New-starter IT onboarding is a small, recurring event that reveals a lot about how well an environment is actually managed. A business with clean identity governance, defined role templates and documented access requirements can onboard someone in hours. A business without those things discovers it every single time a new person starts, because each onboarding becomes a manual, ad hoc exercise in remembering what the last person in that role needed.

Good onboarding starts before day one: a defined role template that specifies exactly which systems, groups and licence tier a given position needs, built once and reused rather than reconstructed from memory each time. Device provisioning, account creation and access grants should be triggered from that template, not from a manager's recollection of what they think IT needs to know.

The other half of onboarding that gets skipped is offboarding's mirror image — access review at the point of a role change, not just at departure. Someone who moves from finance to operations should have finance-specific access removed as part of the move, not left in place because nobody thought to check.

The business cost of getting this wrong isn't dramatic, which is exactly why it persists. A new hire spending their first two days waiting on access requests is a quiet, recurring productivity loss that never shows up as an incident, just as a slightly worse first impression and a slower ramp every single time.

A managed IT relationship should treat onboarding as a process to be engineered once and then simply operated — not reinvented by whoever happens to be free when the request comes in.

All technical perspectives