A new starter's first week tells them what kind of business they have joined. Spending it waiting for a login, borrowing somebody's laptop and being unable to see the files they were hired to work on is a bad first message, and it is entirely avoidable.
Onboarding automates well because it is high-consequence, low-frequency and completely rule-based. Here is how to build it, and how to build the half that matters more.
Start with one form
Every onboarding automation begins with a single trigger. One form, filled in when the offer is accepted, capturing:
- Full name and preferred name
- Job title and department
- Start date
- Manager
- Role template — the important one
- Location and whether they are office-based, hybrid or on site
- Equipment needed
The role template is what makes everything downstream possible. Rather than somebody deciding what access a new estimator needs, you define it once, and every estimator gets the same. That consistency is also what makes offboarding reliable, because you know exactly what to take away.
What the automation does
On submission, ideally a week before the start date:
- Creates the account with the correct naming convention and a password that must be changed at first sign-in.
- Assigns the licence appropriate to the role — not everybody needs the same plan, as covered in the plan comparison.
- Adds them to groups based on the role template. This is where access actually comes from, and driving it from groups rather than individual permissions is the single most important design decision.
- Creates the mailbox and grants access to any shared mailboxes the role requires.
- Adds them to the right Teams and distribution lists.
- Raises tasks for the things a machine cannot do: prepare the laptop, order the phone, arrange building access, book the induction.
- Notifies the manager with a checklist and a start-date reminder.
- Enrols the device in Intune when it is first signed into, so encryption and compliance are enforced from the outset.
Fifteen minutes of somebody's attention against two to four hours done by hand, and every new starter gets exactly the same setup.
Access should come from group membership, never from somebody adding permissions individually. Individual permissions are invisible, they accumulate, and they are what makes leavers dangerous.
The half most businesses never build
Offboarding. It is less pleasant to think about, it is done under time pressure, and it is a genuine security control.
What happens without it is predictable. An account stays active for months. A shared password is never changed. Files remain shared from a personal OneDrive. An application outside the main login — the courier portal, the supplier account, the social media scheduler — is never touched because nobody remembered it existed.
What a leaver automation should do, in order
- Block sign-in immediately and revoke active sessions. Not reset the password — revoke the sessions, or an already-signed-in device keeps working.
- Remove from all groups, which removes access to everything driven by group membership. This is the payoff for doing onboarding properly.
- Set an out of office naming who to contact instead.
- Delegate the mailbox to their manager or successor.
- Transfer OneDrive ownership before it is deleted. Microsoft removes it on a schedule after the account goes, and businesses discover this late.
- Wipe company data from any enrolled personal device, selectively, leaving personal content alone.
- Raise tasks for the things outside your control: shared passwords to change, third-party accounts to reassign, equipment to collect, building access to revoke.
- Convert the mailbox to shared and release the licence, which preserves the correspondence at no cost. The reasoning is in this article on email recovery.
The first two steps should happen within minutes of the person's last day, and for anything sensitive, before they are told.
What to check quarterly
Automation drifts. Once a quarter, compare active accounts against your payroll list. Every account that does not match a current employee needs an explanation, and there is almost always at least one that does not have a good one.
Check group memberships against role templates at the same time. Access accumulates when people change roles internally — they gain what the new job needs and keep what the old one had.
What this is worth
The time saving is real and it is not the point. The point is that new starters are productive on day one, that access is consistent and auditable and that when somebody leaves you can say with confidence what they can no longer reach.
That last capability is what client security questionnaires and Cyber Essentials ask about, and it is very difficult to answer honestly without this in place.
Our business automation and managed IT teams build joiner and leaver processes for UK businesses as a standard piece of work. Get in touch and we will start with the role templates, because everything else follows from those.








