An IT onboarding checklist defines how an employer provisions a new hire's identity, device, access and licences before the start date. It works from a role based access template rather than ad hoc requests, records every asset and account issued, and builds the removal path at the same time so the eventual offboarding is a reversal rather than an investigation.
IT onboarding fails in two directions and both are expensive. Provision too little and the new hire spends their first days raising tickets instead of working. Provision by copying another employee's permissions and you grant access nobody has reviewed, to systems the person will never use, which then persists for years. This checklist is written for IT, security and people teams working together, and it treats provisioning as a repeatable role based process with an audit trail rather than a series of individual favours.
IT should not learn about a new hire from an email the week before. Provisioning needs a defined trigger, normally the accepted offer status in the applicant tracking system or the creation of the record in the HR system, and enough lead time to order hardware and complete the build.
The trigger should carry everything IT needs in one payload: legal name, preferred name, start date, job title, department, manager and location. Chasing those details individually is where most of the delay comes from.
The account is the foundation of everything that follows, so create it in the identity provider and let downstream systems inherit from it. Systems provisioned outside single sign on become the accounts nobody remembers to remove.
Set up authentication properly at creation rather than leaving it to the new hire. Multi factor enrolment, recovery methods and group membership all belong in the build, not in a request the person makes on day one from an account they cannot yet access.
A device handed over unconfigured turns the first day into a setup session. Enrol it in your management platform, apply the baseline configuration, install the standard software set and encrypt the disk before it leaves IT.
Record the asset at the same time. Serial number, model, assigned user and issue date take a minute to capture during the build and are very difficult to reconstruct two years later when the person leaves.
Run this checklist inside your hiring pipeline
Free 1-user plan · No credit card
Cloning an existing employee's permissions is fast and is the main reason organisations accumulate access nobody can justify. It copies whatever that person collected over years, including the temporary grant from an incident three roles ago.
Maintain an access matrix per job family instead: the systems every holder of that role needs, at what permission level, and which additions require named approval. Anything outside the template becomes an explicit request with a reason attached.
Software licences are assigned during onboarding and almost never reviewed afterwards, which is how organisations end up paying for seats belonging to people who left. Assign only what the role actually needs and record the assignment against the person.
Where a tool has both a full and a limited licence tier, default to the lower one. Upgrading later takes minutes; identifying over licensed users retrospectively takes an audit.
The first weeks are when a new hire is most vulnerable to impersonation attacks, because they do not yet know who is supposed to be asking them for things. Cover that directly rather than relying on a generic annual module scheduled months away.
Keep it practical. What a real internal request looks like, how to verify an unexpected instruction, where to report something suspicious and what the password and device rules actually are will serve better than an abstract policy overview.
Every account and asset issued during onboarding has to be recovered eventually, and the difference between a clean removal and a forensic exercise is whether anyone recorded what was granted at the time.
Maintain a per employee record of accounts, assets, licences and any non standard access. This is also the record that makes access reviews possible, which is otherwise a task nobody can complete accurately.
We'll send this checklist plus the rest of the onboarding pack — and the occasional hiring tip. No spam, unsubscribe anytime.
Pitch N Hire is an applicant tracking system. The steps on this page become stages in a pipeline, so nothing is skipped and everyone can see where each candidate stands.
Free for 1 user · No credit card · Talk to a real hiring expert
Pitch N Hire keeps the offer, the paperwork trail, and the candidate record in one place — so nothing is retyped between hiring and day one. Start free with the 1-user plan.
Prefer to talk? Book a demo · Talk to sales · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert