The cost of the improvised first day
Everyone has seen the improvised first day: the new hire sits at a bare desk while someone hunts for a spare laptop, IT gets called about an email account, and by Thursday the person has been working out of a personal Gmail because that was faster. A wage is being paid for a week of waiting, and worse habits are being set — the personal-account workaround, the shared password shouted across the room.
The fix is not software; it is a checklist run before the person walks in. Small businesses actually have the advantage here: you have one or two systems people, a handful of apps, and no committee. A first version of the checklist takes an hour to write and pays back on the very next hire.
One week out: accounts and access decisions
A week before the start date, create the accounts and — more important — decide the access.
- Email account, in your standard name format, added to the right groups and shared calendars.
- Accounts in each app the role needs: the CRM, the accounting platform, the project tool. The role part is the point. Least privilege is the principle that people get access to what their job requires and nothing more — the new bookkeeper needs the accounting system, not the admin console.
- Write the access list down as you grant it. That written list becomes the exact record you will need at offboarding, and it is the difference between removing access in ten minutes versus discovering forgotten accounts for months.
- Resist granting admin rights for convenience. Every unnecessary admin account is a free extra target handed to attackers, and quietly ungranting it later never happens.
Device prep before the first morning
The device should be ready two days early, because something always needs a second pass.
- Update the operating system fully — first boot on a new machine can mean an hour of patches you do not want burning the first morning.
- Turn on disk encryption, BitLocker on Windows or FileVault on Mac, and set the screen to lock automatically.
- Install endpoint protection and the standard app set for the role, and remove the manufacturer junkware.
- Sign the machine into your device management if you have it, even the free tier bundled with Google Workspace or Microsoft 365.
- Set up the browser: work profile, the extension set you allow, bookmarks to the apps they will live in.
If the hire is remote, ship the laptop configured, with a one-page getting-started sheet in the box, and never ask a new hire to work from a personal machine while theirs is on order — that shortcut creates exactly the data sprawl offboarding cannot undo.
Day one: MFA, password manager, and the walkthrough
The first morning has three jobs, in order.
MFA enrollment happens before anything else, while you are standing there or on the first video call. The person signs in, sets a new password, and enrolls their phone or a hardware key. Doing this first means every later login is already protected, and it signals on day one that this is how the company works.
The password manager seat comes next: create the account, show them how it generates and fills passwords, and store their first few work credentials in it together. Ten minutes now prevents years of reused passwords.
Then the human tour: the email signature set to your standard, the phone or softphone configured, where files live, how support gets asked for, and one sentence you should say out loud — if an email feels off, forward it and ask; nobody here gets in trouble for checking. That sentence does more than most security training.
The checklist is your offboarding plan in reverse
Here is the quiet payoff: the onboarding checklist, run backward, is your offboarding checklist. Every account created, every access granted, every device issued on day one is a line item to reclaim on the last day. Same list, opposite direction.
Businesses that improvise onboarding always improvise offboarding, and that is where the real damage sits — former employees with working logins months after leaving, mailboxes nobody thought to close, a laptop never returned. If you keep the written access list from step one current whenever someone's access changes, offboarding becomes a ten-minute procedure with nothing forgotten: disable sign-in, revoke sessions, transfer files and email, reclaim the device, check the list, done.
One document, maintained at hiring, protects you at every departure. That symmetry is the whole reason to formalize this.
Build yours this week
- Open a document and list every system your business uses. For each, note which roles need it and who can create accounts on it.
- Turn that into a checklist with three parts: one week out, two days out, first morning — using the items above as the skeleton.
- Add the offboarding mirror at the bottom: the same items, phrased as removals, plus reclaim the device and revoke sessions.
- Assign an owner. In a small business this is usually the office manager or you, but a name goes on it.
- Run it on your next hire, note what the checklist missed, and fix it — the second run is always smooth.
If you would rather hand the whole thing off, setting up onboarding, device management, and the security baseline is a fixed-scope project we take on at HashWhales for small teams across DC, Maryland, and Northern Virginia. Either way, stop improvising first days; they are too expensive.
