A new person's first day tells them more about how an organization works than anything they will be told in it. A laptop ready, an email address that works, access to the systems they need, and a clear answer to "who do I ask when something breaks" says the business is organized. A morning spent waiting while someone hunts for a spare machine and works out which license to buy says something else, and it is remembered.

Preparation depends on lead times, available equipment, approvals, and a clear division of responsibility. A checklist cannot remove every constraint, but it can make unfinished work visible before the start date.

Start before the start date

Start planning as soon as the appointment and required approvals allow. Work backward from the start date using the actual lead times for equipment, accounts, and training.

That is not about polish. It is because almost everything in the process has a lead time somebody forgot: hardware has to arrive and be configured, licenses have to be purchased and assigned, a mailbox created before it can be added to distribution lists, and access to a third-party system frequently depends on a vendor responding to a request.

Some steps may take longer than expected or depend on another person. Track those dependencies, start independent work where practical, and explain any remaining limits to the manager and new starter.

Four things to have ready

Accounts. The identity comes first because everything else attaches to it: an account on your main platform, a mailbox, membership of the right groups and distribution lists, and multi-factor authentication set up on day one rather than "when there's time". CISA's small-business guidance is straightforward about MFA being an essential layer, and the easiest moment to establish the habit is before anyone has developed a different one.

A device. Configured, updated, encrypted, enrolled in whatever management you use, with the software they will actually need already installed. If people use their own devices, decide the rules in advance and write them down, because "we will sort that out later" becomes a policy by default.

Access, scoped deliberately. Give what the role requires, not a copy of whatever the last person had. Copying an existing user’s permissions without review can carry forward access that does not fit the new role. Use an approved role definition and record any exceptions. If someone needs elevated rights occasionally, decide how that is granted rather than making it permanent.

Support instructions. Where to report a problem, how to reach the help desk, what the process is for requesting software, and where the status pages are. Clear instructions help the person understand how to get help and what information to provide.

The checklist itself

  • Confirm start date, role, location and manager, and who is responsible for each item below.
  • Order or allocate the device, and configure it before the start date.
  • Create the account and mailbox, and add group and list memberships based on the role.
  • Enable multi-factor authentication and record the enrollment.
  • Grant application access from a role definition rather than by copying another user.
  • Request third-party or vendor accounts early, allowing for their response time.
  • Prepare a short first-day document with support contacts, reporting routes and key links.
  • Assign a named person to check in at the end of week one.
  • Record what was issued and granted, in a single place, at the time it happens.

That final line is the one that pays off later, and it is worth insisting on. Recording the access while it is granted is more reliable than trying to reconstruct it from memory during a later review.

Use the access record when responsibilities change

The onboarding record is also an input to offboarding, although departures require their own approvals, timing, and data-handling decisions.

When someone leaves, you need to know what they had. Not approximately — exactly. Which systems, which third-party accounts, which shared credentials, which equipment, and whether they were the sole administrator of anything.

Consider a hypothetical company where a long-serving operations manager leaves on good terms. Two months later the website certificate fails to renew, because it was tied to an account created in her name. Nobody acted badly. There was simply no record connecting her to that account, so nothing on the departure checklist pointed at it.

Ownership of things is the item people miss. Before someone's last day, ask what they are the only person able to do, and what accounts are registered to them personally. Domain registrars, vendor portals, payment processors and certificate providers are the usual suspects.

  • Coordinate account access changes with the authorized departure process and timing; retain or remove data according to applicable organizational requirements.
  • Reclaim equipment, and record its return.
  • Transfer ownership of files, accounts and vendor relationships, explicitly and by name.
  • Remove access from third-party systems, which frequently sit outside your main platform.
  • Rotate any shared credential the person knew, however inconvenient.
  • Redirect or delegate the mailbox in line with your policy.
  • Update your access records so the next review is accurate.

The one habit underneath both

Keep a current record of who has access to what. Everything above is easier if that exists and more difficult to organize if it does not.

It does not need to be a system. A maintained document beats a sophisticated tool nobody updates. What matters is that it is written down when the change happens, not reconstructed from memory when someone asks.

Honest limits

Checklists reduce mistakes; they do not eliminate them. They also drift — a checklist written two years ago will reference tools you no longer use and omit ones you now depend on. Review it whenever you change a core system, and let the person who most recently joined tell you what was missing. Their feedback offers a useful perspective alongside the manager’s and support team’s observations.

Your next step

Write the checklist before your next hire, not during it. Then ask the person responsible for departures whether the records contain what their process needs. Review a prior case only if authorized, and keep personal information within the appropriate access boundaries.

ALCO USA Inc helps businesses make everyday technology easier to support, including the processes around getting people started and moving them on, alongside managed hosting and development.

Sources and further reading

ALCO USA Inc: https://alcohq.com/
CISA on requiring multi-factor authentication: https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication