All guides

Starters and leavers, done properly

Starters and leavers is where security and service quality meet. Get it wrong at the start and a new person spends their first week half-working; get it wrong at the end and someone who left in March still has a live mailbox in September. Neither is a technology problem - both are process problems, and they're fixable in an afternoon.

IT support11 min readUpdated 30 July 2026

Who this is for

HR leads, office managers and IT managers who want new starters productive on day one and leavers properly offboarded the same day.

01

Why it slips

In most organisations the process technically exists. It just lives in someone's head, gets triggered by a message in a chat window, and depends on whoever picks it up knowing which systems to touch.

  • Notice arrives late - IT hears about a start date three days before, or a leaver a week after.
  • There's no single list of systems, so departmental tools get missed.
  • Nobody owns the confirmation step, so nothing is checked afterwards.
  • Role changes are ignored entirely, so access accumulates as people move around.

Access that accumulates as people move internally is the most common finding in an access review, and the hardest to spot because nothing is obviously wrong.

02

The starter process

As soon as the offer is accepted

  • HR sends one form: name, start date, job title, manager, location, and which existing person's access most closely matches.
  • Order hardware. This is the item with a lead time, so it goes first.

The week before

  • Create the account, apply the role-based access group, set up the mailbox and enrol the device.
  • Add them to the right Teams, shared mailboxes and distribution lists.
  • Prepare a short welcome note: how to sign in, how MFA works, how to get help.

Day one

  • Fifteen minutes with someone to sign in, set up MFA and check the basics work.
  • The manager confirms by the end of day one that nothing is missing.

The single biggest improvement most organisations can make is defining access by role rather than by person. "Same as Sarah" copies Sarah's accumulated access, including the things she shouldn't still have.

03

The bit everyone forgets: movers

When someone changes role, access is almost always added and almost never removed. Over a few years that produces people with visibility across finance, HR and operations because they once helped out.

  • Treat a role change as a leaver from the old role and a starter in the new one.
  • Remove the old role's access groups on a defined date, not "once they've handed over".
  • If a handover genuinely needs old access, agree an end date and diary it.

04

The leaver process

Speed matters here, and the order matters more than people expect. Deleting an account outright can destroy data the business needs, so the sequence is: cut access, preserve data, then tidy up.

  • On the last day: disable the account and force sign-out of every active session, including mobile.
  • Reset the password and remove MFA methods so the account can't be re-enrolled.
  • Convert or delegate the mailbox so mail keeps being answered, and set a forwarding arrangement with an end date.
  • Transfer ownership of their OneDrive files and any documents or sites they own.
  • Recover the laptop, phone and any physical access tokens, and record that you did.
  • Remove them from third-party systems - the accounting package, the CRM, the design tools, the courier account.
  • Reclaim the licence once the mailbox has been dealt with.
  • After thirty days, review and delete or archive in line with your retention policy.

Third-party systems are where leavers linger. Keep a list of every subscription with named users and check it every time someone leaves.

05

Making it stick

  • One trigger. HR raises a single request; IT does not act on corridor conversations.
  • One checklist per event, completed and stored - so you can evidence it later for insurance, audit or certification.
  • One quarterly review comparing all active accounts against the current staff list. It takes twenty minutes and catches everything that slipped.

None of this needs software to begin with. A shared checklist and a named owner will get you most of the way, and you'll understand the process well enough to automate the right parts later.

The short checklist

  • Define access by role, not by copying another person's account.
  • One HR form triggers every starter and leaver.
  • Order hardware as soon as the offer is accepted.
  • Have the manager confirm nothing is missing on day one.
  • Treat internal role changes as a leaver plus a starter.
  • Disable accounts and sign out all sessions on the last day.
  • Keep a list of third-party systems with named users, and check it every time.
  • Review all active accounts against the staff list quarterly.

Want a second opinion on where you've got to?

Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.