecurity training is short, repeated and specific to the business rather than an annual ninety-minute video watched at 1.5x speed with the sound off. Schedule it from the IT onboarding and offboarding checklist so it happens on a date rather than eventually.
The 30-day access review
Thirty days in, review what the new starter actually uses against what they were granted. This single step catches most of the drift a role profile cannot anticipate, and it is far easier to remove an unused permission at day thirty than at year three. Build the review into the IT onboarding and offboarding checklist as a dated task with an owner, because a review that depends on somebody remembering will not happen twice.
Documenting what was granted, and why
Every grant outside the standard role profile needs a recorded approver and a reason. This is not bureaucracy for its own sake — it is the only way to know, two years later, whether an unusual permission was a considered decision or an accident nobody questioned. Auditors ask this question constantly, and “we think it was for a project” is not an answer.
Feedback that improves the process
Ask the new starter at week four what was missing, slow or confusing. They are the only person in the business who has just experienced the entire process end to end, and their answer is more useful than any internal review. Feed it straight back into the role profiles and the IT onboarding and offboarding checklist, then close the loop by telling them what changed.
Movers: the step most checklists forget entirely
Internal moves create more permission sprawl than joiners and leavers combined, because the person is still here, still working and still needs access to something — just not the same something.
Why role changes produce the worst access creep
A promotion adds permissions. A transfer adds permissions. A secondment adds permissions. Almost nothing in the ordinary run of business ever removes them, so after two or three moves a long-serving employee holds a combination of access no policy would ever approve deliberately. Auditors call this toxic accumulation, and it is the reason internal fraud is usually committed by people who have moved departments. A mover branch in the IT onboarding and offboarding checklist is the only thing that stops it.
Removing old access is a separate task
Treat a mover as a leaver from the old role and a joiner to the new one, with two distinct tasks and two completion records. Bundling them into a single “update access” ticket reliably produces the additive half and quietly skips the subtractive half. This is the single highest-value correction most businesses can make to their IT onboarding and offboarding checklist, and it costs nothing but discipline.
Temporary elevation with a real expiry
Cover, project work and holiday delegation all need genuine expiry dates, not intentions. Set the removal task at the moment you grant the access, with a date attached, and use time-bound group membership where your platform supports it. Permanent permissions granted for a fortnight in August are how estates become impossible to reason about.
Contractors, temps and third parties
Contractors need end dates recorded at the point of creation and enforced automatically, because nobody sends a resignation letter for a contractor whose engagement simply lapsed. Third-party support accounts belonging to suppliers deserve the same treatment plus a named internal sponsor and a quarterly review. A good IT security posture is undone quickly by a dormant vendor login created for a migration finished last year.
Offboarding: the first four hours after notice
Offboarding is where an IT onboarding and offboarding checklist earns its reputation, because everything that goes wrong here goes wrong quickly and in public. The right sequence is well established, and the timing matters more than the tooling.
Disable, do not delete
Disable the account, revoke active sessions and reset the password. Do not delete anything. Deletion destroys mailbox contents, personal file storage, audit history and the chain of evidence you may need weeks later, and in several platforms it is irreversible after thirty days. Disabling is instant, complete and reversible, which is precisely the combination you want at the moment somebody resigns. Every leaver path in the IT onboarding and offboarding checklist should start with that single word: disable.
The sequence that prevents data loss
Revoke sessions and tokens first, because disabling an account does not always terminate a signed-in session on an unmanaged device. Then remove MFA registrations, block sign-in, reset credentials, convert the mailbox to shared, transfer file ownership to the manager, remove group memberships and finally collect the hardware. Running that order backwards is how a leaver spends their last afternoon downloading a client list. This part of the IT onboarding and offboarding checklist should be a written runbook, not a memory test.
Mailbox, files and delegated access
Convert the mailbox rather than deleting it, set an auto-reply naming a colleague, and apply delegated access for the manager with an end date. Transfer ownership of cloud files before the licence is removed, because reclaiming personal storage after deprovisioning ranges from tedious to impossible. Check for mail forwarding rules the leaver may have created — an auto-forward to a personal address is the most common quiet exfiltration route there is.
Hardware return and the leaver’s device
Record every asset issued to the person and get each item back with a signature, including the dock, the monitor, the headset, the phone and the fobs anybody forgets. Where return is delayed or the departure is remote, remote wipe is the fallback rather than the plan. Reissue only after a clean rebuild — never by handing a leaver’s machine to a new starter with the old profile still on it.
The hostile or sudden departure
Agree the escalation path before you need it. A dismissal, a resignation to a direct competitor or a departure under investigation needs simultaneous access removal at the exact moment the conversation begins, coordinated between HR, the manager and IT. Legal hold on the mailbox may be required, and preserving evidence takes precedence over tidying up. Write this variant into the IT onboarding and offboarding checklist in advance, because it is the one occasion when nobody has time to think it through.
Beyond the obvious: SaaS, shadow IT and forgotten credentials
The systems your identity platform controls are the easy half. The other half is where leavers keep access for years, and it is invisible unless you go looking deliberately.
The applications single sign-on does not cover
Every business runs tools bought on a company card by a department that needed something quickly: a design subscription, a survey tool, a courier portal, a supplier extranet, a social media scheduler. None federate to your directory, so disabling the main account changes nothing at all. The only defence is a maintained list of these applications with a named owner each, reviewed quarterly and consulted on every leaver. Attach that list to the IT onboarding and offboarding checklist, because no directory will ever generate it for you.
Shared accounts, service accounts and the password vault
Shared logins are bad practice and they exist anyway. When somebody leaves, every shared credential they knew must be rotated — not just removed from their vault, because they may have memorised or exported it. Service accounts used for integrations need documented owners so they are not disabled during a leaver sweep, which is how a payroll integration fails on a Friday night. A password manager with per-user access and full audit logging turns rotation into a list rather than an archaeology project.
Personal devices, BYOD and cached company data
Anyone who read email on a personal phone holds cached company data. Selective wipe of the managed work profile, leaving personal content untouched, needs to be in place before the departure rather than negotiated during it. Say so explicitly in the acceptable use policy staff sign on day one — which is another reason the IT onboarding and offboarding checklist should link the two ends of employment together in a single document.
Building a leaver inventory you can trust
Assemble the definitive list once and maintain it: identity platform, every non-federated application, shared credentials, hardware, physical access, mobile devices, external portals, distribution lists and any client-facing accounts in the person’s name. Store it beside the IT onboarding and offboarding checklist rather than in somebody’s head. The list is the deliverable — the tasks are easy once the list is right.
Compliance and audit: proving the IT onboarding and offboarding checklist ran
Doing the work is only half the requirement. Being able to demonstrate you did it, on a specific date, for a specific person, is what turns a good process into evidence.
What auditors actually ask for
They ask for a sample. Pick five leavers from the last twelve months, show the date each account was disabled, show who authorised it, and show the current state of that identity. The answer needs to come from a system rather than from recollection. Businesses that log completion against a ticket pass this in ten minutes; businesses relying on email threads spend a week reconstructing a story. Logging each IT onboarding and offboarding checklist run against a ticket is what makes the difference.
UK GDPR, retention and the leaver’s mailbox
A leaver’s mailbox contains personal data belonging to them and to third parties, so retaining it indefinitely because deleting things feels risky is itself a compliance problem. Set a defined retention period, document the lawful basis, and delete on schedule. Sound data protection practice here is about being deliberate: retention that is decided, written down and applied consistently beats retention that simply happens.
Cyber Essentials, ISO 27001 and access control evidence
Access control is a named requirement in both schemes. Cyber Essentials asks for a documented process covering account creation, privilege approval and prompt removal on departure. ISO 27001 goes further and wants evidence of periodic access reviews. A well-run IT onboarding and offboarding checklist produces most of that evidence as a by-product, which is why certification is far cheaper for businesses that already run one — the pattern we described in our ISO 27001 certification cost guide.
Retention periods and when to finally delete
Decide the timeline in advance: disable immediately, retain the mailbox for a defined period tied to business need, release the licence once the mailbox is converted, and delete the identity at the end of the retention window. Publish those dates so nobody has to make a judgement call at speed. An estate full of disabled accounts kept “just in case” is a smaller risk than live ones, but it is not zero risk.
Automating the IT onboarding and offboarding checklist
Automation is worth doing and easy to overdo. The aim is removing the steps that fail through forgetting, not building a workflow engine nobody maintains.
Where automation pays back fastest
Account creation from an HR record, group membership from a role attribute, licence assignment from group membership, and scheduled disablement on a recorded leave date. Those four cover the majority of both halves of the process and each is a well-trodden integration. Automated reminders to managers ahead of a start date or a leave date cost almost nothing and remove the most common failure of all — nobody told IT. Those four steps are where an IT onboarding and offboarding checklist stops depending on human memory.
The HR system as the single source of truth
Automation only works when one system is authoritative for who works here, in what role, from what date, to what date. If that is genuinely your HR platform, integrate to it and stop maintaining a parallel list. If it is not — if leave dates are updated late or job titles are decorative — fix the data before automating, because an automated IT onboarding and offboarding checklist reading unreliable input produces the same errors faster and with more confidence.
What should stay manual
Anything requiring judgement: exceptions to role profiles, elevated privilege, hostile departures, legal hold and the physical handover of a device. A good rule is that automation handles the predictable path and a human handles every branch off it. Approvals should be logged whichever way they arrive, and change management discipline applies to the workflow itself.
Measuring whether the process works
Track four numbers monthly: time from offer acceptance to a working account, percentage of new starters fully provisioned on day one, time from leave date to account disablement, and the count of enabled accounts belonging to people who have left. That last figure should be zero, and if it is not, you have found your next month’s work. Metrics turn the IT onboarding and offboarding checklist from an opinion into something you can improve.
Putting the IT onboarding and offboarding checklist into practice
Nothing above requires new software or a large budget. It requires deciding the process once, writing it down and giving it an owner — which is why most businesses can implement the whole thing in a quarter.
A realistic 90-day rollout
Spend the first month auditing: list every application, every account and every person, and reconcile that against your current payroll. Expect surprises. Month two, write the role profiles and the runbooks, and agree the triggers with HR. Month three, run the IT onboarding and offboarding checklist manually on every joiner and leaver, fix what breaks, then automate only the steps that proved stable. Automating a process you have not yet run by hand is the classic way to hardcode an existing mistake.
The objections you will hear, and the answers
“We are too small for this” — a ten-person business has the same dormant-account exposure and less capacity to absorb an incident. “It slows hiring down” — it does the opposite, because the delay today is caused by improvisation, not by process. “HR will not adopt it” — they will, once the request form is one screen and the reminders arrive automatically. Each objection is really a request for the process to be lightweight, which is a fair requirement rather than a reason to skip it.
When to bring in a managed IT partner
Bring in help when the estate is bigger than the person maintaining it, when nobody can produce a leaver list on request, or when certification is coming and the evidence does not exist. A partner should hand back a documented process you own rather than a dependency you rent, and the same logic applies to leaving one — a topic we covered in our office move IT checklist for the operational equivalent.
Start with the leaver half
If you do one thing this week, list every enabled account and reconcile it against your current payroll. It takes an afternoon, it will find something, and it is the fastest possible demonstration of why the rest of the IT onboarding and offboarding checklist is worth building. Onboarding failures are embarrassing and expensive; offboarding failures are quiet, and they are the ones that end up in a breach report.