Jump to content

Recommended Posts

Posted

Hi

 

Has anyone managed to nail the user onboarding and offboarding process for their trust? We are still getting staff starting without HR telling us when they should and numerous times a month HR forget to notify us when staff have left.

 

It would be good to know what process everyone else has that makes it more robust so IT don't find out a user has left 3 month down the road and they were notified by HR.

 

Thanks

Posted

Our HR are good at notifying us but actually the account enabling and disabling is done based on data from the MIS (SIMS in our case).

 

For staff, the account is created when HR notify us, it is then automatically enabled on their start date and disabled at the end of their leave date. The only thing HR need to do is confirm that the person should have an account (i.e. the safeguarding is complete). So, when a member of staff leaves, their account is automatically disabled whether HR have told us or not.

 

On rare occasions this has led to accounts being disabled because the MIS is wrong but that's useful because any frustration caused to the user by their account being disabled is nothing compared to the frustration they would experience if they had not been paid!

 

We have a similar system for student accounts. Accounts are semi-automatically created as soon as they appear in the MIS (actually just added to a CSV file in our case), automatically enabled on their start date and then automatically disabled on their leave date.

 

I've always thought it was a bit of a nonsense expecting departments to notify IT of every new starter, especially students who all have a standard set up process. The MIS is the single point of truth, once the staff member or student is in there, you have been notified in my opinion. The data is in a consistent format then too, it's better than receiving an email that someone will need to read, understand and action. The most difficult bit about starters and leavers (of any type) is going through the various onboarding/off-boarding processes for all the third party sites they may need to access.

Posted
One word - Salamander. Well worth the money, creates all users on their MIS start date, adds them to the appropriate groups, assigns relevant 365 licences, and disables the account on their MIS leaving date. It also creates mail groups based on classes, and sets up Teams for us. I've not yet had a request they couldn't fulfill
Posted

Similar to others, we create and suspend accounts based on MIS data.

In our case Bromcom can do Google account provisioning but we find it too limited and there is no AD creation. So we have a custom in-house solution that pulls from Bromcom and creates accounts in AD and Google and adds to relevant groups which then sends emails with account details to appropriate parties. The same process checks and suspends/disables accounts based on MIS leaving date.

Posted

Another Salamander user here.

MIS is the only single point where everything is constant. Not only can you use it to onboard users, you can use it for door entry, class groups in Google and MS ect.

Posted
Another vote for Salamander. It won't complete eradicate issues if HR forgot to add start/end dates into employee records...but it really does make life a lot easier.
Posted
We use Bromcom's built in Google integration, which has been great for us. It relies on other staff keeping staff records in Bromcom up to date, but it creates our users without issue.
Posted
Question for those using Salamander. Do you get many occasions where an account needs to remain active in some capacity after the official leaving date, and if so, how do you accomodate it? For instance, we occasionally have a situation where a member of staff has left, but their account needs to remain active for some reason (e.g. they've retired but come in every so often to help out over the next year). They'll still be bound by a data protection agreement with the school, although not a full employee on the payroll. We also keep students leavers' mailboxes active after exam results and into the new term, to accomodate appeals, resits, return of text books, etc. I'd love to have something like Salamander in place to automate account provisioning some more, but would like to retain that flexibility also.
Posted
Yes, Salamander have this set up for us. We have a user defined field in SIMS - "retain account", with a tick box. If Retain Account is Yes, Salamander doesn't archive it. Similarly, we have a "Do not Provision" tickbox, for those employees who do not need a computer account.
  • Thanks 2
Posted
Question for those using Salamander. Do you get many occasions where an account needs to remain active in some capacity after the official leaving date, and if so, how do you accomodate it? For instance, we occasionally have a situation where a member of staff has left, but their account needs to remain active for some reason (e.g. they've retired but come in every so often to help out over the next year). They'll still be bound by a data protection agreement with the school, although not a full employee on the payroll. We also keep students leavers' mailboxes active after exam results and into the new term, to accomodate appeals, resits, return of text books, etc. I'd love to have something like Salamander in place to automate account provisioning some more, but would like to retain that flexibility also.

We have Salamander to only deactivate the user's account 7 days after their official leaving date. This is because we've had several occasions where HR has added the wrong leaving date, before the user actually leaves, or a user has left and come back to employment within a short space of time. For leavers that we are aware of, we change their password manually and deactivate their staff pass to prevent unathorised access to the systems.

 

As for the mailboxes, we have Salamander convert them to shared mailboxes, which keeps the mailbox intact and can be accessed again at any time, regardless of account status. For example, we recently had to go into a mailbox of a member of staff who left 4 years ago.

Posted
Question for those using Salamander. Do you get many occasions where an account needs to remain active in some capacity after the official leaving date, and if so, how do you accomodate it? For instance, we occasionally have a situation where a member of staff has left, but their account needs to remain active for some reason (e.g. they've retired but come in every so often to help out over the next year). They'll still be bound by a data protection agreement with the school, although not a full employee on the payroll. We also keep students leavers' mailboxes active after exam results and into the new term, to accomodate appeals, resits, return of text books, etc. I'd love to have something like Salamander in place to automate account provisioning some more, but would like to retain that flexibility also.

 

I'd say if they are on coming in to work, even volunteering, you should have a record of them in your MIS to keep track of DBS and emergency contacts. Speak to Salamander though as they seem to be able to do just about everything except make AD sit up and beg using their framework.

  • Thanks 1
Posted
Question for those using Salamander. Do you get many occasions where an account needs to remain active in some capacity after the official leaving date, and if so, how do you accomodate it?

 

We have a user defined field in SIMS - "retain account", with a tick box. If Retain Account is Yes, Salamander doesn't archive it. Similarly, we have a "Do not Provision" tickbox, for those employees who do not need a computer account.

Nice - we have a 'Do not provision' but not a 'Retain account'.

 

We do however make use of the "Service Agreement" in a staff record; ITTs and other long-term cover staff who are not employed/contracted but need timetable and account have a service agreement.

 

Salamander only disables you if you've exceeded the last-dated agreement on your record.

Posted
Thanks everyone for your feedback. The problem we have is that not all our provisions have an MIS and the HR team uses a HR system for staff which im not 100% sure it will work with Salamander so something i will have to check.
Posted

We had similar and still do if I'm being honest. :(

 

I put some things in place which stopped the knock on the office door saying "can I have an account?" and not having a clue who they were.

 

However I push it back to HR/Admin etc as it's their job. ESPECIALLY as ours is all provisioned via SIMs into Office 365 and everything. They add them to SIMs, they get provisoned, they make them a leaver, they get disabled.

 

That pushes it back to HR to do their job.

Posted
Thanks everyone for your feedback. The problem we have is that not all our provisions have an MIS and the HR team uses a HR system for staff which im not 100% sure it will work with Salamander so something i will have to check.

 

Im am not 100% and it could get a little messy if they could, but Salamander could in theory onboard/offboard users via a CSV/XML file that HR could be in charge off. It would requre a little bit of thinking to work it all out to start with.

This could be done manually or if the HR system could auto extract data into a CSV/XML then I am sertain that Salamander could work with that.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...