FORTLYN GUIDE
Employee onboarding and offboarding automation
Build a repeatable process for employee accounts, access, devices, approvals, and handover.
Explore all resources →Make the first day ready before it arrives.
A new employee needs more than an account. They need the right device, approved access, working communication tools, and someone to contact when a task fails. Employee onboarding automation connects these responsibilities in a repeatable process, with a clear owner and a visible status.
Start with one approved request
Capture the employee’s role, manager, start date, work location, and required systems in one controlled intake. Ask the manager to approve access before accounts are provisioned. Keep sensitive personnel information in the appropriate HR system; an IT request should contain only the information needed to perform the work.
- Identify the manager who authorizes the request.
- Assign owners for accounts, devices, application access, and orientation.
- Define the due dates and the route for exceptions.
- Record what is ready, what is waiting, and who needs to act next.
Connect Microsoft 365 and everyday tools
A defined process can coordinate Microsoft 365 licensing, group membership, shared files, email, phones, and line-of-business applications. Use role-based access as a starting point and require approval for additional permissions. Confirm available licenses and application integration options before choosing the automation.
SharePoint lists and Power Automate can support requests, approvals, reminders, and status reporting where they fit the environment. Some provisioning actions require additional permissions, connectors, or licenses. Design these dependencies into the scope before implementation.
Test the experience, not just the account
Before marking an employee ready, verify the agreed sign-in method, device setup, email, shared files, and required applications. Test a representative everyday task with the user. A successful account-creation message does not establish that the employee can do their work.
- Record the checks completed and any exceptions.
- Provide the approved support route and setup instructions.
- Assign remaining tasks rather than hiding them behind a completed status.
- Schedule a follow-up to catch access or workflow gaps.
Build offboarding into the same process
Departures need a separately authorized workflow with a defined effective time. Confirm who approves access changes, how devices are returned, and who becomes responsible for business information. Follow the organization’s retention and preservation instructions before deleting accounts or data.
The checklist should address sign-in access, active sessions, application accounts, shared credentials where applicable, group membership, device handling, and reassignment of work. Record completion and escalate exceptions. Automation should not decide retention or disclosure requirements on its own.
Keep people in control
Require review for sensitive access, unexpected role changes, and failed steps. Give each automated action an accountable owner, a record of its result, and a practical recovery path. Test joiners, role changes, delayed starts, cancelled requests, and departures before expanding the process.
What should an onboarding automation include?
A useful first version needs six things: an approved request, assigned task owners, scheduled access, readiness checks, an exception queue, and a recorded handover. Automating account creation alone leaves devices, business applications, and the employee’s first working day disconnected.
A minimum readiness checklist
- Request approved: the manager confirms the role, start date, required tools, and access level.
- Ownership assigned: each account, device, and application task has a named owner and due date.
- Access prepared: licensing and permissions match the approved role; sensitive access has separate approval.
- Working day tested: sign-in, email, shared files, and one real work task pass the agreed checks.
- Handover delivered: the employee knows where to get help, and unresolved tasks have owners.
- Completion reviewed: the manager can see what passed, what failed, and what still needs attention.
What happens when a step fails?
Send the failed task to an accountable person and keep the overall request visibly incomplete. For example, if a required application has no available license, the workflow should flag that dependency instead of announcing that the employee is ready. Retrying a failed action should not create duplicate accounts or send repeated welcome messages.
Include test cases for a changed start date, a cancelled hire, a rejected access request, and an unavailable approver. These checks make the workflow useful outside the ideal path.
What should stay under human approval?
Keep hiring decisions, privileged access, exceptions, and data-retention decisions with authorized people. Offboarding must follow the organization’s instructions for access removal and information handover. Microsoft’s former-employee checklist explains the separate access, data, and account steps to consider.
How much does a first workflow cost?
FortLyn’s Workflow Improvement starts at $1,500 for one agreed workflow, including configuration, testing, documentation, and handover. Software and third-party costs are additional. An onboarding and offboarding program spanning several systems may require a broader scope; it should not be assumed to fit the starting price. Review pricing and scope before choosing the first process.
Start with a focused workflow
Choose one role and a small set of systems for the first implementation. Map the current handoffs, agree the acceptance checks, and measure whether the process reduces missing information and unassigned work.
Explore workflow automation, review Microsoft 365 setup and support, or request a technology review to define the first scope.
Let’s make technology work for you.
Start with the systems, bottlenecks, and goals that matter to your business.
