#joiners and leavers

Two checklists built from your own inventory, so nothing is forgotten on the way in and nothing is left open on the way out. Every step is confirmed by a person and timestamped.

##Why a checklist

Onboarding is annoying when it goes wrong. Offboarding is dangerous. The gap between someone's last day and their last working login is where most small-company security incidents live, and it is almost always an oversight rather than a decision.

The checklist is generated from what the workspace already knows: the accounts that exist, the licences assigned, the devices issued, the shared drives granted. It is specific to the person, not a generic template somebody has to adapt.

##The joiner checklist

Raise a joiner from the dashboard or by replying to the request that arrived in the inbox - "new starter on the 6th, sales" is classified as an account ticket and offers to create the checklist.

joiner · priya.n · starts 06 Oct7 steps · 2 done
[x] account created priya.n@acme-traders.com [x] groups assigned sales, all-staff [ ] licence assigned Microsoft 365 Business ← 0 free seats [ ] device issued laptop-21 · reserved [ ] shared drives sales-shared (read/write) [ ] mfa enrolled pending first sign-in [ ] welcome note sent agent install link included → a seat must be bought or reclaimed before 06 Oct

That licence warning is the point of generating the list from inventory. A new starter with no mailbox on their first morning is a bad morning, and the checklist saw it coming eleven days out.

##Role templates

A template says what a role normally gets. Create one per role you hire into more than once, and the checklist starts pre-filled.

template · salesedit once, reuse
groups        sales, all-staff
licences      Microsoft 365 Business, CRM seat
device        laptop · standard build · dock if office-based
drives        sales-shared (read/write), company-wide (read)
software      browser, CRM client, VPN
# excluded deliberately
not granted   finance drive, admin console, server access

# a template is a starting point. Anything unusual about the
# individual still gets added by hand, and that is recorded.

Templates are also where least privilege actually gets enforced in a small company. The decision about whether sales needs the finance drive is easier to make once, calmly, than each time somebody joins in a hurry.

##The leaver checklist

The leaver list is built from reality rather than the template: what this person actually holds, right now, according to the inventory.

leaver · arjun.m · last day 18 Aug9 steps · 9 done
[x] sessions revoked all devices · approved by ravi.k 18:04 [x] sign-in disabled 18:05 [x] mfa tokens removed 1 authenticator, 1 security key [x] mailbox delegated to meena.r · 30 days [x] drive access removed sales-shared, company-wide [x] devices collected laptop-17, dock-09 (signed for) [x] device wiped + reissued laptop-17 → priya.n [x] licences reclaimed M365 seat, CRM seat $ 360/yr [x] tickets reassigned 3 open → ops closed 19 Aug 09:12 · full trail retained

Steps are confirmed, not assumed

Each step needs a person to confirm it, and the ones that touch a device or an account need an admin to approve the action first. A checklist that ticks itself is a checklist that proves nothing.

##Why the order matters

Revocation runs before notification. If the sequence is reversed, the window between "your access is being removed" and the access actually being removed is a real window, and people have used it.

  1. Sessions first. Disabling an account does not end a session that is already open. Revoke tokens, then disable.
  2. Then second factors. A left-behind authenticator is a re-entry route if the account is ever re-enabled.
  3. Then data access. Shared drives, mailbox rights, anything delegated.
  4. Then hardware and licences. Collect the kit, reclaim the seats - the money part, which also happens to be the easiest to forget.

A rushed leaver - a dismissal, a walkout - can run the first three steps immediately as a single approval, with the hardware and licence steps left open for the following week.

###Contractors and temporary access

A joiner can be given an end date at creation. The leaver checklist is then generated automatically on that date, which means contractor access expires on schedule rather than whenever somebody remembers the project ended.

##What you can prove afterwards

A closed leaver checklist is the artefact an insurer, a client security questionnaire or an auditor is actually asking for: who did what, when, approved by whom, and what the system looked like either side.

It exports as a single PDF or JSON record per person. Service providers can generate these per client, which turns a monthly compliance question into a file.

##Limits

Limits - what this does not do

  • This is not an HR system. Contracts, payroll, leave and appraisals are elsewhere, and there is no HR integration that creates joiners for you.
  • Account actions run against the identity providers we support - Microsoft Entra ID and Google Workspace. Anything else becomes a manual step with a confirmation, not a silent gap.
  • Devices are not remotely wiped. The step records that a wipe was carried out, using your platform tooling.
  • Licence seats are reclaimed in the identity provider, not cancelled with the reseller. Reducing what you pay for is still a purchase decision.
  • No step runs on a schedule without approval, including contractor expiry - the checklist is generated on the date, and a person closes it.