Onboarding of an Employee Procedure
This is a Controlled Document
In line with Vaxa's governance framework, changes to controlled documents must be approved or merged by a code owner. All contributions are welcome and encouraged.| Version | Effective | Reviewed | Next review due |
|---|---|---|---|
| 1.0.0 | 2025-01-05 | 2025-01-05 | 2026-01-05 |
Purpose
This procedure establishes a standardized and compliant process for onboarding employees at Vaxa, whether they are casual, part-time, or full-time. It ensures consistent implementation of:
- Australian employment law obligations (Fair Work Act 2009)
- ISO27001 information security requirements
- DISP insider threat management controls
- Personnel screening and background check requirements
- System access and identity management controls
This procedure is critical to ensuring we properly vet, onboard, and integrate new employees while managing insider risk and maintaining compliance with our legal and regulatory obligations.
Scope
This procedure applies to all employees engaged by Vaxa, including:
- Full-time employees: Permanent staff working standard full-time hours
- Part-time employees: Permanent staff working regular but reduced hours
- Casual employees: Staff engaged on an as-needed basis with casual loading
This procedure does not cover:
- Contractors (see Onboarding of a Contractor Procedure)
- Vendors or suppliers providing products/services
- Volunteers or unpaid interns
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Employee | Provide required documentation to complete the onboarding process, complete mandatory training, and adopt required controls and policies |
| HR Lead | Manage the employment contract process, Xero setup, superannuation enrolment, Fair Work compliance, and ensure all administrative requirements are met |
| Hiring Manager | Define role requirements, determine screening level, conduct interviews, provide onboarding context to IT and HR, and manage probationary period reviews |
| IT | Set up the employee in required systems, provision access based on role and security level, provide devices as required, and deliver IT orientation |
| Legal | Review employment contracts for compliance, ensure Fair Work Act adherence, manage any employment-related legal risks |
| Security Officer | Oversee background screening process, conduct security awareness training, ensure DISP and ISO27001 compliance, monitor insider threat indicators |
Procedure
Position Approval & Role Definition
Before commencing recruitment, ensure:
- Budget approval has been obtained for the position
- Position description is current and accurate, including:
- Role title and reporting line
- Key responsibilities and deliverables
- Required qualifications and experience
- Employment type (casual/part-time/full-time)
- Salary range or wage rate
- Working arrangements (office/remote/hybrid)
- Screening level is determined based on the role’s access requirements:
- Level 2 (Standard): Most employees with typical system access
- Level 3 (Sensitive Access): Employees with access to sensitive information, financial systems, or who could cause significant reputational damage
- Level 4 (Executive): Directors and senior leaders with strategic decision-making authority
See the Personnel Screening Policy for detailed screening level criteria.
Candidate Selection
Initial Recruitment
- Advertise the position through appropriate channels
- Review applications against selection criteria
- Conduct initial screening interviews
- Perform preliminary reference checks
- Shortlist candidates for detailed assessment
Pre-Offer Considerations
Before extending an offer, consider whether:
- An NDA is required prior to sharing sensitive information during the interview process
- The candidate requires any workplace adjustments or accommodations
- There are any conflicts of interest that need to be managed (see Conflict of Interest Policy)
Background Screening
Under our Personnel Screening Policy, all employees must undergo comprehensive background screening via our approved provider, Certn. The screening level determines the depth of checks required.
All employment offers must be conditional on successful completion of background screening.
Level 2 (Standard) - Mandatory Checks
All employees at Level 2 and above must undergo:
- 100 points of ID verification: Passport, driver’s license, birth certificate, or equivalent
- Right to work in Australia: Citizenship, permanent residency, or valid work visa
- 5-year address history: Verified and cross-referenced against sensitive countries
- National police check: Must be less than 12 months old at time of engagement
- Character references: Two references verified and documented
- Referee checks: Professional references from previous employers
- Social media assessment: Review of publicly available social media profiles
- Qualification and experience verification: Verification of claimed credentials directly with issuing institutions
Level 3 (Sensitive Access) - Additional Checks
In addition to Level 2 checks, Level 3 employees require:
- Employment history verification: Detailed verification including Defence-related work (if applicable)
- Credit check: Basic public record credit check (mandatory for those with financial system access)
- Professional membership verification: Direct verification with professional bodies where membership is required for the role
Level 4 (Executive) - Additional Checks
In addition to Level 2 and 3 checks, Level 4 employees require:
- ASIC checks: Banned & Disqualified Persons, Enforceable Undertakings Register, and Australian Directorships
- Comprehensive credit check: Detailed financial history assessment
- Enhanced employment history: Comprehensive verification of all previous roles and responsibilities
Screening Process
- Hiring Manager confirms screening level requirement with Security Officer
- HR Lead initiates screening via Certn once candidate accepts conditional offer
- Candidate provides required documentation and consents to screening
- Certn conducts checks and provides outcome report
- Security Officer reviews screening outcomes and approves or raises concerns
- Only upon successful screening can final employment offer be confirmed
Note: Screening must be completed before the employee’s start date. No system access or onboarding can commence without successful screening completion.
Employment Offer & Contract
Conditional Offer Letter
Once a suitable candidate is identified and preliminary checks are positive, issue a conditional offer letter including:
- Position title and classification
- Employment type (casual/part-time/full-time)
- Proposed salary/wage (including casual loading if applicable)
- Superannuation contribution details (currently 11.5%, increasing to 12% from 1 July 2025)
- Leave entitlements (varies by employment type - see below)
- Probationary period (6 months standard)
- Proposed start date
- Reporting manager
- Working arrangements and location
- Condition: Offer subject to satisfactory background screening and reference checks
Employment Contract
Once screening is successfully completed, Legal will prepare the employment contract. The following information is required:
Employee Details:
- Full legal name
- Date of birth
- Residential address
- Contact phone number
- Email address (personal)
- Emergency contact details
- Tax File Number (TFN)
- Superannuation fund details
Employment Specifics:
- Position title for Vaxa systems
- Employment type (casual/part-time/full-time)
- Salary/wage and payment frequency
- Hours of work (for part-time) or minimum engagement (for casual)
- Superannuation fund and contribution rate
- Leave entitlements based on employment type
- Probationary period terms (6 months)
- Notice period requirements
- Place of work and working arrangements
- Any specific conditions or requirements
- Applicable Modern Award or Enterprise Agreement
- Optionally: headshot photo for use in Vaxa systems
Internal Details:
- Direct manager/supervisor
- Any client SharePoint sites the employee will require access to
- Project budgets in Productive the employee needs access to
- System access requirements (e.g., BitWarden, production environments, finance systems)
- Device requirements (laptop, phone, etc.)
Provide this information to Legal, who will prepare the contract. The contract shall be sent to the employee for signing, and once returned, the onboarding process can proceed.
Signed contracts are automatically filed in the Contract Register via the Vaxa Link integration.
Employment Type Considerations
Full-Time Employees:
- Standard 38 hours per week (or as specified in contract)
- Full annual leave entitlement (4 weeks per year, accruing progressively)
- Full personal/carer’s leave entitlement (10 days per year, accruing progressively)
- Entitled to public holidays without loss of pay
- Notice period as per Fair Work Act or contract (typically 1-4 weeks)
- Eligible for all employee benefits and programs
Part-Time Employees:
- Regular guaranteed hours (e.g., 20 hours per week)
- Pro-rata annual leave based on hours worked
- Pro-rata personal/carer’s leave based on hours worked
- Entitled to public holidays (pro-rata)
- Notice period as per Fair Work Act or contract
- Eligible for employee benefits (may be pro-rata)
Casual Employees:
- Casual loading (typically 25%) in lieu of leave entitlements
- No annual leave or personal/carer’s leave
- Not entitled to paid public holidays (receive loading instead)
- Minimum notice periods may not apply (check Modern Award)
- May convert to permanent after 12 months (Casual Conversion provisions under Fair Work Act)
- System access and training may be limited to essential requirements only
Pre-Start Administrative Setup
Once the contract is signed, HR Lead commences administrative setup before the employee’s start date.
Xero Payroll Setup
- Create new employee record in Xero
- Enter personal details (name, DOB, address, contact details)
- Record TFN and tax-free threshold election
- Set up superannuation details (fund name, member number, contribution rate)
- Configure pay template:
- For full-time/part-time: ordinary hours, salary rate
- For casual: casual hourly rate with loading
- Set up leave entitlements (if applicable)
- Record bank account details for salary payments
- Assign to appropriate pay calendar
- Configure any automatic deductions or allowances
Required Documentation
Ensure the employee provides the following before commencing:
- Tax File Number Declaration (ATO form)
- Superannuation Standard Choice Form (if choosing their own fund)
- Bank account details for salary payments (BSB, account number, account name)
- Proof of identity (certified copy of passport, driver’s license, or birth certificate)
- Work eligibility documents:
- Australian citizens: Birth certificate or passport
- Permanent residents: Visa evidence
- Temporary visa holders: Valid work visa with appropriate conditions
- Academic qualifications (original certificates or certified copies)
- Professional memberships (if relevant to role)
- Working with Children Check (if role requires contact with minors)
- Driver’s license (if role requires driving)
Insurance & Workers Compensation
- Ensure employee is covered under Vaxa’s workers compensation insurance
- Add employee to professional indemnity policy if required
- Update public liability insurance if employee numbers change significantly
IT & Systems Setup
IT setup cannot commence until the employment contract is signed, per our Information Security Policy.
Once the contract is signed, HR Lead notifies IT to commence system provisioning. IT will reference the contract and onboarding information provided by the Hiring Manager.
Entra / M365 Accounts
Step 1: Create User in M365 Admin Portal
- Visit admin.microsoft.com and log in with an admin account
- Navigate to
Users→Active Users - Click
Templatesand selectEmployee (Business Premium)template - Complete the form with:
- First name and last name (as per contract)
- Display name (First Last)
- Username:
first.last@vaxagroup.com - Position title (as per contract)
- Department (as applicable)
- Office location (if relevant)
- Mobile phone (as provided)
- Click
Add userto create the account- This automatically assigns an M365 Business Premium license
- Verify sufficient licenses are available before creation
- Locate the newly created user and assign their manager (usually the Hiring Manager)
- Navigate to
Groupsand clickManage groups - Assign to
OS_x_Employeesgroup at minimum - Assign to any additional role-based groups:
OS_x_Finance(for finance team members)OS_x_Technical(for engineers and technical staff)OS_x_Consultants(for client-facing consultants)- Client site access groups (as specified by Hiring Manager)
Step 2: Configure Authentication in Entra
- Visit entra.microsoft.com and log in with an admin account
- Navigate to
Users→All Usersand select the new employee - Click
Authentication methodsin the left menu - Click
Add authentication method - Select
Temporary Access Passand configure:- Lifetime: As short as practical but long enough for employee to set up (recommend 24 hours)
- Start time: Immediate or delayed to start date
- One-time use: Set to
No(allows multiple setup attempts if needed)
- Click
Addand copy the TAP code - Save the TAP into a Bitwarden Send with:
- Expiration matching TAP lifetime
- Deletion on first access for security
- Copy the Bitwarden Send link for the welcome email
Step 3: Send Welcome Email
Draft an email to the employee’s personal email address (not their Vaxa email, as they can’t access it yet) and CC the Hiring Manager and IT team:
Subject: Welcome to Vaxa - Setting up your account
Hi [Employee Name],
Welcome to the Vaxa team! We’re excited to have you joining us on [Start Date].
Your Vaxa account has been created and requires a few setup steps from you. Please follow these instructions to set up your authentication.
Important: This is a time-sensitive process - your Temporary Access Pass expires in 24 hours, so please complete the setup as soon as possible.
Your Temporary Access Pass: [Bitwarden Send Link]
Once you’ve completed the authentication setup, you’ll be able to access:
- Email and Microsoft 365: Your Vaxa email is
first.last@vaxagroup.com - Productive: Our project management and time tracking tool - access via Cloudflare Access
- Teams: For communication and collaboration
- SharePoint: For document management and client sites
[If applicable: We’ve also provisioned your access to:
- [List any additional systems, client sites, or specialized tools]]
Before your first day, please:
- Complete the authentication setup (instructions linked above)
- Set up your email signature (template will be provided on your first day)
- [Complete any pre-start training modules assigned in the LMS - we’ll send separate instructions]
If you have any questions or encounter any issues, please don’t hesitate to reach out to me directly.
We look forward to seeing you on [Start Date]!
Warm regards, [IT Team Member Name] IT Team, Vaxa
System Access Provisioning
By being assigned to the OS_x_Employees group, the employee will automatically receive access to core systems. Additional access is provisioned based on role and screening level:
All Employees:
- M365 Services: Email, Teams, SharePoint, OneDrive, Office apps (online and desktop)
- Productive: Project management and time tracking (accessed via Cloudflare SSO)
- Cloudflare Access Portal: vaxagroup.cloudflareaccess.com
- BitWarden: Password manager (all employees receive access)
- LMS: Learning Management System for training and compliance
Role-Based Access (as specified by Hiring Manager):
- Client SharePoint sites: Specific client workspaces as required
- Productive project budgets: View/edit access to project budgets for time/expense tracking
- Scheduling software (Cal.com): For client-facing staff requiring appointment scheduling
- Production IT environments: Engineers only (Google Cloud, AWS, Azure, etc.) - requires Level 3 screening minimum
- Finance systems (Xero, banking): Finance team only - requires Level 3 screening minimum
Access Approval Process:
- Standard access (as above): Automatic via group membership
- Privileged access (production systems, finance, etc.): Requires evaluation per Evaluation of Privilege Requests Procedure
Device Provisioning
For eligible employees, IT will provision corporate devices:
Full-Time Employees:
- MacBook (model based on role requirements) - standard issue
- Mobile phone if required for role
- Security key/hardware token for Level 3/4 employees
- Peripherals as required (monitor, keyboard, mouse, headset)
Part-Time Employees:
- Device provisioning based on role requirements and hours worked
- Generally provided for 20+ hours per week roles
Casual Employees:
- Device provision rare - usually BYOD arrangements
- If provided, must be returned immediately upon cessation
Device Setup:
- Configured per macOS Software Management policy
- Enrolled in MDM (Mobile Device Management)
- Standard software suite installed
- Added to asset register
- Asset tag applied
- Employee signs device acceptance form
Security & Compliance Onboarding
Security onboarding is mandatory for all employees and must be completed before they can access systems containing OFFICIAL or higher classified data.
Mandatory Security Training
All employees must complete the following training, ideally before their start date or on day one:
Information Security Awareness (LMS module)
- Understanding Vaxa’s security framework
- ISO27001 and DISP requirements overview
- Your role in maintaining security
Data Classification Training (LMS module)
- Understanding data classification levels
- Applying protective markings
- Handling requirements by classification
- See Data Classification Policy
Insider Threat Awareness (In-person or recorded briefing)
- Understanding insider risk indicators
- DISP compliance requirements
- Reporting obligations and processes
- See Insider Threat Statement
Privacy & Confidentiality (LMS module)
- Personal information handling
- Privacy Act obligations
- Client confidentiality requirements
- See Privacy Policy
Cyber Incident Response (LMS module)
- Recognizing security incidents
- Reporting procedures
- Phishing and social engineering awareness
- See Cyber Incident Response Plan
Policy Acknowledgments
All employees must read and acknowledge the following policies before commencing work. HR will track acknowledgments and maintain records:
- Code of Conduct - behavioural expectations and standards
- Information Security Policy - overarching security framework
- Data Classification Policy - data handling requirements
- Privacy Policy - personal information management
- Conflict of Interest Policy - disclosure obligations
Additional policy acknowledgments for specific roles:
- Privileged Access Policy - for Level 3/4 employees with elevated access
- Finance-related policies - for those with financial system access
Security Briefings
The Security Officer (or delegate) will conduct:
Initial Security Briefing (Day 1 or Week 1):
- Identity and access management (IAM) requirements
- Multi-factor authentication (MFA) setup and usage
- Password manager (BitWarden) setup and best practices
- Physical security (office access, visitor management, clean desk)
- Reporting security incidents and concerns
- Social engineering and phishing awareness
- Secure communication practices
DISP Insider Threat Briefing (if handling Defence-related work):
- Enhanced insider threat awareness
- Reporting obligations specific to Defence contracts
- Security clearance requirements (if applicable)
- Contact procedures for Defence Security incidents
First Day Induction
The Hiring Manager coordinates the first day experience to ensure the employee feels welcomed and prepared.
Welcome & Orientation
Morning:
- Welcome by Hiring Manager and team
- Office tour (if office-based) including:
- Workstation/desk allocation
- Kitchen and amenities
- Meeting rooms and bookable spaces
- Emergency exits and assembly points
- First aid facilities
- Introduction to team members and key stakeholders
- Overview of probationary period expectations
IT Equipment Handover:
- If devices were shipped to employee: Unboxing and setup assistance
- If devices issued in-office: Handover and asset acknowledgment signing
- Login credentials verification
- MFA device setup confirmation
- Email signature configuration
- Calendar and scheduling setup
Operational Setup
Productive Training:
- How to log time to projects
- Expense claiming process
- Project budget visibility
- Time approval workflows
- Mobile app usage (if applicable)
Communication Tools:
- Teams channels and etiquette
- Email best practices
- SharePoint site navigation
- File storage structure (OneDrive vs SharePoint vs local)
- Video conferencing setup and protocols
Work Processes:
- Project management workflows
- Client communication protocols
- Documentation standards
- Code of conduct practical applications
- Escalation procedures
Administrative Completion
Health & Safety:
- WHS induction
- Emergency procedures and evacuation plan
- First aid officer identification
- Incident reporting procedures
- Ergonomic workspace setup
- Mental health and wellbeing resources
Physical Access:
- Building access cards/keys issued
- Parking arrangements (if applicable)
- After-hours access procedures (if required)
- Visitor sign-in process
Additional First Day Tasks:
- Employee photo for directory (if not provided earlier)
- Completion of any outstanding forms
- Super fund enrolment confirmation
- Banking details verification
- Emergency contact confirmation
Probationary Period Management
All employees are subject to a 6-month probationary period during which performance and suitability are assessed.
30-Day Review
Conducted by: Hiring Manager
Purpose: Early check-in and course correction
Review areas:
- Settling in and cultural fit
- System access is complete and functional
- Initial training completion status
- Early performance indicators
- Any support needs or concerns
- Access rights are appropriate for role
Documentation: Brief notes in personnel file
90-Day Review
Conducted by: Hiring Manager with HR input
Purpose: Mid-probation formal assessment
Review areas:
- Performance against initial goals
- Competency development
- Training and development needs
- System access audit - confirm appropriate privileges
- Cultural alignment and team integration
- Any performance concerns requiring action
Documentation: Formal review meeting notes, performance feedback record
6-Month Probationary Review
Conducted by: Hiring Manager with HR Lead
Purpose: Confirm permanent employment or extend/terminate probation
Review areas:
- Overall performance against position requirements
- Achievement of probationary goals
- Competency levels
- Cultural fit and values alignment
- Attendance and conduct
- Recommendation: Confirm, extend, or terminate
Outcomes:
- Confirm employment: Probation successfully completed, becomes permanent employee
- Extend probation: Further time needed (typically 3 months), with clear improvement plan
- Terminate employment: Not suitable for role, notice given per Fair Work requirements
Documentation: Formal probation completion letter or extension/termination notice
During Probation
Reduced notice periods apply:
- First month: 1 day notice (either party)
- After first month: 1 week notice (either party)
Access Reviews:
- IT conducts access audit at 30 days to confirm appropriate provisioning
- Any changes to access based on evolving role understanding
Ongoing Compliance & Monitoring
Access Reviews
Per our IAM Policy, access must be regularly reviewed:
- Privileged access (Level 3/4, production systems, finance): Quarterly review by System Owners
- Standard access (general employees): Bi-annual review
- Role changes: Immediate access review and re-provisioning
Continuous Monitoring
The Security Officer monitors for insider threat indicators including:
- Unusual system access patterns
- Data exfiltration attempts
- Policy violations
- Performance issues or behavioural changes
- Financial distress indicators
- Unexplained affluence
See Insider Threat Statement for reporting procedures.
Ongoing Training & Awareness
- Annual security awareness refresher: All employees (LMS)
- Data classification updates: As policy evolves
- Role-specific training: As technologies and processes change
- Privacy Act updates: When legislation changes
- Ad-hoc security bulletins: As threats emerge
Re-Screening
Per the Personnel Screening Policy:
- Level 3/4 employees: Periodic re-screening at intervals determined by risk assessment
- All employees: May be re-screened if:
- Significant role change requiring elevated access
- Security concern arises
- Extended international travel to sensitive countries
- Required by client contracts
Performance Management
- Regular 1-on-1 meetings with manager
- Annual performance reviews
- Development plans and training opportunities
- Promotion and progression pathways
- Documented performance concerns and improvement plans
Exceptions
Some employees may require modified onboarding procedures due to:
- Remote/interstate location requiring different logistics
- Specialized roles with unique system requirements
- Expedited onboarding for urgent business needs (screening still mandatory)
- Client-specific requirements or clearances
Exception Process:
- Hiring Manager documents the exception requirement and justification
- HR Lead reviews for compliance implications
- Security Officer assesses for security risks
- Documented approval required before proceeding
- Exception and mitigating controls recorded in personnel file
Emergency Access: In rare cases where urgent access is required before full onboarding completion:
- Screening must still be successfully completed
- Contract must be signed
- Temporary limited access may be granted pending full provisioning
- Security Officer must approve emergency access requests
- Full onboarding must be completed within 2 weeks
Compliance & Monitoring
Responsibilities
- HR Lead: Monitors completion of all administrative onboarding steps, tracks policy acknowledgments, maintains onboarding documentation
- IT: Monitors system provisioning timeliness, tracks access requests, conducts access reviews
- Security Officer: Monitors screening completion, tracks security training completion, oversees DISP compliance
- Hiring Manager: Ensures timely onboarding progression, conducts probationary reviews, provides onboarding experience feedback
Metrics & Reporting
The following metrics should be tracked quarterly:
- Time from offer acceptance to screening completion
- Time from contract signing to first day access provisioning
- Security training completion rates (target: 100% within first week)
- Policy acknowledgment completion rates (target: 100% before day one)
- Probationary period success rate
- Employee onboarding satisfaction scores
Audit & Review
- Annual procedure review: Ensure process remains compliant with evolving legislation and standards
- Quarterly compliance audit: Sample recent onboardings for procedural adherence
- Access provisioning audit: Verify Access aligns with approved requests and role requirements
- Screening compliance check: Confirm all employees have appropriate screening for their level
Non-Compliance
Failure to follow this procedure may result in:
- Delayed employee start dates
- Compliance violations (Fair Work, privacy, security)
- Insider threat risks
- Audit findings
- Regulatory penalties
Non-compliance should be reported to HR Lead and Security Officer for remediation.
References
- Personnel Screening Policy - Defines screening levels and requirements
- Information Security Policy - Overarching security framework
- IAM Policy - Identity and access management requirements
- Code of Conduct - Employee behavioural expectations
- Data Classification Policy - Data handling requirements
- Insider Threat Statement - DISP insider threat awareness
- Onboarding of a Contractor Procedure - Related procedure for contractors
- Evaluation of Privilege Requests Procedure - Privileged access approval process
- Fair Work Act 2009 - Australian employment legislation
- Privacy Act 1988 - Australian privacy legislation
- AS 4811:2022 - Employment Screening standard