BG Beter Geregeld ICT
Toegangsbeheer · 5 min leestijd · 01 August 2026

New employee or intern? Here's what to sort out on day one

September is hiring season. Six practical steps to get a new employee, intern, or temp off to a good and secure start on day one — without having to undo things later.

September is just around the corner, and with it comes something almost every SMB does at the same time: onboarding new colleagues, welcoming interns, or getting a temp set up in the office. Everyone quickly gets an email address, access to a shared folder, and sometimes a key to the front door. And then? Then the work takes over and nobody gives it a second thought.

That's exactly where things go wrong. Not through a spectacular hack, but through a forgotten account that can still access the client list months later. This post is a practical checklist for a new employee's first working day, so you don't have to unravel things further down the line.

Why that first day matters so much

What you sort out on day one, you won't have to clean up later. And conversely: whatever you forget to configure tends to stay in place for years. At client sites, we regularly come across accounts belonging to people who left two years ago, still with full access to mailboxes and cloud folders. That's not negligence — it's just being busy.

A short, consistent procedure takes 20 minutes and prevents a lot of headaches. Below are the six steps we follow ourselves.

1. Only grant access to what's actually needed

It's tempting to give someone access to everything straight away "for convenience". Don't. For each system, ask yourself: does this person need this to do their job today?

  • A marketing intern doesn't need access to payroll.
  • A new sales rep doesn't automatically need access to all client contracts.
  • A temp on reception doesn't need access to the accounts.

It might sound strict, but it's actually better for everyone: your new colleague has less to learn, and you have less to answer for if something goes wrong.

2. Enable two-factor authentication straight away

Don't wait until things "calm down a bit". New accounts are an attractive target, precisely because people haven't got their password memorised yet and are therefore more likely to fall for phishing. Set up two-factor authentication (2FA) as soon as the account is created, together with the new colleague. Five minutes' work.

Make sure a backup code or secondary phone number is also on record — otherwise you'll be stuck the moment someone loses their phone.

3. Record when access should end

For a temporary contract or internship: note the end date in your calendar straight away. Not as a vague reminder somewhere, but as a concrete appointment: "disable account [name] on [date]". For a permanent contract: note when you'll do the first review and which permissions you'll revisit at that point.

This prevents the classic situation: someone left two months ago, but their account is still receiving client emails.

4. Go through the ground rules in plain language

No thick policy document, no mandatory e-learning. Just spend ten minutes walking through what applies in your office. Think about:

  • Where do we store files (and where definitely not)?
  • Are you allowed to open work files on a personal device?
  • What do you do if you receive a suspicious email or phone call?
  • Who do you report a lost phone or laptop to?
  • Can you share passwords with a colleague? (No.)

Those last two often catch new colleagues off guard. Better they hear it now than next month.

5. Set up the email signature and auto-reply properly

Small things, but they matter. A signature with the correct job title, phone number, and company details looks professional to the outside world. And check that the mail settings for a temporary worker are configured so that emails are forwarded or answered when they're away.

Not sure whether your emails are reliably reaching clients? That's often nothing to do with the new employee — it's your domain settings. A quick check of SPF, DKIM, and DMARC can prevent messages from ending up in spam.

6. Document what you've set up

Sounds dull, but it's essential. Keep one simple overview per employee: which accounts, which permissions, which devices have been lent out. A spreadsheet is fine. When someone leaves, you'll know exactly what to cancel, reclaim, or revoke.

This doesn't need to be an HR system. A single page in your shared folder with a name, start date, systems, and end date is more than enough for most SMBs.

Twice a year: a quick review

Alongside this onboarding checklist, we recommend going through all accounts twice a year. Who has access, who still works there, and who doesn't? This is called an access review, and at most SMB offices it takes less than an hour. It's the cheapest security measure there is.

In short

  • Grant only what's needed, not what seems convenient.
  • 2FA on from day one.
  • End date in the calendar straight away.
  • Go through the ground rules verbally.
  • Get the signature and email settings right.
  • Keep brief documentation of everything.

Would you like help with this? We help SMBs with an access check and implementing 2FA. No subscription — just getting it right, once.

Onderwerpen

#mkb #onboarding #access-review #toegangsbeheer #2Fa

Volledige gids: Access Management for SMBs: The Complete Guide (2026)

Dit artikel is onderdeel van onze uitgebreide Toegangsbeheer-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →