Skip to content

General Employee Onboarding Task List

Use the current staff onboarding and offboarding runbook as the primary checklist. This page retains application-specific background. River Oaks Church - Created October 2025

Below is a list of services and accounts that need setup in order to onboard a new staff member. For IT-dept specific staff, please see the IT Onboarding guide.

-- Assign the user to their respective OU group

-- Most users DO NOT need admin access.

-- User needs to self register via link

-- After self registration, bitwarden admin user (acct is stored on bitwarden) can invite the user to join the River Oaks org.

-- User needs to accept invitation

-- Admin needs to re approve user (via green confirm button)

-- Admin needs to create a collection inside the staff collections for the new member, titled after their name.

-- Admin needs to grant permissions to user for their personal collection, and any other department collections deemed necessary

-- Admin creates user

  • Staff Device WiFi

-- Delivered by the approved Jamf configuration profile. The staff member does not enter credentials, manually configure church WiFi, or use the WiFi request form. Technology verifies enrollment, scope, and profile installation. See Staff Device WiFi.

  • Planning Center Online

-- Performed by existing admin

-- All staff SHOULD have planning center, but scheduled viewer permissions.

  • Ubiquiti STAFF Accoutn

-- ALL USERS who have a desk phone will need an account with their username -unifi@riveroaks.org as the email. [I have done this for Gina already]. This is an account THEY DONT have access to, just so we can have an account signed into their phone. I'll add more info here in the future.

-- All staff need to request a key fob just like all end users do so that they "accept" the terms of having a key.

-- Once they submit the request, they can be approved and assigned to the Staff group via tech portal. [Rachel or Eileen should be experts at this by now]

  • VPN Access

-- VPN access is granted automatically via Google account, but user will need to self login to Cloudflare WARP by opening the app on their Mac.

-- It will eventually be automatically enabled on all devices that are off network

  • Amazon

-- Amazon supports multi user accounts, so they will need to have their own account and to be assigned to their own department

  • Summary

-- Most accounts will be automatically given on Bitwarden when the user gets assigned to the collections. Any service that supports multi-user accounts should only be accessed through a user's individual account (not through shared acct)

-- This onboarding list only lists services that users need, it's of course still important for users to understand what everything is used for