Why Bad Onboarding = Messy Offboarding

By the time an employee hands in their notice, the decisions that will make their departure clean or messy have already been made. They were made in the first weeks of the person's tenure, when nobody was paying close attention because the new hire had just arrived and there were a hundred other things to do. A shared login here, a quick SaaS sign-up there, a personal laptop used until the company hardware arrived. By month six, none of those feel like decisions at all. They feel like how things are.

This post covers what's really going wrong when offboarding takes three weeks, the four onboarding shortcuts that guarantee a painful exit, how to retrofit hygiene on the team you already have, and what your IT provider should be doing at onboarding that probably isn't happening.

What’s really going wrong when offboarding takes three weeks

A clean offboarding takes about 90 minutes of IT time. An account is disabled in your identity provider, which cascades access revocation across every tool connected via single sign-on. The device is remotely wiped or collected and wiped on-site. Email is forwarded to a manager or converted to a shared mailbox. The departing person's accounts in your CRM and project tools are reassigned. A handover note, already templated because it was templated at onboarding, gets filled in and filed.

The messy version of the same process can take three weeks. It starts with a manual list of tools nobody can fully remember, which usually means asking the departing employee to help reconstruct it. You find a Figma account, a Loom workspace, a Notion instance, and an Airtable base, all set up independently, all with passwords sitting in the departing employee's personal password manager. The laptop is at their house and they're not in any rush. A client emails to say they received a strange message from a personal address. Six weeks later, a vendor charges the company card for a seat you thought you cancelled.

Letting new employees sign up for SaaS tools on their own

When a staff member signs up for a tool independently with details only they know that account is functionally theirs. You can’t reset it without triggering notifications to them. This is the most common source of “ we can’t find half the logins when someone leaves” problem.

FIX: Is to provision every tool through a central Identity system where any new SaaS application gets connected to your single sign-on before the first user logs in.

SaaS - Software as a service

4 Onboarding Shortcuts that guarantee a messy exit

Shared logins for tools you didn’t want to pay per-seat for

Shared credentials are the worst offender at offboarding. When five people use the same login for a tool, you can't remove one person's access without changing the password for everyone. You usually find this out at the worst possible time, when the person leaving is the one who set up the account and nobody else remembers the password at all.

FIX: Per-seat is the cost of doing this properly. The savings from shared logins reappear during offboarding as wasted hours and exposed access.

Tolerating personal devices “just until we get the sorted”

With personal devices an employee will installs apps, connect to client systems, downloads files and what was a temporary fix becomes how they work permanently. When they leave you have no ability to wipe company data from a device that is not company owned and never enrolled in a management system.

FIX: Is to issue company -owned devices on day one and enrol them in a mobile device management. When a personal device is used - require a managed app access for company emails and files.

Letting client relationships live in one person’s inbox

This one is specific to agencies and professional services. When an employee leaves their client relationships often leave with them. The context, the email history, the preferences, and the half-finished threads lived in one person's inbox. With the person gone, all of that becomes inaccessible or awkward to retrieve.

FIX: Create a shared inbox or CRM where client communication is logged.

How to retrofit hygiene on the team you already have.

The clean up most businesses need is for the team they already have before a new starter arrives. You can’t go back and re- onboard your existing staff but you can do the following:-

Blue background with a white check mark

SaaS Audit
Retrieve recent credit card statements for all cards that are used for business expenses. Create a list of every recurring SaaS and who set it up, who has the login, whether it is a personal or business email and who can access it.

Blue background with white check mark overlay.

The device register
Build a simple list: who has what, when the device was issued, whether it is enrolled in a management system and what company data each device can access. Ensure to ask employees for any devices they use for work - personal or business. For any personal devices the minimum is making sure company email and file access happens through managed apps that can be remotely disconnected.

Blue checkmark icon on a square background.

Client communication in shared places

Move client communication into shared places so the relationship stays with the business not just the employee who has moved on. Continuity is the goal.

What an IT Provider Should be doing at onboarding

They should set up the new account in your identity provider, enrol the device in your mobile device management system, and provision access through single sign-on so every tool the new hire uses is connected to a central identity that can be switched off in one action. They should also maintain a handover document for each staff member, updated periodically, listing every system the person accesses, every client relationship they own, and every credential tied to their identity.

When that's in place, offboarding becomes a checklist and an hour rather than a three-week excavation.

Article adapted with permission from The Technology Press.

Next
Next

How to Prepare Microsoft 365 Permissions for a Safe Copilot Rollout