IT Operations

IT Onboarding and Offboarding Checklist

Affix Center · · 6 min read

IT Onboarding and Offboarding Checklist - Affix Center

A new employee in Thane waits three days for a laptop and email access. A sales manager who resigned from your Mumbai office still has access to the CRM two months later. Both problems have the same root cause: there is no written IT onboarding and offboarding checklist, so each joiner and leaver is handled from memory by whoever is free in IT or HR that day.

The cost is real on both sides. Slow onboarding wastes a new hire's first week and creates a poor first impression. Weak offboarding leaves open accounts, shared passwords and company data on personal phones, which is one of the most common paths to a data leak. This guide sets out a practical process that small IT teams and HR departments can run together.

Why Joiner and Leaver Processes Break Down

In most Indian SMEs and mid-sized firms, the process fails at the handoff between HR and IT. HR knows who is joining or leaving, but IT hears about it late or not at all. Common symptoms include:

  • Accounts created by copying another user, which quietly copies excess permissions.
  • Laptops issued without an asset record, so no one knows who holds which device.
  • Shared logins for accounting, GST or vendor portals that nobody changes when someone leaves.
  • SaaS tools bought by individual teams, outside IT's view.
  • No record of what was revoked, which makes audits and disputes difficult.

The fix is not expensive software. It is a clear trigger, an owner for every step and a record that the step was done.

Set Up the Process Before the First Ticket

Before writing the checklist, agree on three basics with HR and department heads:

  1. A single trigger: HR raises a joiner or leaver ticket as soon as an offer is accepted or a resignation is confirmed. No ticket, no access.
  2. Role-based access templates: define standard access for each role, such as accounts executive, sales, plant supervisor or developer. New users get the template, not a copy of a colleague.
  3. Clear owners: HR owns dates and approvals, IT owns accounts and devices, and the reporting manager confirms what access the person actually needs.

If your internal IT team is small, a managed service partner can run this process for you. Our IT operations and helpdesk services include joiner and leaver handling as a standard part of day-to-day support.

IT Onboarding Checklist

Before day one

  • Receive the joiner ticket with name, role, department, location, manager and start date.
  • Create the email account and directory user using the role template.
  • Assign licences for productivity, communication and business applications.
  • Prepare and image the laptop or desktop with standard software, antivirus or endpoint protection and disk encryption.
  • Record the device serial number, asset tag and assigned user in the asset register.
  • Set up access to the ERP, HRMS or other line-of-business systems only after manager approval.

On day one

  • Hand over the device against a signed acknowledgement.
  • Enforce a password change at first login and enrol multi-factor authentication.
  • Explain the acceptable use policy, and get it signed.
  • Show the person how to raise a helpdesk ticket and whom to call for urgent issues.

In the first two weeks

  • Confirm with the manager that access is correct, and remove anything not needed.
  • Complete basic security awareness training, covering phishing, password hygiene and safe use of WhatsApp and personal email for work data.
  • Close the onboarding ticket with a summary of what was provided.

IT Offboarding Checklist

Offboarding carries more risk than onboarding, so it needs stricter timing. For most roles, access should be removed at the end of the last working day. For sensitive exits, such as a termination or someone joining a competitor, remove access at the time the person is informed.

Accounts and access

  • Disable the directory account and email login. Do not delete immediately; keep the mailbox for a defined period and set up forwarding or a delegate if needed.
  • Revoke access to ERP, CRM, HRMS, cloud storage and all SaaS tools.
  • Remove VPN, remote desktop and Wi-Fi credentials.
  • Change passwords for any shared accounts the person knew, including bank, GST, tender and vendor portals.
  • Remove the user from WhatsApp groups and messaging channels used for work.
  • Revoke multi-factor tokens and remove company data from personal phones using mobile device management, where it is in place.

Devices and data

  • Collect the laptop, phone, access card, dongles and any storage devices, and check them against the asset register.
  • Back up and transfer work files to the manager or successor.
  • Wipe and reimage devices before they are reissued.
  • Update the asset register and close the ticket with a record of every step.

Security and Compliance Points to Keep in Mind

Joiner and leaver records are not just good housekeeping. They support audits, investigations and legal obligations. A few points apply to most Indian organisations:

  • Logs: the CERT-In directions issued in April 2022 require covered entities to maintain logs of their ICT systems for a rolling 180 days within Indian jurisdiction. Login and access change records are part of that picture.
  • Personal data: the Digital Personal Data Protection Act, 2023 has been passed, and its rules are yet to be finalised. It is sensible to collect only the employee data you need and to know where it is stored.
  • Least privilege: quarterly access reviews help catch accounts that were missed at exit and permissions that grew over time.

Our cybersecurity services can help you design access controls, run periodic access reviews and check that offboarding really removes every route into your systems.

Make Your IT Onboarding and Offboarding Checklist Stick

A checklist on a shared drive will be ignored within months. To keep it in use:

  • Build it into your helpdesk tool as a ticket template with mandatory steps.
  • Link it to your HRMS so that a joining or exit entry automatically creates the IT ticket.
  • Report monthly on open joiner and leaver tickets and how long they took.
  • Review the checklist every six months, and whenever you add a new business application.

Also plan for internal moves. When an employee changes department or role, treat it as a small offboarding and onboarding together: remove the old access, then apply the new role template. Role changes are where permissions quietly pile up, because new access is added and old access is never taken away.

Frequently Asked Questions

Who should own the IT onboarding and offboarding checklist?

HR should own the trigger and dates, and IT should own the checklist steps. The reporting manager approves access. One named person should be accountable for the process overall.

How quickly should access be removed when someone leaves?

By the end of the last working day for normal exits. For terminations or sensitive roles, remove access at the moment the person is informed.

Should we delete a leaver's email account?

Disable it first, then retain the mailbox for a defined period based on your legal and business needs before deleting or archiving it.

Do small businesses really need this?

Yes. Small firms often rely on shared passwords and personal devices, which makes a written process even more important.

How Affix Center Can Help

Affix Center helps businesses in Mumbai, Thane, Pune and across Maharashtra run IT support that includes structured joiner and leaver handling, asset tracking and access reviews. We can set up the process in your helpdesk, create role-based templates and handle the tickets for you.

To put a reliable IT onboarding and offboarding checklist in place, get in touch with our team.