Onboarding & Offboarding Checklist¶
Shared with the CNT
This procedure runs on infrastructure the lab and the CNT operate together. The CNT manual keeps its own copy; changes to the shared steps are agreed with the CNT.
What this page tells you
Every account, server, listserv and protocol a new member may need, who requests it, how, and what is removed when the person leaves. Owners are roles, not people; the current holder of each role is in the lab's people directory.
The PI confirms the start date and which systems the person needs; the data research coordinator requests the technical accounts; the regulatory coordinator handles the IRB protocols; the lab administrator handles logistics. Nobody needs every line. Students and postdocs working only with de-identified data stop at the SEAS servers and GitHub; hospital systems are requested only for people who will work with identified data or in the clinic. The step-by-step request procedures are linked from Getting set up.
Logistics (lab administrator and PI)¶
| Item | At onboarding | At offboarding |
|---|---|---|
| Onboarding and offboarding forms | Welcome form sent before day one | Exit form; end date recorded |
| PennKey, department email | Confirmed with the department business office | Removed by the department on the end date |
| Lab and department websites | Person added | Person removed |
| Listservs and Slack | Added to the lab list, the shared CNT lists if applicable, and Slack | Removed |
| Computer and peripherals | Ordered or assigned; office supplies | Computer returned and wiped |
Protocols (regulatory coordinator)¶
| Item | At onboarding | At offboarding |
|---|---|---|
| IRB protocols | Added to each protocol the person will work under, after CITI and HIPAA training: Adding Personnel to an IRB Study or Adding a Non-Penn / New Hire | Removed from each protocol at the next modification |
| Study personnel list | Updated | Updated |
Compute and data systems (data research coordinator)¶
Requested through the CETS or PMACS helpdesk as described in Submitting CETS & PMACS Helpdesk Tickets; a person must be on the relevant IRB before access to systems that hold identified data is requested.
| System | How it is requested | At offboarding |
|---|---|---|
| SEAS servers (Borel, Pioneer, Leif, Finkel) and user groups | Data research coordinator emails CETS | Removed from the servers and groups |
| SEAS sponsored research account and SEAS email | Data research coordinator emails CETS; email can be requested on its own | Expires after at most one year unless renewed |
| GlobalProtect VPN | Comes with the SEAS account | Expires with the account |
| MATLAB licence (CETS) | Faculty or the user asks the data research coordinator, who emails CETS | Released |
| PMACS account, VDI, Ivanti Secure VPN | Data research coordinator submits a PMACS helpdesk ticket: PMACS VPN | Deactivated when the person leaves Penn |
| BSC cluster project folders | PMACS helpdesk ticket | Removed from the project groups |
| cnt1 and cnt-fs (identified data) | After IRB membership, PMACS helpdesk ticket for the matching user groups | Removed from the groups |
| cntgpu1 | PMACS helpdesk ticket | Removed |
| REDCap account and project access | Requesting a REDCap Account; project access granted by the project owner | Removed from each project |
| PMACS helpdesk ticketing rights | PMACS helpdesk ticket, for staff who will file tickets themselves | Removed |
| Azure archive accounts | PMACS helpdesk ticket | Removed |
| Pennsieve workspace | Granted by a workspace administrator: Pennsieve Data Access Rules | Removed |
| ieeg.org projects | Added by an existing project member: Adding Users to the ieeg.org Portal | Removed from the projects |
| Penn+Box folders | Shared by the folder owner | Removed |
| GitHub organisation | Added by an organisation owner | Removed |
| AWS accounts (ieeg.org infrastructure) | Granted by the account owner, only for people who maintain it | Removed |
Hospital systems (only for people who need them)¶
| System | How it is requested | At offboarding |
|---|---|---|
| PennMedicine account and email, PennChart | Through the department's PennMedicine sponsor; PennChart training first | Deactivated by the hospital |
| UPHS F5 VPN, Citrix remote desktop, UPHS desktops | UPHS IS helpdesk ticket: UPHS F5 VPN Access, Citrix Remote Desktop Access | Removed |
| Isilon neurology share, EMU shared drive | UPHS IS helpdesk ticket: Requesting Shared Drive Access | Removed |
When someone leaves¶
Set the end date with the department and the data research coordinator a month ahead where possible. Before the last day: data and code handed over to a named person and documented (Leaving the lab); personal copies of identified data deleted and confirmed; accounts above removed in the order listed, hospital systems first; computer returned. Shared credentials the person knew are rotated.