Monday morning, a new starter in reception
At quarter to nine, the client's office manager emails: 'New starter today, can you set them up?' There is no job title, no manager, no indication of which shared mailboxes or applications they need, and no laptop ordered. The engineer creates a Microsoft 365 account, assigns a licence, copies group memberships from someone who seems similar, and hopes. By lunch, the starter has email but not the finance system, and has been added to a shared mailbox they should not see.
Meanwhile, someone who left the same client three weeks ago still has an active account, because the leaver notice never came. It turns up only when their mailbox starts receiving phishing emails.
Why starters and leavers go wrong
The client's HR or office manager knows about the change, but does not know what the MSP needs to act on it. The MSP knows what it needs, but hears too late and with too little.
- Requests arrive by email with missing details.
- Each client has different applications, groups and shared mailboxes.
- Leavers are forgotten because the leaving process focuses on HR, not IT.
- Account creation is manual and copied from 'someone similar'.
- Devices, licences and security tools are not part of the same request.
What rushed starters and missed leavers cost
| Problem | Effect |
|---|---|
| Starter set up on the day | A first morning without working IT |
| Permissions copied from another user | Access to data the starter should not see |
| Leaver account left active | A security risk and a licence still paid for |
| Leaver mailbox not handled | Lost emails, or data kept longer than your client's policy allows |
| No confirmation to client | The client does not know what was done |
What access each role should have, and how leavers' data is kept, is your client's decision. The form captures their decisions so your engineers can follow them.
Starter and leaver forms we build
- A form per client, in your client portal or as a secure link, with that client's roles, departments, applications, shared mailboxes and devices as choices.
- Required notice periods shown on the form (for example, laptops need ordering in advance), with the request marked urgent if it comes in late.
- A PSA ticket created with a task list matched to the request: account, licence, groups, applications, device, security tools.
- Automation of routine account steps in Microsoft 365 or Google Workspace through their APIs, based on role templates the client approves, with an engineer checking before activation.
- Leaver handling that follows the client's choices: block sign-in, convert or delegate the mailbox, remove licences on the right date, collect the device.
- A completion summary emailed to the requester listing what was done, and a monthly list of licences freed by leavers.
A normal week with the forms in place
The office manager fills the starter form a week ahead: role, start date, manager, laptop needed. The ticket appears with its tasks. The laptop is ordered, and on the Friday before the start date, the account is created from the finance team template, which includes the finance system and the right shared mailbox. On Monday the starter logs in and everything works.
When someone leaves, the leaver form asks the questions the office manager would never have thought to answer: who should have the mailbox, for how long, and where the laptop is going. On the leaving date, sign-in is blocked on schedule, the mailbox is converted, and the licence is freed at the end of the month.
Once a quarter, the account manager can send each client a list of accounts with no sign-in for a long time, as a prompt to check for leavers nobody reported.
Do starters and leavers look like this for you?
- Starter requests arrive on the start day.
- Engineers copy permissions from 'someone similar'.
- You have found leavers' accounts still active weeks later.
- Each engineer handles leavers differently.
- Clients do not receive confirmation of what was done.