blog

Your New Hire Can't Work and Your Former Employee Still Can. Both Are IT Problems

Written by Nick Stevens | Aug 20, 2026, 5:45:00 PM

Your new hire can't work and your former employee still can. Both are IT problems. Here's what good onboarding and offboarding actually require. 

TL;DR: Most growing businesses treat IT onboarding and offboarding as administrative tasks. They're actually two of the highest-consequence processes in the organization. Get onboarding wrong and your new hire spends their first week watching a loading spinner instead of doing the job you hired them for. Get offboarding wrong and your former employee may still have access to your systems long after they've moved on. One in four ex-employees still has access to data from a previous employer, according to Delinea. IBM puts the global average breach cost at a record $4.99 million. Both problems are entirely preventable with the right processes in place.

Think about what happens when a relay race goes wrong. It's almost never the running that's the problem. Each athlete is fast, trained, and ready. The failure happens in the handoff: the baton gets fumbled because the timing was off, the communication wasn't clear, or nobody practiced the exchange enough to make it automatic under pressure. The race was lost in the two seconds between runners, not in the legs that covered the distance.

IT onboarding and offboarding are the relay handoffs of your organization. When a new employee joins, someone has to pass them everything they need to run: access, tools, permissions, context. When someone leaves, someone has to take it all back cleanly before the next leg of the race begins. When those handoffs are practiced, documented, and owned, they happen in minutes and nobody notices. When they're informal and improvised, the baton hits the ground, and the consequences show up on both ends.

The stakes are higher than most organizations realize until something goes wrong. A new hire who can't access critical systems in their first week isn't just frustrated; they're an expensive resource delivering nothing while the organization waits for someone to sort out a ticket. A former employee whose access wasn't fully revoked isn't just an oversight; they're a potential security exposure that could linger for months without anyone noticing. Both scenarios are common. Both are preventable.

According to IBM's research, organizations using automated provisioning reduce what used to take days across dozens of systems down to minutes. The gap between those two timelines, multiplied across every hire and every departure, adds up to something worth taking seriously. This post covers what good IT onboarding and offboarding actually require and how to build processes that don't depend on whoever happens to be available that week.

Table of Contents

  1. Why Onboarding and Offboarding Are IT Problems, Not HR Problems
  2. Getting New Hires Running From Day One
  3. The Offboarding Gap Nobody Talks About
  4. What a Former Employee With Live Credentials Can Really Cost
  5. Making Both Processes Scale
  6. The First Day Sets the Tone. So Does the Last One
  7. Key Takeaways
  8. Frequently Asked Questions

Why Onboarding and Offboarding Are IT Problems, Not HR Problems

The ownership confusion is where most onboarding and offboarding problems actually start. HR owns the hiring and separation experience. IT owns the systems and the access. But the handoff between them is almost always informal, undocumented, and dependent on whoever happens to be paying attention when a new person starts or someone gives notice.

According to Enboarder's 2025 HR Leader Survey, 42.5 percent of HR professionals believe HR or People Ops owns onboarding. That's a reasonable assumption from an HR perspective. The problem is that IT access, device provisioning, software setup, and security enrollment aren't HR functions. They require IT involvement from the start, not as a compliance checkbox at the end. When that involvement comes late or gets treated as someone else's problem, access delays of up to a week are the predictable result, according to Ivanti's 2026 research.

And only 12 percent of employees say their company does onboarding well, per FirstHR's 2026 Onboarding Statistics Report. That number hasn't moved in years, not because organizations don't care, but because the coordination gap between HR and IT remains one of the most consistently unaddressed problems in the modern workplace.

Offboarding has the same ownership problem with higher stakes. When someone leaves, HR processes the separation. IT is supposed to revoke the access. When that handoff is informal or delayed, the access doesn't disappear with the employee. It just sits there, unmonitored, attached to credentials that belong to someone who no longer works for the organization. A 2026 security operations study found that 35 percent of security incidents were linked to improperly offboarded employees. That's not a small number, and it's entirely a process problem.

Both onboarding and offboarding need clear, documented ownership that spans HR and IT. Not because either team is doing something wrong, but because the handoff between them is where things consistently go wrong when nobody's specifically responsible for making it work.

Getting New Hires Running From Day One

The goal of IT onboarding isn't to complete a checklist. It's to make sure a new hire can do their job the moment they sit down. Everything before that moment is overhead, and overhead has a cost that most organizations underestimate.

Companies spend an average of $4,700 per hire and it takes five to eight months for a new employee to reach full productivity, according to the Brandon Hall Group. That timeline starts on day one. Every day a new hire spends waiting for access, chasing down credentials, or working around missing permissions pushes that timeline further out. Strong onboarding, by contrast, improves two-year retention by 82 percent. The first week sets a tone that turns out to be remarkably persistent.

What good IT onboarding actually covers is more than email and a laptop. It starts before the employee walks in the door: accounts created, devices configured, role-based access applied, MFA enrolled, and security training queued before the first morning. Role-based access is the piece that changes the process from reactive to systematic. When you define what a marketing hire needs versus a finance hire versus an operations hire, provisioning becomes execution rather than a conversation about what this particular person probably needs. You define the access package once per role. Then you apply it every time, consistently, without reinventing the process with each new requisition.

The security setup that happens at onboarding is also significantly easier to get right the first time than to fix retroactively. Employees who start without MFA, without device management enrollment, and with excessive permissions granted under time pressure are persistent security risks. Getting those controls in place before day one isn't just an operational improvement. It's where the security posture for that employee gets established, and it's much harder to enforce after the fact.

The Offboarding Gap Nobody Talks About

If onboarding gets attention because its failures are visible, offboarding gets ignored because its failures are invisible. A former employee whose access wasn't fully revoked doesn't send a notification. They just exist quietly in the system, attached to credentials nobody is monitoring, until something forces the issue.

The scale of the problem is larger than most organizations realize. Wing Security's 2025 research found that 63 percent of businesses have former employees who still have active access through SaaS applications that were never deprovisioned. Sixty-eight percent of organizations cannot confirm with certainty that all access has been revoked when someone departs, according to Oomnitza's research. And 50 percent of former employee accounts remain active for longer than a day after the employee leaves, per a OneLogin study of 500 IT decision-makers. These aren't edge cases. They're the predictable result of offboarding treated as an afterthought.

The reason this keeps happening is structural. The average organization now has 29 SaaS applications per employee, according to BetterCloud. When someone leaves, the obvious accounts get closed: email, maybe the main directory account. The long tail of applications, the project management platform, the cloud storage login, the shared password for the accounting tool, the remote desktop access, the OAuth tokens that persist independently of the main account, those get missed. Not because anyone was negligent, but because the process was never designed to find them all.

The timing of access revocation matters as much as the completeness. For voluntary departures, access should be revoked on the last day of employment, not the following week when IT gets around to the ticket. For involuntary terminations, it should happen before or simultaneously with the separation conversation. Every hour between the departure and the access cut is an open window, and most organizations have no idea how wide that window actually is.

What a Former Employee With Live Credentials Can Really Cost

The cost of poor offboarding shows up in two ways. The first is financial and well-documented. The second is reputational and harder to quantify, but often more damaging.

On the financial side, the Ponemon Institute's 2026 Cost of Insider Risks Global Report found that the average annual cost of insider risk reached $19.5 million per organization in 2025. Worth noting: 55 percent of those incidents were caused by negligent employees rather than malicious ones. That reframes the offboarding conversation in a useful way. Most of the risk isn't from disgruntled former employees trying to cause damage. It's from situations nobody planned for: a former employee who still has access and uses it out of habit, a shared credential that was never rotated, an account nobody remembered to close because it was in a third-party tool rather than the main directory.

The timing dimension is worth specific attention. Cyberhaven's research found a 720 percent surge in data exfiltration activity in the 24 hours before a layoff. That's not primarily about malicious intent; it's about employees who know they're leaving and take materials they feel are theirs, files they created, contacts they built, documents they'll "need later." Without a structured offboarding process that includes activity monitoring and access controls tightened before the departure conversation, that window is wide open.

For professional services firms and law firms specifically, a former employee retaining access to client files isn't just a security incident waiting to happen. It's a potential ethics violation, a compliance exposure, and a client trust problem that lands regardless of whether the access was ever actually used. The exposure exists the moment the account stays live. What happens with it is secondary to the fact that it shouldn't be there at all.

Making Both Processes Scale

The operational difference between organizations that handle onboarding and offboarding well and those that don't almost always comes down to the same thing: whether the process is built to run without depending on whoever happens to be available that week.

Manual, ticket-driven onboarding and offboarding work fine at small scale. When you're hiring three people a year and losing one, informal processes and good institutional memory are enough. When you're hiring twenty people a quarter and losing ten, the same informal approach produces inconsistent results, access gaps, and security exposure that compounds with every new hire and every departure. According to BetterCloud, the average enterprise now runs 275 SaaS applications, and every new hire needs access to the right subset of them. Every departure needs that access revoked across all of them. Doing that manually, across that surface area, at any meaningful scale, is a process waiting to fail.

The organizations moving away from that model are doing so quickly. By 2026, 68 percent of enterprises expect to fully automate access provisioning and deprovisioning across cloud services, up from 49 percent in 2025. The trigger is simple: when a new hire is added to the HR system, automated workflows create accounts, assign role-based access, enroll devices, and queue security training. When a departure is recorded, the same automation revokes access across connected systems, transfers file ownership, and generates the offboarding checklist for items requiring human confirmation.

For organizations not ready for full automation, a documented checklist with clear ownership is the minimum viable starting point. Every role should have a defined access package. Every departure should trigger a named process with a deadline. It's not as reliable as automation, but it's dramatically more reliable than memory. For the broader picture of what a technology environment built to scale actually requires, see our previous post, Your Technology Is Either Compounding Your Growth or Taxing It.

The First Day Sets the Tone. So Does the Last One

Most organizations put real thought into hiring. The job description, the interviews, the offer. Then the person shows up and spends their first week waiting for access that should have been ready before they walked in. Most organizations also put real thought into separations. The conversation, the paperwork, the transition plan. Then the person leaves and their accounts stay active for weeks because nobody owned the offboarding checklist. Both moments matter more than most businesses realize, and both are almost entirely a function of whether someone built a process for them.

The relay race doesn't fail because the runners aren't fast enough. It fails in the handoff. Getting those handoffs right, on the first day and the last one, is what separates an IT function that protects the business from one that creates exposure at both ends of the employee lifecycle.

Heroic Technologies works with professional services firms, law firms, and mid-sized businesses across Oregon, Washington, and California. Onboarding and offboarding process design is a consistent part of the work they do with new clients, because it's one of the clearest indicators of whether an IT environment has been built deliberately or just accumulated over time.

When it comes to onboarding and offboarding specifically, that means documenting the role-based access packages that should exist for every role, identifying the systems where provisioning isn't connected to HR events, and building the processes that make day one and the last day consistent regardless of who's handling IT that week.

The baton should never hit the ground. Get in touch with Heroic Technologies and let's make sure yours doesn't.

Key Takeaways

  • Only 12 percent of employees say their company does onboarding well. The coordination gap between HR and IT is the most consistently unaddressed reason why.
  • Companies spend an average of $4,700 per hire and five to eight months reaching full productivity. Strong onboarding improves two-year retention by 82 percent. The first week sets a tone that persists.
  • Role-based access templates turn provisioning from a discovery process into an execution process. Define the package once per role. Apply it every time.
  • 63 percent of businesses have former employees with active access through SaaS apps that were never deprovisioned. 68 percent can't confirm all access has been revoked when someone departs.
  • The average annual cost of insider risk hit $19.5 million per organization in 2025. 55 percent of those incidents were caused by negligence, not malice. Most offboarding failures aren't intentional. They're structural.
  • By 2026, 68 percent of enterprises expect to fully automate provisioning and deprovisioning. For those not ready, a documented checklist with clear ownership beats informal memory every time.

Frequently Asked Questions

1. Who should own the IT onboarding and offboarding process: HR or IT?
Both, with defined handoffs between them. HR owns the people process: hiring, separation, and the HR system events that trigger everything else. IT owns the technical execution: account creation, access provisioning, device setup, and revocation. The problems happen in the gap between those two functions. A documented process with named owners on both sides and clear triggers closes that gap.

2. What's the minimum viable IT offboarding process for a small organization?
A documented checklist with a named owner and a deadline triggered the moment HR records a departure. At minimum: email access revoked, all application accounts closed or transferred, hardware collected or remotely wiped, shared credentials rotated, and completion documented. It's not as reliable as automation, but it's dramatically more reliable than memory and informal follow-up.

3. How do we know if a former employee still has access to our systems?
Run an access audit across every platform the organization uses, not just the main directory. SaaS applications, cloud storage, project management tools, and third-party integrations are where lingering access most commonly hides. If you can't answer with certainty whether all former employee access has been revoked, that uncertainty is the problem. A structured audit surfaces what informal offboarding left behind.