Skip to content
IT White GloveManaged IT support · Advisory · Canada
Menu

Onboarding and offboarding guide · Canada · EN / FR

What has to happen, in writing, the day someone joins or leaves.

Ce guide est aussi tenu en français. Accueil et départ des employés →

Most onboarding and offboarding failures are not technical. They are ownership failures—no one was clearly responsible for creating an account before day one, or for revoking one the day someone left, so it happened late, partially, or not at all. The fix is not a longer checklist; it is naming who does each step and what proves it was actually done.

The decision to enable

Decide who provisions and who revokes access at each stage of the employment relationship, and what evidence proves the loop actually closed—not just that a request was made.

Separate the request from the responsibility

A new-hire form or an exit notice tells someone that action is needed; it does not by itself get an account created or a laptop returned. Name, role by role, who is accountable for provisioning access on day one and for revoking it on the last day—not just who is notified that the event happened.

  • Who creates accounts and assigns access before the start date, not on it
  • Who is accountable for revoking access the day someone leaves, not the week after
  • What happens when HR, IT, and the hiring manager each assume someone else owns the step

Build the access map before you need it for a departure

Removing someone’s access is only as complete as the list of what they had access to. Maintain a current map of systems, shared mailboxes, file locations, and third-party tools tied to each role, so offboarding is a checklist against a known list—not a scramble to remember everything a departing employee could reach.

Decide what proves the loop actually closed

A ticket marked “complete” is not the same as confirmed evidence that an account was disabled, a device was returned, or a shared password was rotated. Define what evidence—a specific log entry, a signed equipment return, a confirmed password change—counts as proof for each step, and who checks that proof exists rather than trusting that the step happened.

  • What evidence confirms an account was actually disabled, not just flagged for review
  • Who verifies company equipment was physically returned, and how that is recorded
  • How shared credentials the departing person knew are rotated, not just noted

Treat contractors and temporary staff with the same discipline

A contractor or seasonal hire often gets access faster than a full-time employee and loses it more slowly, because the arrangement feels temporary and informal from the start. Apply the same provisioning-and-revocation ownership to every non-employee with system access, tied to the actual engagement dates rather than an assumption that someone will remember to remove it.

Decision frame

What leadership should be able to verify.

These criteria do not produce a score. They expose the questions that need resolution before a responsible decision.

CriterionUseful signalLeadership question
OwnershipA named role, not a form or a notification, is accountable for each provisioning and revocation step.If this person started or left today, who is actually responsible for each access change?
Access mapWhat each role can reach is documented before someone leaves, not reconstructed afterward.Could you list everything this person can access right now, from memory or from a record?
EvidenceCompletion is confirmed by a specific record, not a status flag.What proves this account was actually disabled, not just marked for disabling?
CoverageContractors and temporary staff follow the same discipline as employees.Which non-employees currently have access tied to no clear end date?

Practical scenarios

The same discipline applied to different decisions.

An employee’s access is still active a month after departure

Situation: A routine access review finds that a departed employee’s email and file access remained active for weeks after their last day, because the offboarding request sat in a queue.

Useful response: Treat this as an ownership failure to correct, not a one-time oversight—confirm who was supposed to act on the request, why the delay happened, and add a verification step so revocation is confirmed, not just requested.

Boundary: This guide does not investigate whether the extended access was actually used or determine breach notification obligations.

A new hire cannot work on their first day because nothing was provisioned

Situation: A start date arrives before an account, email access, or required software has been set up, leaving a new employee unable to do their job on day one.

Useful response: Confirm the lead time each provisioning step actually requires and assign a specific owner and deadline ahead of the start date, rather than relying on the hiring manager to chase IT informally once the person has already arrived.

Boundary: This guide does not configure a specific provisioning or identity management tool.