Skip to content

Onboarding & Offboarding Checklist

Shared with the CNT

This procedure runs on infrastructure the lab and the CNT operate together. The CNT manual keeps its own copy; changes to the shared steps are agreed with the CNT.

What this page tells you

Every account, server, listserv and protocol a new member may need, who requests it, how, and what is removed when the person leaves. Owners are roles, not people; the current holder of each role is in the lab's people directory.

The PI confirms the start date and which systems the person needs; the data research coordinator requests the technical accounts; the regulatory coordinator handles the IRB protocols; the lab administrator handles logistics. Nobody needs every line. Students and postdocs working only with de-identified data stop at the SEAS servers and GitHub; hospital systems are requested only for people who will work with identified data or in the clinic. The step-by-step request procedures are linked from Getting set up.

Logistics (lab administrator and PI)

Item At onboarding At offboarding
Onboarding and offboarding forms Welcome form sent before day one Exit form; end date recorded
PennKey, department email Confirmed with the department business office Removed by the department on the end date
Lab and department websites Person added Person removed
Listservs and Slack Added to the lab list, the shared CNT lists if applicable, and Slack Removed
Computer and peripherals Ordered or assigned; office supplies Computer returned and wiped

Protocols (regulatory coordinator)

Item At onboarding At offboarding
IRB protocols Added to each protocol the person will work under, after CITI and HIPAA training: Adding Personnel to an IRB Study or Adding a Non-Penn / New Hire Removed from each protocol at the next modification
Study personnel list Updated Updated

Compute and data systems (data research coordinator)

Requested through the CETS or PMACS helpdesk as described in Submitting CETS & PMACS Helpdesk Tickets; a person must be on the relevant IRB before access to systems that hold identified data is requested.

System How it is requested At offboarding
SEAS servers (Borel, Pioneer, Leif, Finkel) and user groups Data research coordinator emails CETS Removed from the servers and groups
SEAS sponsored research account and SEAS email Data research coordinator emails CETS; email can be requested on its own Expires after at most one year unless renewed
GlobalProtect VPN Comes with the SEAS account Expires with the account
MATLAB licence (CETS) Faculty or the user asks the data research coordinator, who emails CETS Released
PMACS account, VDI, Ivanti Secure VPN Data research coordinator submits a PMACS helpdesk ticket: PMACS VPN Deactivated when the person leaves Penn
BSC cluster project folders PMACS helpdesk ticket Removed from the project groups
cnt1 and cnt-fs (identified data) After IRB membership, PMACS helpdesk ticket for the matching user groups Removed from the groups
cntgpu1 PMACS helpdesk ticket Removed
REDCap account and project access Requesting a REDCap Account; project access granted by the project owner Removed from each project
PMACS helpdesk ticketing rights PMACS helpdesk ticket, for staff who will file tickets themselves Removed
Azure archive accounts PMACS helpdesk ticket Removed
Pennsieve workspace Granted by a workspace administrator: Pennsieve Data Access Rules Removed
ieeg.org projects Added by an existing project member: Adding Users to the ieeg.org Portal Removed from the projects
Penn+Box folders Shared by the folder owner Removed
GitHub organisation Added by an organisation owner Removed
AWS accounts (ieeg.org infrastructure) Granted by the account owner, only for people who maintain it Removed

Hospital systems (only for people who need them)

System How it is requested At offboarding
PennMedicine account and email, PennChart Through the department's PennMedicine sponsor; PennChart training first Deactivated by the hospital
UPHS F5 VPN, Citrix remote desktop, UPHS desktops UPHS IS helpdesk ticket: UPHS F5 VPN Access, Citrix Remote Desktop Access Removed
Isilon neurology share, EMU shared drive UPHS IS helpdesk ticket: Requesting Shared Drive Access Removed

When someone leaves

Set the end date with the department and the data research coordinator a month ahead where possible. Before the last day: data and code handed over to a named person and documented (Leaving the lab); personal copies of identified data deleted and confirmed; accounts above removed in the order listed, hospital systems first; computer returned. Shared credentials the person knew are rotated.