The new hire IT onboarding checklist for a 10 to 30 person company
Rushed day-1 IT setup creates shared logins and over-permissioned accounts that last for years. A 4-phase onboarding checklist fixes it without slowing anyone down.
· Jake Schaaf, Founder of Atticus Rowan
It is 8:40 am on a new hire’s first day and their account does not exist yet. So the office manager does what office managers do under pressure: shares the login for a coworker’s account “just for today,” forwards a password by text and asks IT to sort it out later.
Later never comes. That shared login is still in use in November. The new hire’s permanent account, created in a rush that afternoon, was cloned from the most senior person in the department, so a junior estimator now has access to payroll folders nobody remembers granting.
This is how identity sprawl starts at small companies. Not through breaches, through onboarding shortcuts that become permanent. We covered the exit side in our offboarding guide. Onboarding is the mirror image, and doing it right is mostly a matter of having the checklist before the morning it is needed.
Why cloning accounts is the quiet failure
The most common small-business provisioning method is “make them like Susan.” Copy an existing employee’s account, groups and permissions, done in 2 minutes.
The problem is that Susan’s access is not a role definition. It is 6 years of accumulated grants: the folder from a project in 2021, the accounting share from when she covered a leave, the admin right someone gave her to fix a printer. Cloning copies all of it. Do this for every hire and within a few years nobody can say who is supposed to have access to what, only who does.
The fix is a role template: a short, written definition of what each role gets. At a 10 to 30 person company there are usually only 4 to 8 distinct roles. Writing the templates is a 1-time afternoon of work, and it turns every future hire from an improvisation into a repeatable procedure. It also makes the eventual offboarding reversible, because you know exactly what was granted.
Phase 1: before day 1
Everything in this phase can happen the week before the start date, which is exactly why it usually does not. Put it on the calendar the day the offer is signed:
- Create the account with the standard naming convention
- Assign licensing (email, Microsoft 365, line-of-business apps)
- Apply group memberships from the role template, nothing more
- Order or stage hardware, and if you enforce device baselines, enroll it before it ships to the desk
- Pre-stage the password manager invitation, you have one of those, right
- Tell the hiring manager what will be ready and what to expect
The goal is simple: at 8:30 am on day 1, the account works. Nearly every onboarding security failure traces back to this phase not happening, because every shortcut in the next phase is downstream of a missing account.
Phase 2: day 1, security before convenience
The first hour sets habits. Sequence matters:
- MFA enrollment happens at first sign-in, before the inbox loads. An account that runs “temporarily” without MFA has a way of staying that way
- Password manager setup happens the same morning, with the first credentials issued through it rather than on a sticky note
- The 15-minute security conversation: how the company handles password requests, what a phishing report looks like, who to call about anything odd. New hires are disproportionately targeted by fraudsters precisely because they do not yet know what normal looks like and will not question an urgent email that appears to come from the owner
- Personal phone access follows the BYOD baseline, app protection on, not an unmanaged mail profile
None of this takes longer than the insecure version. It just has to be the default path rather than an afterthought.
Phase 3: week 1
Two items, both short:
- Security awareness onboarding. The starter module of whatever training program the company runs, completed in week 1 while attention is high
- First access review. A 10-minute check with the manager: can the hire reach everything the job needs, and did anything get granted outside the template to make something work? If so, write it down. Undocumented “just to fix it” grants are how templates rot
Phase 4: day 30
One calendar reminder closes the loop:
- Review every permission granted since day 1
- Remove anything temporary that is no longer needed
- If a granted permission turned out to be genuinely required for the role, update the role template so the next hire gets it on day 1
- Confirm MFA, password manager and training are all actually in place, not assumed
The day-30 review is the difference between templates that stay accurate and templates that were accurate once. It takes 15 minutes and it is the step we most often find skipped.
What this buys a small business
A documented onboarding process is not bureaucracy for its own sake. At 10 to 30 users it delivers 3 concrete things:
- Least privilege by default, which shrinks the damage any single compromised account can do
- A clean answer on cyber insurance questionnaires that increasingly ask about joiner and leaver processes
- Offboarding that actually works, because access that was granted deliberately can be revoked completely
The pattern is the same one that runs through all of identity: the cheap time to get it right is at the start. Untangling access years later costs far more than granting it correctly on day 1.
Atticus Rowan builds and runs joiner, mover and leaver processes for small businesses as part of managed IT and security. If your onboarding currently depends on cloning Susan, get in touch and we will help you put the checklist in place before the next start date.
Related insights
More on Identity & access →July 22, 2026
Rolling out MFA without an employee revolt
The technical side of MFA takes an afternoon. The human side takes 3 weeks, and skipping it is why small business rollouts fail.
June 29, 2026
Employee offboarding security: the orphaned account nobody disabled
Employee offboarding security is an identity control, not an HR courtesy. Why ad-hoc offboarding leaves orphaned accounts live for months and what a documented, measured deprovisioning process looks like.
June 27, 2026
Managed identity for a 50-person company: when accounts become the perimeter
Managed identity for a small business means Entra ID as the control plane, MFA and conditional access as baseline, SSO to cut password sprawl, a joiner-mover-leaver lifecycle and ITDR monitoring for the Microsoft 365 tenant.