Employee Onboarding and Offboarding Process
Below is a typical enterprise employee onboarding and offboarding process covering HR, IT, Security, Facilities, Finance, Legal, and the employee’s manager.
1. Employee Onboarding Process
Purpose
The onboarding process ensures a new employee, contractor, or intern is properly hired, verified, equipped, trained, and granted the right access before starting work.
Typical Workflow
Phase 1: Pre-hire / Offer Acceptance
| Step | Owner | Description |
|---|---|---|
| Offer accepted | HR | Candidate accepts offer and employment terms. |
| Background check | HR / Legal | Complete background check, employment verification, or other required screening. |
| Employee record created | HR | Create employee profile in HRIS such as Workday, Rippling, BambooHR, or ADP. |
| Start date confirmed | HR / Manager | Confirm start date, work location, employment type, and reporting manager. |
| Onboarding ticket created | HR / IT | Trigger onboarding workflow in Jira, ServiceNow, or HRIS. |
Phase 2: Identity and Account Setup
| Step | Owner | Description |
|---|---|---|
| Create identity account | IT | Create account in Microsoft Entra ID, Google Workspace, Okta, or another identity provider. |
| Assign email address | IT | Create company email account. |
| Assign groups | IT / Manager | Add user to role-based access groups. |
| Enable MFA | IT / Security | Require multi-factor authentication before access is granted. |
| Set temporary password or invitation | IT | Send secure account activation instructions. |
| Assign standard apps | IT | Grant access to required apps based on role and department. |
Common systems include:
- Microsoft 365 or Google Workspace
- Slack or Teams
- Zoom
- Jira / Confluence
- GitHub / GitLab
- Salesforce
- HRIS
- Finance tools
- Cloud platforms
- VPN or Zero Trust access
Phase 3: Device and Asset Provisioning
| Step | Owner | Description |
|---|---|---|
| Assign laptop | IT | Assign company-managed laptop. |
| Record asset | IT | Record serial number, owner, device type, and location. |
| Enroll in MDM | IT | Enroll device in Intune, Jamf, Kandji, or similar. |
| Install security tools | IT / Security | Install EDR / XDR, antivirus, DLP, and monitoring tools. |
| Apply baseline configuration | IT | Configure encryption, screen lock, firewall, OS updates, and standard apps. |
| Ship or issue device | IT / Facilities | Ship to remote employee or prepare for office pickup. |
Minimum security requirements:
- Disk encryption enabled
- Screen lock enabled
- Endpoint protection installed
- MDM enrollment complete
- Local admin rights restricted
- OS patched
- Device assigned to a named user
Phase 4: Application and Role-Based Access
| Access Type | Approval Needed |
|---|---|
| Standard business apps | Manager approval |
| Engineering tools | Engineering manager or system owner |
| Source code repositories | Repo owner or engineering lead |
| Cloud access | Cloud owner and security approval |
| Production access | System owner and security approval |
| Customer data access | Data owner and manager approval |
| Admin access | Security, IT, or executive approval |
Best practice:
Access should be granted based on role, not one-off individual requests whenever possible.
Phase 5: Training and Policy Acknowledgment
| Training | Owner |
|---|---|
| Security awareness training | Security / HR |
| Privacy training | Legal / Security |
| Acceptable use policy | HR / IT |
| Code of conduct | HR |
| Data handling policy | Security |
| Secure development training | Engineering / Security |
| AI acceptable use policy | Security / Legal, if applicable |
The employee should acknowledge key policies before receiving access to sensitive systems.
Phase 6: First-Day Orientation
| Step | Owner | Description |
|---|---|---|
| Welcome session | HR | Company overview, benefits, payroll, policies. |
| Team introduction | Manager | Introduce team, role expectations, goals. |
| IT orientation | IT | Explain device, password, MFA, support channels. |
| Security briefing | Security | Explain phishing, data protection, incident reporting. |
| Tool walkthrough | Manager / IT | Review key systems and workflows. |
Phase 7: Manager Confirmation
The manager should confirm:
- Employee has the correct access
- Employee received required equipment
- Required training is completed
- Role expectations are clear
- No unnecessary access was granted
The onboarding ticket is then closed with evidence.
Onboarding Evidence for SOC 2 / ISO 27001
Enterprises usually keep:
- HR record
- Onboarding ticket
- Manager approval
- Access approval
- Device assignment record
- MDM enrollment evidence
- MFA status
- Security training completion
- Policy acknowledgment
- Background check result, if applicable
2. Employee Offboarding Process
Purpose
The offboarding process ensures that departing employees, contractors, or interns have their access removed, assets recovered, company data protected, and responsibilities transferred.
Typical Workflow
Phase 1: Termination Notification
| Step | Owner | Description |
|---|---|---|
| Termination initiated | HR / Manager | HR confirms termination date and type. |
| Offboarding ticket created | HR / IT | Create offboarding workflow. |
| Termination risk assessed | HR / Security | Determine if this is normal, sensitive, or high-risk termination. |
| Final working date confirmed | HR | Confirm when access should be removed. |
Termination types:
| Type | Access Removal Timing |
|---|---|
| Voluntary resignation | On final working day |
| Involuntary termination | Immediately at termination meeting |
| Contractor end date | On contract end date |
| High-risk termination | Immediate or pre-staged removal |
Phase 2: Access Removal
| Step | Owner | Description |
|---|---|---|
| Disable identity account | IT | Disable account in Entra ID, Google Workspace, Okta, etc. |
| Revoke sessions | IT | Sign user out of active sessions. |
| Reset password | IT | Reset password if account is retained temporarily. |
| Remove from groups | IT | Remove from role-based groups. |
| Remove SaaS access | IT / App Owners | Remove access to business applications. |
| Remove source code access | Engineering / IT | Remove from GitHub, GitLab, Bitbucket, etc. |
| Remove cloud access | Cloud / Security | Remove AWS, GCP, Azure, Kubernetes, production access. |
| Remove VPN / ZTNA access | IT / Security | Revoke remote access. |
| Remove admin roles | IT / Security | Remove all privileged access. |
High-risk systems to check:
- Identity provider
- File storage
- Source code
- Cloud platforms
- Production systems
- VPN / ZTNA
- Password managers
- Finance systems
- CRM
- Customer support tools
- AI systems and datasets
Phase 3: Data and Ownership Transfer
| Step | Owner | Description |
|---|---|---|
| Transfer email ownership | IT / Manager | Delegate or archive mailbox if needed. |
| Transfer files | IT / Manager | Transfer Google Drive, OneDrive, SharePoint ownership. |
| Transfer tickets | Manager | Reassign Jira, ServiceNow, GitHub issues. |
| Transfer code ownership | Engineering | Reassign repository ownership or CODEOWNERS. |
| Transfer customer accounts | Sales / Support | Reassign CRM or support ownership. |
| Preserve records | Legal / IT | Apply legal hold or retention if required. |
Phase 4: Asset Recovery
| Step | Owner | Description |
|---|---|---|
| Recover laptop | IT / Facilities | Collect or request return shipment. |
| Recover badges | Facilities | Disable and collect building access cards. |
| Recover phones or hardware | IT | Collect company-owned devices. |
| Recover security keys | IT / Security | Collect YubiKeys or hardware tokens. |
| Update inventory | IT | Mark assets as returned, wiped, reassigned, or missing. |
| Wipe device | IT | Securely erase device before reassignment or disposal. |
For remote employees, companies often provide a prepaid return shipping label.
Phase 5: Security Review
Security may review:
- Recent file downloads
- Source code activity
- Cloud access activity
- Admin actions
- Email forwarding rules
- Personal device access
- Failed login attempts
- Unusual data movement
- Use of USB devices, if monitored
This is especially important for:
- Involuntary terminations
- Privileged users
- Departing engineers
- Finance users
- Security users
- Employees with customer data access
Phase 6: Final Payroll, Benefits, and Legal Tasks
| Step | Owner | Description |
|---|---|---|
| Final paycheck | HR / Finance | Process final pay according to local law. |
| Benefits termination | HR | End or transition benefits. |
| Expense reconciliation | Finance | Close open expenses and corporate card. |
| NDA / confidentiality reminder | HR / Legal | Remind employee of ongoing obligations. |
| Exit interview | HR | Optional feedback process. |
| Legal hold | Legal | Apply if litigation or investigation exists. |
Phase 7: Closure and Evidence
The offboarding ticket should not be closed until:
- Identity account is disabled
- Critical SaaS access is removed
- Source code access is removed
- Cloud access is removed
- VPN / ZTNA access is removed
- Device is returned or wiped
- Ownership transfer is completed
- HR confirms termination process is complete
Offboarding Evidence for SOC 2 / ISO 27001
Enterprises usually keep:
- Offboarding ticket
- HR termination record
- Account disablement timestamp
- Access removal evidence
- Source code removal evidence
- Cloud access removal evidence
- Device return or wipe evidence
- Asset inventory update
- Manager confirmation
- Security review evidence, if applicable
3. Recommended Enterprise SLAs
| Activity | Recommended SLA |
|---|---|
| Standard onboarding request | 3–5 business days before start date |
| Urgent onboarding | Same day with manager approval |
| Standard offboarding | Same business day |
| Involuntary termination | Immediate or within 1 hour |
| Privileged access removal | Immediate |
| Device recovery | Within 5–10 business days |
| Contractor access expiration | Automatic on contract end date |
| Access review after role change | Within 5 business days |
4. Minimal Enterprise Checklists
Onboarding Checklist
## Employee Onboarding Checklist
Employee name:
Role:
Department:
Manager:
Start date:
Employment type:
- [ ] HR record created
- [ ] Background check completed, if required
- [ ] Onboarding ticket created
- [ ] Identity account created
- [ ] Email account created
- [ ] MFA enabled
- [ ] Role-based groups assigned
- [ ] Laptop assigned
- [ ] Device enrolled in MDM
- [ ] Endpoint protection installed
- [ ] Disk encryption verified
- [ ] Required applications assigned
- [ ] GitHub / GitLab access granted, if needed
- [ ] Cloud access granted, if needed
- [ ] VPN / ZTNA access granted, if needed
- [ ] Security training completed
- [ ] Policy acknowledgment completed
- [ ] Manager confirmed access
- [ ] Ticket closed
Offboarding Checklist
## Employee Offboarding Checklist
Employee name:
Manager:
Termination date:
Termination type:
- [ ] Offboarding ticket created
- [ ] Identity account disabled
- [ ] Active sessions revoked
- [ ] Password reset or account suspended
- [ ] MFA device removed
- [ ] Role-based groups removed
- [ ] SaaS access removed
- [ ] GitHub / GitLab access removed
- [ ] Cloud access removed
- [ ] VPN / ZTNA access removed
- [ ] Admin access removed
- [ ] Email forwarding reviewed
- [ ] File ownership transferred
- [ ] Tickets and projects reassigned
- [ ] Company device recovered or wiped
- [ ] Badge access disabled
- [ ] Corporate card disabled
- [ ] Asset inventory updated
- [ ] Security review completed, if needed
- [ ] HR / Finance tasks completed
- [ ] Manager confirmed completion
- [ ] Ticket closed
5. Key Principle
The enterprise rule of thumb is:
Onboarding should grant the right access at the right time. Offboarding should remove all access at the right time with proof.
For SOC 2 and ISO 27001, the most important thing is not just doing onboarding and offboarding, but being able to prove that access was approved, appropriate, removed on time, and reviewed regularly.