Employee changes cross HR, managers, IT, security, and application owners. A good MSP can operate the technical steps, but the business must authorize the person’s access and timing.
Choose an authoritative request channel
Define who may request a joiner, role change, or departure and how their authority is verified. Set required fields: person, manager, start or end time with time zone, location, role, equipment, and application access. Avoid relying on an informal message from an unverified sender. Urgent requests need an escalation route that still confirms authorization.
Prepare access by role
Agree a role-based starting set of applications and permissions with the business owner. Route exceptions to the appropriate approver. The MSP should not decide on its own whether someone may see payroll, client records, or executive correspondence. Record approvals so later reviews can explain why access was granted and whether it remains appropriate.
Make the first-day experience testable
Confirm device preparation, shipping or collection, sign-in instructions, required authentication setup, and support contact details. Ask the manager to verify the employee can reach the needed applications. Avoid sending reusable credentials through unapproved channels. A completed provisioning ticket is not enough if the employee cannot do the work.
Treat role changes as access reviews
Changing a title often requires removing old permissions as well as adding new ones. Compare the old and new roles with the application owners. Review groups, shared mailboxes, administrator roles, external sharing, and local application accounts where relevant. Record temporary access with an expiry or review date so it does not become a permanent exception.
Coordinate departures precisely
Confirm the approved time and who can authorize changes to it. The checklist should cover sign-in, active sessions, application access, shared secrets where applicable, devices, and ownership of business data. Have the appropriate business or legal owner decide retention and transfer needs before deletion. Keep personal employment circumstances out of technical tickets unless necessary for the task.
Verify and reconcile
Reconcile completed changes against the people list and application inventory through an agreed review cadence. Track failed steps and systems that require manual work. For an illustrative monthly review, inspect a small sample of recent joiners and leavers and compare the approvals with the actual access record. Investigate mismatches and improve the checklist.
Working checklist
✓Authorized requester and exact timing
✓Manager-approved role and exceptions
✓Device and first-day access verified
✓Old permissions reviewed on role change
✓Departure access and data steps confirmed
✓Exceptions assigned and reconciled
Published by Bay Area Managed IT. Examples are illustrative; they are not provider quotes, audited results, or local market survey findings. Read our editorial approach →
Bring these questions to your next provider conversation.
Use a common scope and keep the evidence beside each answer.
Prepare your RFP →