Onboarding and Offboarding Across a Franchise Network

Retail-side networks have high staff turnover across many sites. Every arrival and every departure is an access decision, and at scale those decisions are made hundreds of times a year by people who are not in IT.
A store manager needs a new casual on the floor by tomorrow morning. Someone else left last Friday and nobody told head office. The speed of the first and the silence of the second are the same problem expressed in opposite directions.
In a single-site business, onboarding and offboarding are handled by whoever is available. In a network, the absence of a repeatable process means access decisions are made inconsistently, late, or not at all — and the gap between a person leaving and their access being removed is where the risk lives.
The short answer
Onboarding and offboarding must be automated, repeatable processes built on centralised identity management — so that when someone joins at any location, the right accounts, permissions and security settings are provisioned from a template without manual decisions, and when someone leaves, every account is removed across every system without relying on someone remembering to ask. The LOOKUP Business Modernisation Framework™ provides the staged method for building that capability.
Two problems that look like one
Onboarding is a speed problem: someone cannot work until they have access. Offboarding is a risk problem: someone can still work after they have left. They look like the same task — managing access — but they have opposite failure modes and need opposite attention.
Businesses usually solve the first and neglect the second, because only the first generates complaints. A new starter who cannot log in calls immediately. A departed staff member who can still log in does not call at all. The absence of a complaint is not evidence that offboarding is working.
In a franchise network, the gap is wider because the person who knows someone has left is a store manager, not an IT manager. The information has to travel from the site to head office to whoever manages accounts, and at each step it can stall. By the time it arrives, the person's access may have been live for days or weeks.
Treating onboarding and offboarding as a single, symmetrical process — the same template, the same trigger, the same owner — is what closes both gaps at once.
Onboarding a new franchisee or location
When a new location opens, the technology setup has to be provisioned quickly and consistently. Quickly, because the opening date is fixed and staff need to work from day one. Consistently, because every location that deviates from the standard becomes a support problem and a security gap that head office inherits later.
Consistently means the same accounts, the same permissions, the same security settings, without anyone deciding case by case. A store manager should not be choosing which licences to request. A franchisee should not be setting up their own email. The standard defines what a location gets, and provisioning applies it.
This is the same principle as opening new locations on a repeatable blueprint: the value is not in any individual choice but in the fact that it is identical every time. Onboarding staff at a new or existing location is the access layer of that same blueprint.
How this maps to the LOOKUP Business Modernisation Framework™
Building reliable onboarding and offboarding across a franchise network follows the same eight-stage sequence — understanding the current state before securing it, standardising before automating, and preparing for AI only after the foundations are in place.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Discover
Map every system, account type and access level across the network to understand what onboarding and offboarding currently involves at each location and where the gaps are.
Secure
Enforce multi-factor authentication and conditional access on every account so that provisioning and deprovisioning happen within a controlled identity environment, not in the open.
Modernise
Move identity and account management into Microsoft 365 so that joiner, mover and leaver processes run through a single central platform rather than scattered local systems.
Standardise
Define the standard account templates, permission sets and security policies that every new location and new staff member receives, so provisioning is repeatable without manual decisions.
Optimise
Automate the joiner and leaver workflows so that a trigger from the franchise or HR system provisions or removes accounts across every connected system without a manual handoff.
Prepare
Ensure permissions and data boundaries are clean enough that future AI tools for access review and anomaly detection can rely on the identity structure already in place.
Implement
Deploy the automated onboarding and offboarding workflows at a pilot location, prove the process end to end, then replicate it across the network site by site.
Improve
Review access reports regularly to catch accounts that should have been removed, refine the templates based on what the network actually needs, and close the loop on every gap found.
Onboarding staff at a location
When a new staff member joins at any location, the goal is simple: the right accounts exist, the correct access is granted for their role, and the person is productive on their first shift. That sounds straightforward, but in a network it breaks down when every site handles it differently and nobody at head office can see what was actually granted.
The most common shortcut — copying a colleague's access because it is faster than working out what the new role actually needs — is where permission creep begins. One person's accumulated access, built up over years and across roles, gets inherited by the next person, and then the next, until every store manager has access to systems and information their role was never meant to reach. The shortcut feels harmless in the moment and is invisible until someone asks why a casual at one site can see financial reports for the whole network.
The fix is role-based provisioning: the role defines the access, not the person who held it last. A new starter is assigned a role, and the role carries a defined set of accounts, permissions and security settings. Nobody copies, nobody guesses, and the access granted is the access the role requires — nothing more.
This matters across franchise groups because the volume of joiners is high and the people doing the onboarding are not IT specialists. A repeatable, role-based process is what makes that volume manageable without it becoming a security liability.
Offboarding, and why it is usually incomplete
Offboarding is the process that protects business data and brand integrity after someone leaves. It is also the process most likely to be incomplete, because the person who left is not there to complain and the people who remain assume someone else handled it.
Shared accounts nobody owns
Generic store logins, shared mailbox accounts and communal point-of-sale credentials do not get disabled when a person leaves, because they are not tied to a person. They sit there, live, accessible to anyone who knows the password — including the person who just left.
Devices that go home
Staff devices — phones, tablets, laptops — are often not returned or remotely wiped when someone departs. A device that still has email, documents and network access configured is a live connection to the business sitting in someone's home.
Mobile and remote access
VPN credentials, remote desktop sessions and mobile device management enrolments can persist long after a person's main account is disabled. If offboarding only checks the primary email account, every other path in remains open.
Third-party and supplier systems
Staff often have logins to external platforms — rostering tools, supplier portals, delivery services — that are provisioned outside the main IT environment. Nobody at head office may even know these accounts exist, let alone have a way to remove them.
Accounts at sites head office does not manage directly
In a franchise network, some accounts are created locally by the store and never visible to head office. When someone leaves, the site may disable what they know about and miss what they do not — and head office has no list to check against.
This is why incomplete offboarding is directly connected to containing an incident before it spreads across the network: a live account belonging to someone who has left is an access path an attacker does not need to compromise, only to find.
Role-based access as the answer to both
When access is attached to a role rather than a person, both problems shrink. Onboarding becomes assignment: a new starter is given a role, and the role carries the accounts and permissions. Offboarding becomes removal: the role is taken away, and everything attached to it goes with it. Nobody has to remember a list, because the list is the role.
This is harder than it sounds because it requires the business to define its roles — what each one needs and does not need — before anyone joins or leaves. That work is front-loaded. But once it is done, every subsequent joiner and leaver is faster, more consistent and more complete than a manual process will ever be.
The Essential Eight, published by the Australian Signals Directorate as a baseline set of mitigation strategies, includes restricting administrative privileges as one of its strategies. Role-based access is the practical expression of that principle: people reach what their role requires, and nothing beyond it, which is what makes both onboarding and offboarding tractable at network scale.
What good looks like
A defined joiner process
A new starter triggers a workflow that creates the right accounts, assigns the right role-based permissions, enrolls the device and applies security settings — all before the person arrives for their first shift, with a named owner accountable for the process.
A defined leaver process
A departure triggers a workflow that removes every account, revokes every access path, wipes or recovers devices and disables shared credentials — with a named owner who confirms completion rather than assuming someone else did it.
Access granted and removed centrally
Both processes run through a single identity platform, not a patchwork of local systems, so that head office can see what was granted and what was removed across every location without having to ask each site.
The ability to answer who has access to what, today
At any point, a director at head office can produce a current list of who has access to which systems across the network — not a list that was accurate at some point in the past, but one that reflects the state of access right now, with named owners for both the joiner and leaver processes.
How LOOKUP helps
Microsoft 365 identity management
LOOKUP configures Microsoft 365 as the central identity platform for the network, so every account — head office, store managers and floor staff — is created, managed and removed through one tenant rather than a patchwork of local directories.
Role-based access design
LOOKUP works with head office to define the roles the network actually uses and the access each role requires, so that onboarding becomes assignment and offboarding becomes removal rather than a manual checklist that someone has to remember.
Device enrolment and management
LOOKUP sets up device enrolment so that phones, tablets and point-of-sale hardware are provisioned to a standard, monitored while in use, and remotely wiped when someone leaves — closing the gap that devices going home create.
Repeatable joiner and leaver processes
LOOKUP builds the joiner and leaver workflows so they run the same way at every location, whether that is a long-standing site or opening a new location on the same blueprint. LOOKUP coordinates with point of sale and line-of-business platforms rather than replacing them, so the identity layer sits on top of the systems the network already runs.
Frequently asked questions
What should happen on a new staff member's first shift?
A new staff member should arrive to find their accounts already created, their role-based access assigned, their device enrolled and their line-of-business applications ready — so they are productive from the first shift rather than waiting for IT to catch up. The joiner process should be triggered before the person starts, not after they walk through the door. Anything that has to be requested on the day is a gap in the process, not a feature of it.
Why does copying an existing person's access cause problems?
Copying a colleague's access gives a new starter everything that person accumulated over years — including permissions they no longer need, tools they never used and access to areas unrelated to their role. That is how permission creep begins, and it is why every offboarding becomes harder than the last. Role-based access replaces the copy approach by assigning a defined set of permissions for the role, not the person sitting in it.
How quickly should access be removed after someone leaves?
Access removal should be tied to the departure itself, not to a later review or a convenient pause in the schedule — ideally before the person's final shift ends, and certainly before any account remains active overnight after a departure. The trigger should be the leaver notification from the location, and the action should be automatic rather than waiting for someone to remember. Any delay is a window in which a former staff member can still reach business systems.
What typically gets missed when someone leaves a franchise location?
The things most commonly missed are shared store accounts nobody personally owns, personal devices that go home, mobile and remote access tokens, third-party supplier logins, and accounts at sites head office does not manage directly. Each of these survives offboarding because nobody is specifically responsible for it. A complete leaver process names every category and assigns an owner to each.
Who is responsible for offboarding at a franchisee-owned site?
Head office owns the identity and access layer — the Microsoft 365 tenant, the conditional access policies and the central directory — even at franchisee-owned sites, because a gap at one location is a network risk. The franchisee owns the local notification: telling head office someone has left, returning devices and confirming local systems are closed out. The split has to be documented so neither side assumes the other handled it.
How should a shared store account nobody personally owns be handled?
Shared store accounts should be replaced with individual accounts wherever possible, because an account nobody owns is an account nobody removes — and it becomes a permanent back door into the network. Where a shared account is genuinely unavoidable, it should have a named owner at the location, a strong password that is rotated on a schedule and multi-factor authentication tied to a device rather than a person. It should appear on the access review list so it is never forgotten.
What happens to a device when the person using it leaves?
The device should be enrolled in a management platform that allows head office to remotely wipe it the moment the person leaves, removing business data and access without waiting for the device to be returned. If the device is personally owned, the management profile should separate business data from personal data so the business side can be removed without touching the personal side. A device that goes home with someone who has left is one of the most common gaps in franchise offboarding.
How do you revoke access to third-party and supplier systems?
Third-party and supplier access should be inventoried as part of the joiner process, so that when someone leaves there is a list of external systems to close out — not a scramble to remember what the person could reach. Where a third-party system supports single sign-on through Microsoft 365, removing the Microsoft account removes the third-party access automatically. Where it does not, the leaver process needs a named step for each external system.
What does role-based access actually mean in practice?
Role-based access means permissions are attached to a defined role — store manager, floor staff, area manager — rather than to an individual, so that onboarding becomes assigning a role and offboarding becomes removing it. When someone changes role, their old role is removed and the new one assigned, rather than layering new permissions on top of old ones. It is the single change that makes both joiner and leaver processes repeatable across a network.
Can head office remove access at a site it does not manage directly?
Yes, if the identity layer is centralised in Microsoft 365 — head office can disable an account, revoke conditional access and trigger a device wipe regardless of which site the person worked at, because the account lives in the tenant head office owns. That is the structural reason for centralising identity rather than leaving each site to run its own directory. The local site does not need to act for the access to be removed.
How do you onboard a whole new location rather than one person?
Onboarding a new location means provisioning the tenant configuration, licences, security policies, device profiles and role templates before the site opens, so that every staff member who joins afterward is assigned a role that already exists rather than having access built from scratch. The location onboarding is the blueprint; the staff onboarding is the process that runs on top of it. Both should be repeatable rather than invented per site.
How do you know who currently has access to what across the network?
You run an access review — a structured check of who holds which role, which accounts are active and which devices are enrolled — and you do it on a schedule rather than only when something goes wrong. Centralised identity in Microsoft 365 makes this a report rather than a site-by-site audit. If the answer takes longer than a report, the access is not centralised enough to be managed.
What happens to access when someone changes role rather than leaving?
A role change should trigger the same removal-and-assignment process as a departure followed by an arrival — the old role's access is removed and the new role's access is assigned, rather than adding the new permissions on top of the old ones. Without this, people accumulate access across every role they have ever held, and the access review becomes impossible. The joiner-leaver process should treat role changes as a first-class event, not an afterthought.
How do you keep the joiner and leaver processes from decaying over time?
The processes decay when nobody owns them, so each one needs a named owner inside head office and a review point on a schedule — not a one-off document that sits in a folder. The access review is the mechanism that catches the decay: if the review finds accounts that should have been removed, the process has a gap, and the gap gets fixed. A process that is never reviewed is a process that has already stopped working.
Where do you start if there is no documented joiner or leaver process today?
Start with identity: centralise accounts in Microsoft 365 if they are not already, so that every person and every site is visible in one tenant rather than scattered across local directories. Then define the roles the network uses and the access each role needs, because role-based access is the foundation both processes are built on. Documenting the process comes after the identity layer is in place — a document describing a system that does not exist yet is just paper.
Sources & Further Reading
The following primary and authoritative sources support the research, guidance and industry context discussed on this page:
Essential Eight — Australian Signals Directorate's Australian Cyber Security Centre
A baseline set of mitigation strategies, which include restricting administrative privileges.
View SourceGuidance for AI Adoption — National AI Centre, Department of Industry, Science and Resources
Six essential practices for governing and adopting AI responsibly, which depend on knowing who has access to what.
View SourceEvidence Standard
LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
Ready to make joiners and leavers reliable across every location?
If access at your locations is still managed by hand, book a strategy session with LOOKUP to design a repeatable onboarding and offboarding process that works across the whole network.
Peter Kantarelis
Founder, LOOKUP — Business Technology Strategist
Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.
View More Insights