Employee Onboarding and Offboarding Process

Below is a typical enterprise employee onboarding and offboarding process covering HR, IT, Security, Facilities, Finance, Legal, and the employee’s manager.

1. Employee Onboarding Process

Purpose

The onboarding process ensures a new employee, contractor, or intern is properly hired, verified, equipped, trained, and granted the right access before starting work.

Typical Workflow

Phase 1: Pre-hire / Offer Acceptance

StepOwnerDescription
Offer acceptedHRCandidate accepts offer and employment terms.
Background checkHR / LegalComplete background check, employment verification, or other required screening.
Employee record createdHRCreate employee profile in HRIS such as Workday, Rippling, BambooHR, or ADP.
Start date confirmedHR / ManagerConfirm start date, work location, employment type, and reporting manager.
Onboarding ticket createdHR / ITTrigger onboarding workflow in Jira, ServiceNow, or HRIS.

Phase 2: Identity and Account Setup

StepOwnerDescription
Create identity accountITCreate account in Microsoft Entra ID, Google Workspace, Okta, or another identity provider.
Assign email addressITCreate company email account.
Assign groupsIT / ManagerAdd user to role-based access groups.
Enable MFAIT / SecurityRequire multi-factor authentication before access is granted.
Set temporary password or invitationITSend secure account activation instructions.
Assign standard appsITGrant access to required apps based on role and department.

Common systems include:

  • Microsoft 365 or Google Workspace
  • Slack or Teams
  • Zoom
  • Jira / Confluence
  • GitHub / GitLab
  • Salesforce
  • HRIS
  • Finance tools
  • Cloud platforms
  • VPN or Zero Trust access

Phase 3: Device and Asset Provisioning

StepOwnerDescription
Assign laptopITAssign company-managed laptop.
Record assetITRecord serial number, owner, device type, and location.
Enroll in MDMITEnroll device in Intune, Jamf, Kandji, or similar.
Install security toolsIT / SecurityInstall EDR / XDR, antivirus, DLP, and monitoring tools.
Apply baseline configurationITConfigure encryption, screen lock, firewall, OS updates, and standard apps.
Ship or issue deviceIT / FacilitiesShip to remote employee or prepare for office pickup.

Minimum security requirements:

  • Disk encryption enabled
  • Screen lock enabled
  • Endpoint protection installed
  • MDM enrollment complete
  • Local admin rights restricted
  • OS patched
  • Device assigned to a named user

Phase 4: Application and Role-Based Access

Access TypeApproval Needed
Standard business appsManager approval
Engineering toolsEngineering manager or system owner
Source code repositoriesRepo owner or engineering lead
Cloud accessCloud owner and security approval
Production accessSystem owner and security approval
Customer data accessData owner and manager approval
Admin accessSecurity, IT, or executive approval

Best practice:

Access should be granted based on role, not one-off individual requests whenever possible.

Phase 5: Training and Policy Acknowledgment

TrainingOwner
Security awareness trainingSecurity / HR
Privacy trainingLegal / Security
Acceptable use policyHR / IT
Code of conductHR
Data handling policySecurity
Secure development trainingEngineering / Security
AI acceptable use policySecurity / Legal, if applicable

The employee should acknowledge key policies before receiving access to sensitive systems.


Phase 6: First-Day Orientation

StepOwnerDescription
Welcome sessionHRCompany overview, benefits, payroll, policies.
Team introductionManagerIntroduce team, role expectations, goals.
IT orientationITExplain device, password, MFA, support channels.
Security briefingSecurityExplain phishing, data protection, incident reporting.
Tool walkthroughManager / ITReview key systems and workflows.

Phase 7: Manager Confirmation

The manager should confirm:

  • Employee has the correct access
  • Employee received required equipment
  • Required training is completed
  • Role expectations are clear
  • No unnecessary access was granted

The onboarding ticket is then closed with evidence.

Onboarding Evidence for SOC 2 / ISO 27001

Enterprises usually keep:

  • HR record
  • Onboarding ticket
  • Manager approval
  • Access approval
  • Device assignment record
  • MDM enrollment evidence
  • MFA status
  • Security training completion
  • Policy acknowledgment
  • Background check result, if applicable

2. Employee Offboarding Process

Purpose

The offboarding process ensures that departing employees, contractors, or interns have their access removed, assets recovered, company data protected, and responsibilities transferred.

Typical Workflow

Phase 1: Termination Notification

StepOwnerDescription
Termination initiatedHR / ManagerHR confirms termination date and type.
Offboarding ticket createdHR / ITCreate offboarding workflow.
Termination risk assessedHR / SecurityDetermine if this is normal, sensitive, or high-risk termination.
Final working date confirmedHRConfirm when access should be removed.

Termination types:

TypeAccess Removal Timing
Voluntary resignationOn final working day
Involuntary terminationImmediately at termination meeting
Contractor end dateOn contract end date
High-risk terminationImmediate or pre-staged removal

Phase 2: Access Removal

StepOwnerDescription
Disable identity accountITDisable account in Entra ID, Google Workspace, Okta, etc.
Revoke sessionsITSign user out of active sessions.
Reset passwordITReset password if account is retained temporarily.
Remove from groupsITRemove from role-based groups.
Remove SaaS accessIT / App OwnersRemove access to business applications.
Remove source code accessEngineering / ITRemove from GitHub, GitLab, Bitbucket, etc.
Remove cloud accessCloud / SecurityRemove AWS, GCP, Azure, Kubernetes, production access.
Remove VPN / ZTNA accessIT / SecurityRevoke remote access.
Remove admin rolesIT / SecurityRemove all privileged access.

High-risk systems to check:

  • Identity provider
  • Email
  • File storage
  • Source code
  • Cloud platforms
  • Production systems
  • VPN / ZTNA
  • Password managers
  • Finance systems
  • CRM
  • Customer support tools
  • AI systems and datasets

Phase 3: Data and Ownership Transfer

StepOwnerDescription
Transfer email ownershipIT / ManagerDelegate or archive mailbox if needed.
Transfer filesIT / ManagerTransfer Google Drive, OneDrive, SharePoint ownership.
Transfer ticketsManagerReassign Jira, ServiceNow, GitHub issues.
Transfer code ownershipEngineeringReassign repository ownership or CODEOWNERS.
Transfer customer accountsSales / SupportReassign CRM or support ownership.
Preserve recordsLegal / ITApply legal hold or retention if required.

Phase 4: Asset Recovery

StepOwnerDescription
Recover laptopIT / FacilitiesCollect or request return shipment.
Recover badgesFacilitiesDisable and collect building access cards.
Recover phones or hardwareITCollect company-owned devices.
Recover security keysIT / SecurityCollect YubiKeys or hardware tokens.
Update inventoryITMark assets as returned, wiped, reassigned, or missing.
Wipe deviceITSecurely erase device before reassignment or disposal.

For remote employees, companies often provide a prepaid return shipping label.


Phase 5: Security Review

Security may review:

  • Recent file downloads
  • Source code activity
  • Cloud access activity
  • Admin actions
  • Email forwarding rules
  • Personal device access
  • Failed login attempts
  • Unusual data movement
  • Use of USB devices, if monitored

This is especially important for:

  • Involuntary terminations
  • Privileged users
  • Departing engineers
  • Finance users
  • Security users
  • Employees with customer data access

StepOwnerDescription
Final paycheckHR / FinanceProcess final pay according to local law.
Benefits terminationHREnd or transition benefits.
Expense reconciliationFinanceClose open expenses and corporate card.
NDA / confidentiality reminderHR / LegalRemind employee of ongoing obligations.
Exit interviewHROptional feedback process.
Legal holdLegalApply if litigation or investigation exists.

Phase 7: Closure and Evidence

The offboarding ticket should not be closed until:

  • Identity account is disabled
  • Critical SaaS access is removed
  • Source code access is removed
  • Cloud access is removed
  • VPN / ZTNA access is removed
  • Device is returned or wiped
  • Ownership transfer is completed
  • HR confirms termination process is complete

Offboarding Evidence for SOC 2 / ISO 27001

Enterprises usually keep:

  • Offboarding ticket
  • HR termination record
  • Account disablement timestamp
  • Access removal evidence
  • Source code removal evidence
  • Cloud access removal evidence
  • Device return or wipe evidence
  • Asset inventory update
  • Manager confirmation
  • Security review evidence, if applicable

3. Recommended Enterprise SLAs

ActivityRecommended SLA
Standard onboarding request3–5 business days before start date
Urgent onboardingSame day with manager approval
Standard offboardingSame business day
Involuntary terminationImmediate or within 1 hour
Privileged access removalImmediate
Device recoveryWithin 5–10 business days
Contractor access expirationAutomatic on contract end date
Access review after role changeWithin 5 business days

4. Minimal Enterprise Checklists

Onboarding Checklist

## Employee Onboarding Checklist

Employee name:
Role:
Department:
Manager:
Start date:
Employment type:

- [ ] HR record created
- [ ] Background check completed, if required
- [ ] Onboarding ticket created
- [ ] Identity account created
- [ ] Email account created
- [ ] MFA enabled
- [ ] Role-based groups assigned
- [ ] Laptop assigned
- [ ] Device enrolled in MDM
- [ ] Endpoint protection installed
- [ ] Disk encryption verified
- [ ] Required applications assigned
- [ ] GitHub / GitLab access granted, if needed
- [ ] Cloud access granted, if needed
- [ ] VPN / ZTNA access granted, if needed
- [ ] Security training completed
- [ ] Policy acknowledgment completed
- [ ] Manager confirmed access
- [ ] Ticket closed

Offboarding Checklist

## Employee Offboarding Checklist

Employee name:
Manager:
Termination date:
Termination type:

- [ ] Offboarding ticket created
- [ ] Identity account disabled
- [ ] Active sessions revoked
- [ ] Password reset or account suspended
- [ ] MFA device removed
- [ ] Role-based groups removed
- [ ] SaaS access removed
- [ ] GitHub / GitLab access removed
- [ ] Cloud access removed
- [ ] VPN / ZTNA access removed
- [ ] Admin access removed
- [ ] Email forwarding reviewed
- [ ] File ownership transferred
- [ ] Tickets and projects reassigned
- [ ] Company device recovered or wiped
- [ ] Badge access disabled
- [ ] Corporate card disabled
- [ ] Asset inventory updated
- [ ] Security review completed, if needed
- [ ] HR / Finance tasks completed
- [ ] Manager confirmed completion
- [ ] Ticket closed

5. Key Principle

The enterprise rule of thumb is:

Onboarding should grant the right access at the right time. Offboarding should remove all access at the right time with proof.

For SOC 2 and ISO 27001, the most important thing is not just doing onboarding and offboarding, but being able to prove that access was approved, appropriate, removed on time, and reviewed regularly.

Read more

SOP — Create and Manage Microsoft Azure for Enterprise

Version 1.0 Date 2026-06-22 Domain mptwork.com Model Identity rooted in the existing Microsoft Entra tenant; hierarchy of Management Groups → Subscriptions → Resource Groups → Resources Consoles Azure portal portal.azure.com · Entra admin center entra.microsoft.com Companion SOPs M365/Entra — sop-subscribe-manage-m365-mptwork.md, sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md · AWS

By admin

SOP — Create and Manage a Google Cloud (GCP) Account

Version 1.0 Date 2026-06-22 Domain mptwork.com Model GCP Organization rooted in Cloud Identity / Google Workspace for mptwork.com; hierarchy of Folders → Projects; workforce access via Google Groups, optionally federated to Microsoft Entra Companion SOPs Google Workspace — sop-subscribe-manage-google-workspace-mptwork.md · Entra auth & SSO — sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md

By admin

SOP — Create and Manage an AWS Cloud Account

Version 1.0 Date 2026-06-22 Domain mptwork.com Model AWS Organizations multi-account (management account + member accounts), workforce access via IAM Identity Center federated to Microsoft Entra / Google Companion SOPs Entra auth & SSO — sop-entra-id-authentication-sso-mptwork.md · Google Workspace — sop-subscribe-manage-google-workspace-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md Goal: stand up AWS for MPT Work

By admin