Staff onboarding and offboarding
Updated August 11, 2026.
This is the operational checklist for a River Oaks staff member's technology lifecycle. Use one tracked request per person. Record the requested effective time, supervisor, person completing each step, exceptions, and final verification. Never put passwords, recovery codes, private keys, or copied session tokens in the request.
Roles and approval
| Role | Responsibility |
|---|---|
| Supervisor or People/Office staff | Authorize the hire or departure, effective time, role, department, manager, and any approved data handoff. |
| Technology | Accounts, devices, security groups, password-manager access, portal, Wi-Fi, VPN, phones, and access verification. |
| Ministry or application owner | Planning Center, CCB, website, scheduling, department-specific applications, and data ownership. |
Technology should not create privileged access or disable an employee solely from an informal message. Confirm the request with the supervisor or designated Office owner. Use least privilege and unique accounts; do not solve onboarding by sharing another person's login.
Onboarding intake
Before creating accounts, record:
- legal and preferred name;
- River Oaks email address and job title;
- department, manager, and start date/time;
- required physical location and desk-phone needs;
- required applications and the business owner approving each elevated role;
- hardware being assigned, including asset tag or serial number;
- whether door, VPN, purchasing, finance, or administrator access is actually required.
Onboarding checklist
Identity and core access
- [ ] Create the Google Workspace identity in the correct organizational unit. Require MFA enrollment and recovery information owned by the employee.
- [ ] Add only approved Google groups and shared-drive access. Do not grant a broad administrator role by default.
- [ ] Create or approve the staff user through the Portal's current User Administration interface. Assign the smallest portal role that supports the job.
- [ ] Have the employee self-register for staff Wi-Fi, then verify the intended staff policy is applied.
- [ ] If remote access is required, enroll Cloudflare WARP with the employee's River Oaks identity and verify access from an offsite connection.
Passwords and applications
- [ ] Have the employee create their Bitwarden account, invite it to the River Oaks organization, confirm the invitation, and assign only their personal and approved department collections.
- [ ] Create Planning Center access through its application owner. Scheduled Viewer is the ordinary starting point unless a documented role needs more.
- [ ] Create CCB, Amazon, finance, website, or other line-of-business access only when its owner approves it.
- [ ] Follow the current UniFi phone enrollment workflow for a desk phone. Do not reuse another employee's personal account.
- [ ] If the role needs technology notifications, enroll the employee in the approved alert service and only the topics appropriate to the role.
Physical access and equipment
- [ ] Have the employee submit the normal key-fob request so they acknowledge the access terms. Approve only the door group required for the role.
- [ ] Purchase Apple hardware through an approved automated-enrollment vendor.
- [ ] Assign the Mac or iPad in the asset inventory and confirm automated Jamf enrollment, disk encryption, operating-system updates, screen lock, and endpoint protection.
- [ ] Record issued keys, fobs, phones, adapters, displays, and other equipment.
Handoff and verification
- [ ] Ask the employee to sign in to Google, Portal, Bitwarden, Wi-Fi, required applications, and VPN if applicable.
- [ ] Confirm access to one expected resource and denial from one known privileged resource.
- [ ] Give the employee security-reporting, password-manager, support, and lost device instructions.
- [ ] Have the supervisor confirm the access set, then close the request with account and asset identifiers—not credentials.
Offboarding preparation
Record the authoritative departure request, exact effective time, manager, access-risk level, device-return plan, data owner, and any approved email or file handoff. For an immediate or high-risk departure, Technology and the authorizing owner should coordinate live. Do not announce the departure through technical alerts.
Do not delete accounts or erase equipment at the start. Suspend access first, preserve organizational data, and wait for the approved retention/handoff decision.
Offboarding checklist
At the effective time
- [ ] Suspend the Google Workspace account and revoke active sessions, app passwords, OAuth grants, and recovery methods according to current admin policy.
- [ ] Disable Portal access and revoke active sessions. Preserve the user row for audit history.
- [ ] Remove the employee from Bitwarden organization collections and revoke organization access. Rotate a shared credential only when the employee could actually read it; record the rotation without storing its value.
- [ ] Revoke staff Wi-Fi, Cloudflare WARP/VPN, door groups, keys, fobs, and any remote administration access.
- [ ] Disable or remove Planning Center, CCB, Amazon, GitLab, UniFi, website, finance, and department-application access through each named owner.
- [ ] Remove alert-topic subscriptions and on-call routing.
Data, devices, and communications
- [ ] Transfer Google Drive ownership and other business records to the approved owner. Configure forwarding or delegation only with explicit, time-bounded approval.
- [ ] Recover every recorded device and physical credential. Mark each asset returned, missing, damaged, or approved for remote return.
- [ ] Use Jamf Lost Mode or remote lock only when authorized. Preserve required data before erase; erase and re-enroll only after the handoff is confirmed.
- [ ] Reassign the phone extension and device through the current phone workflow. Do not rename and reuse a former employee's personal identity.
- [ ] Remove the employee from public staff pages and internal schedules when the responsible owner approves the change.
Final verification
- [ ] A second Technology operator reviews high-impact access: Google admin, Bitwarden, GitLab, VPN, door access, finance, and shared mailboxes.
- [ ] Verify the suspended identity cannot access Portal, VPN, staff Wi-Fi, or a representative protected application.
- [ ] Record unresolved assets, retained accounts, forwarding expiration, data owner, and follow-up date.
- [ ] Close the request only after the supervisor or Office owner acknowledges the completed handoff.