Employee IT onboarding and offboarding checklist
Staff changes are one of the most common sources of avoidable IT risk and disruption. A repeatable checklist makes sure a new person has the right device, accounts and training, and that someone leaving no longer has access to systems, data or customer information they do not need.
Last updated
The short answer
For every starter, define the role, device, accounts, licences, access and security training before day one. For every departure, remove or change access promptly, recover business devices and data, preserve needed records and transfer ownership of shared work deliberately.
Why the process matters
Onboarding and offboarding combine people, systems and security. They should be owned by the business with IT and HR/management responsibilities made clear, rather than relying on a last-minute email to a provider.
The controls to include
Role-based access
Give people the access their role needs, not broad access inherited from a previous employee.
Business-owned accounts
Use named business accounts and licences; avoid shared credentials and personal accounts for business work.
Deliberate departures
Remove access, recover assets, redirect work, preserve records and document completion.
Who this is for
- Businesses hiring, restructuring or managing staff turnover.
- Teams using Microsoft 365, Google Workspace, cloud apps or managed devices.
- Owners who want fewer access and handover surprises.
A repeatable process
- Define the role before access. Agree what systems, data, devices and approvals the person genuinely needs.
- Prepare and confirm. Set up the account, device and training, then confirm the user can work without unnecessary permissions.
- Close departures fully. Use a checklist that records account changes, device return, data handover and management confirmation.
How WaTo can help
- We align staff access with Microsoft 365, devices, cloud systems and support processes.
- We help make the checklist practical for managers and staff.
- We can identify stale accounts and access as part of a wider review.
Staff access questions
Should access be removed before a person leaves?
The timing depends on the role and circumstances, but the business should plan it deliberately with management and preserve required records before access is removed.
Can staff share one account?
Shared credentials make accountability, offboarding and security harder. Use named accounts and appropriate shared-mailbox or delegated-access features instead.
How WaTo can help with this
WaTo Consulting. Last reviewed 2026-10-04. Review after identity, device or HR process changes.
Want staff changes to be easier and safer?
WaTo can help design a repeatable access and device checklist for your business.
Mon to Fri, 8:30am to 5pm
