Onboarding and Offboarding Field Crews Without Security Gaps

Seasonal hires, subs and rotating crews make account management hard. Use this checklist to grant access fast and revoke it completely when people leave.

3 min readBy Ironfield Cyber Team

In construction and energy services, headcount moves constantly. Crews ramp up for a project, seasonal workers arrive, subcontractor staff need project software access, and people leave without much notice. Every one of those changes touches IT, and when the process is informal, accounts linger long after the person has gone.

A reliable onboarding and offboarding process is one of the most valuable things a managed IT provider can set up for you. It reduces risk, speeds up the first day, and removes the awkward question of who still has access to what.

The core problem

Most companies are decent at creating accounts and poor at removing them. The reasons are predictable: HR tells payroll but not IT, a foreman releases a worker and no one hears about it, or a subcontractor's employee simply stops showing up. Meanwhile their email, project software login, and VPN access continue to work.

Stale accounts are attractive to attackers because no one is watching them, and they create real exposure if a departing employee is unhappy.

Build the onboarding checklist

Start from roles rather than individuals. Define a handful of standard access profiles, such as project manager, superintendent, estimator, accounting, field laborer, and executive. Each profile lists exactly what the person receives.

For each new hire, the request should capture:

  1. Name, role, start date, and manager.
  2. Which profile applies, plus any approved exceptions.
  3. Device needs: laptop, phone, tablet, rugged device, or none.
  4. Software access, such as Microsoft 365, Procore, Sage, or Viewpoint.
  5. Whether they need access to jobsite networks or secure areas.

Standard profiles keep access consistent and prevent the common habit of copying another employee's permissions, which usually carries too much.

Day-one security basics

Before a new user does real work, confirm:

  • Multi-factor authentication is enrolled.
  • The device is encrypted and managed.
  • They have completed a short orientation on phishing and payment-fraud warning signs.
  • They know how to report something suspicious and whom to call for help.

Field staff who share devices should still have individual accounts. Shared logins make it impossible to know who did what.

Build the offboarding checklist

Offboarding should be triggered by a single event: the manager or HR submits a termination notice. The checklist then runs the same way every time.

  1. Disable sign-in for all systems on the effective date, or immediately for involuntary separations.
  2. Revoke active sessions and tokens, including mobile devices.
  3. Remove access to project management and accounting software.
  4. Collect or remotely lock company devices and confirm return.
  5. Convert the mailbox to shared or forward as business needs require, rather than deleting immediately.
  6. Reassign ownership of files, shared drives, and approval workflows.
  7. Remove the person from distribution lists, group chats, and vendor portals.
  8. Rotate any shared secrets they knew, such as Wi-Fi keys, alarm codes, or shared service account passwords.

Subcontractors and temporary workers

Give outside parties accounts that expire automatically. Set an end date at creation, tied to the contract or project schedule. Review the list monthly: any outside account without a known project owner should be disabled until someone vouches for it.

Make it measurable

A simple monthly review keeps the process honest. Compare the list of active accounts against the current payroll and subcontractor roster. Anyone who appears in IT systems but not in either list is a discrepancy to resolve. Track how long it takes from separation to full account removal and aim to shrink that number.

Common mistakes

  • Deleting accounts too quickly and losing business data.
  • Letting managers request access by text message with no record.
  • Forgetting software that sits outside the main directory, such as vendor portals and bank access.
  • Treating seasonal workers as too temporary to bother with.

Getting it running

Ironfield Cyber builds role-based access profiles and automated onboarding and offboarding workflows for contractors and energy companies. If your last account audit turned up surprises, we can help you set up a process that prevents them.