IT Glossary
Employee onboarding takes a new hire from contract to productive. Learn what the IT half involves and why day-one access still slips so often.
August 7, 2026
Employee onboarding is the process that takes a new hire from signed contract to fully productive team member, covering administrative setup, IT provisioning, training, and integration into the team. In identity terms it is the joiner stage of the joiner, mover, leaver lifecycle, and it is the moment when every account, license, and permission a person will hold is first created.
The list above is not technically hard. What breaks it is scope: the HR trigger covers the ten applications IT knows about, while the new hire actually needs twenty-five, several of which the manager will request informally in week two. Copying another employee access is the usual shortcut, and it is also the origin of most privilege creep, because the template carries permissions the new role never needed.
A 250-person company hires eight people in one month. Each needs Google Workspace, Slack, the HR portal, and between six and twenty role-specific tools. Manual setup takes roughly three hours per hire and still misses two or three applications, which surface as tickets during the first week. Automating provisioning from the HR record cuts that to minutes and, more usefully, produces a written record of exactly what each role receives. Corma runs that provisioning across the full SaaS estate, not only the federated applications.
Onboarding is the whole employee experience, including training and team integration. Provisioning is the technical subset that creates the accounts and assigns the permissions.
HR usually triggers it and IT executes it. The failure point is the handover between the two, which is why most companies connect the HR system directly to the identity workflow.
Access should be ready before the first day. With provisioning automated from the HR record, the technical setup takes minutes rather than hours of manual account creation.
Because it duplicates permissions the new role does not need, including everything the colleague accumulated over years. It builds privilege creep into a brand new account.