Onboarding & offboarding · Burlington, Ontario

Employee IT Onboarding and Offboarding in Burlington

Joiner, mover and leaver processes run as standard service request models: the right access provisioned by role on day one, adjusted when people change jobs, and revoked completely on departure with evidence retained.

What this covers

  • Role-based access templates
  • Device ready before the start date
  • Least-privilege provisioning by default
  • Same-day access revocation on departure
  • Documented audit trail for every change

01The risk

Leavers with live accounts are a standing exposure

Access that outlives employment is one of the most common findings in access reviews — and one of the easiest to eliminate.

Without a defined process, access accumulates. A person moves department and keeps their old permissions. A contractor finishes and their account stays enabled. A departing employee retains mailbox access, a VPN profile, and a SaaS login that HR never knew existed. ISO/IEC 27001 expects access rights to be provisioned, reviewed and removed under a defined process, and NIST CSF treats identity and access management as a core Protect function.

We build joiner, mover and leaver as request models with named approvers. Onboarding provisions from a role template so two people in the same job get the same access. Movers have old rights removed, not just new ones added. Leavers are processed against a checklist that covers every system in the asset register, including the SaaS tools that sit outside the Microsoft tenant.

02Process coverage

What each process includes

Consistent steps, executed the same way every time.

  • Account creation from role template
  • Microsoft 365 licence assignment
  • Group, shared mailbox and file access
  • Device build, enrolment and delivery
  • MFA registration and secure credential handover
  • Line-of-business and SaaS application accounts
  • Phone, extension and Teams configuration
  • Manager sign-off on elevated access
  • Mover: revoke prior access, apply new role
  • Leaver: disable, sign out sessions, reset credentials
  • Mailbox delegation or conversion for continuity
  • Device return, wipe and reissue

03Controls

How the process stays reliable

Reliability comes from templates, approvals and verification — not from remembering.

01

Role templates

Access is defined per role and reviewed periodically, so provisioning is a decision made once rather than improvised per hire.

02

Advance notice workflow

A simple request form gives the desk the lead time to have hardware, accounts and licences ready before the first day.

03

Least privilege

Elevated and administrative access is granted deliberately, time-bounded where possible, and recorded with the approval.

04

Immediate revocation

On departure, accounts are disabled, active sessions revoked and credentials reset — the sequence matters, and a simple password change is not enough.

05

Data continuity

Mailboxes and files are preserved, delegated or archived according to your retention position rather than deleted on the spot.

06

Periodic access review

Scheduled reviews confirm that live accounts still correspond to current employees and current roles.

FAQCommon questions

Questions Burlington organizations ask

How much notice do you need for a new starter?

Several business days is comfortable for standard roles, allowing hardware to be built, enrolled and delivered. Short-notice starts can be accommodated, particularly where a spare standard device is held on site.

What happens to a departing employee's email?

The mailbox is retained and can be delegated to a manager or converted to a shared mailbox so business correspondence remains accessible without keeping the user account active.

Do you cover applications outside Microsoft 365?

Yes. The leaver checklist is built from your asset register, so line-of-business systems, SaaS tools, VPN access and remote access accounts are all included.

Can offboarding happen immediately for a sensitive departure?

Yes. Urgent revocations are treated as priority requests and can be executed within the hour when coordinated with HR, including session revocation and device wipe.

NEXTRelated capabilities

Identity governance sits behind these processes

Joiner-mover-leaver is where identity and access management becomes visible day to day.

Providing Two Decades of IT Experience

Request an IT assessment for your Burlington organization

We review your current environment, security posture, cloud footprint and support model, then outline what to fix first and what it should cost.