Onboarding of an Employee Procedure

This sets out the steps to onboard an employee at Vaxa, including the documentation required, screening processes, and the setup of access to systems and facilities.

Purpose

This procedure establishes a standardized and compliant process for onboarding employees at Vaxa, whether they are casual, part-time, or full-time. It ensures consistent implementation of:

  • Australian employment law obligations (Fair Work Act 2009)
  • ISO27001 information security requirements
  • DISP insider threat management controls
  • Personnel screening and background check requirements
  • System access and identity management controls

This procedure is critical to ensuring we properly vet, onboard, and integrate new employees while managing insider risk and maintaining compliance with our legal and regulatory obligations.

Scope

This procedure applies to all employees engaged by Vaxa, including:

  • Full-time employees: Permanent staff working standard full-time hours
  • Part-time employees: Permanent staff working regular but reduced hours
  • Casual employees: Staff engaged on an as-needed basis with casual loading

This procedure does not cover:

Roles & Responsibilities

RoleResponsibility
EmployeeProvide required documentation to complete the onboarding process, complete mandatory training, and adopt required controls and policies
HR LeadManage the employment contract process, Xero setup, superannuation enrolment, Fair Work compliance, and ensure all administrative requirements are met
Hiring ManagerDefine role requirements, determine screening level, conduct interviews, provide onboarding context to IT and HR, and manage probationary period reviews
ITSet up the employee in required systems, provision access based on role and security level, provide devices as required, and deliver IT orientation
LegalReview employment contracts for compliance, ensure Fair Work Act adherence, manage any employment-related legal risks
Security OfficerOversee background screening process, conduct security awareness training, ensure DISP and ISO27001 compliance, monitor insider threat indicators

Procedure

Position Approval & Role Definition

Before commencing recruitment, ensure:

  1. Budget approval has been obtained for the position
  2. Position description is current and accurate, including:
    • Role title and reporting line
    • Key responsibilities and deliverables
    • Required qualifications and experience
    • Employment type (casual/part-time/full-time)
    • Salary range or wage rate
    • Working arrangements (office/remote/hybrid)
  3. Screening level is determined based on the role’s access requirements:
    • Level 2 (Standard): Most employees with typical system access
    • Level 3 (Sensitive Access): Employees with access to sensitive information, financial systems, or who could cause significant reputational damage
    • Level 4 (Executive): Directors and senior leaders with strategic decision-making authority

See the Personnel Screening Policy for detailed screening level criteria.

Candidate Selection

Initial Recruitment

  1. Advertise the position through appropriate channels
  2. Review applications against selection criteria
  3. Conduct initial screening interviews
  4. Perform preliminary reference checks
  5. Shortlist candidates for detailed assessment

Pre-Offer Considerations

Before extending an offer, consider whether:

  • An NDA is required prior to sharing sensitive information during the interview process
  • The candidate requires any workplace adjustments or accommodations
  • There are any conflicts of interest that need to be managed (see Conflict of Interest Policy)

Background Screening

Under our Personnel Screening Policy, all employees must undergo comprehensive background screening via our approved provider, Certn. The screening level determines the depth of checks required.

All employment offers must be conditional on successful completion of background screening.

Level 2 (Standard) - Mandatory Checks

All employees at Level 2 and above must undergo:

  • 100 points of ID verification: Passport, driver’s license, birth certificate, or equivalent
  • Right to work in Australia: Citizenship, permanent residency, or valid work visa
  • 5-year address history: Verified and cross-referenced against sensitive countries
  • National police check: Must be less than 12 months old at time of engagement
  • Character references: Two references verified and documented
  • Referee checks: Professional references from previous employers
  • Social media assessment: Review of publicly available social media profiles
  • Qualification and experience verification: Verification of claimed credentials directly with issuing institutions

Level 3 (Sensitive Access) - Additional Checks

In addition to Level 2 checks, Level 3 employees require:

  • Employment history verification: Detailed verification including Defence-related work (if applicable)
  • Credit check: Basic public record credit check (mandatory for those with financial system access)
  • Professional membership verification: Direct verification with professional bodies where membership is required for the role

Level 4 (Executive) - Additional Checks

In addition to Level 2 and 3 checks, Level 4 employees require:

  • ASIC checks: Banned & Disqualified Persons, Enforceable Undertakings Register, and Australian Directorships
  • Comprehensive credit check: Detailed financial history assessment
  • Enhanced employment history: Comprehensive verification of all previous roles and responsibilities

Screening Process

  1. Hiring Manager confirms screening level requirement with Security Officer
  2. HR Lead initiates screening via Certn once candidate accepts conditional offer
  3. Candidate provides required documentation and consents to screening
  4. Certn conducts checks and provides outcome report
  5. Security Officer reviews screening outcomes and approves or raises concerns
  6. Only upon successful screening can final employment offer be confirmed

Note: Screening must be completed before the employee’s start date. No system access or onboarding can commence without successful screening completion.

Employment Offer & Contract

Conditional Offer Letter

Once a suitable candidate is identified and preliminary checks are positive, issue a conditional offer letter including:

  • Position title and classification
  • Employment type (casual/part-time/full-time)
  • Proposed salary/wage (including casual loading if applicable)
  • Superannuation contribution details (currently 11.5%, increasing to 12% from 1 July 2025)
  • Leave entitlements (varies by employment type - see below)
  • Probationary period (6 months standard)
  • Proposed start date
  • Reporting manager
  • Working arrangements and location
  • Condition: Offer subject to satisfactory background screening and reference checks

Employment Contract

Once screening is successfully completed, Legal will prepare the employment contract. The following information is required:

Employee Details:

  • Full legal name
  • Date of birth
  • Residential address
  • Contact phone number
  • Email address (personal)
  • Emergency contact details
  • Tax File Number (TFN)
  • Superannuation fund details

Employment Specifics:

  • Position title for Vaxa systems
  • Employment type (casual/part-time/full-time)
  • Salary/wage and payment frequency
  • Hours of work (for part-time) or minimum engagement (for casual)
  • Superannuation fund and contribution rate
  • Leave entitlements based on employment type
  • Probationary period terms (6 months)
  • Notice period requirements
  • Place of work and working arrangements
  • Any specific conditions or requirements
  • Applicable Modern Award or Enterprise Agreement
  • Optionally: headshot photo for use in Vaxa systems

Internal Details:

  • Direct manager/supervisor
  • Any client SharePoint sites the employee will require access to
  • Project budgets in Productive the employee needs access to
  • System access requirements (e.g., BitWarden, production environments, finance systems)
  • Device requirements (laptop, phone, etc.)

Provide this information to Legal, who will prepare the contract. The contract shall be sent to the employee for signing, and once returned, the onboarding process can proceed.

Signed contracts are automatically filed in the Contract Register via the Vaxa Link integration.

Employment Type Considerations

Full-Time Employees:

  • Standard 38 hours per week (or as specified in contract)
  • Full annual leave entitlement (4 weeks per year, accruing progressively)
  • Full personal/carer’s leave entitlement (10 days per year, accruing progressively)
  • Entitled to public holidays without loss of pay
  • Notice period as per Fair Work Act or contract (typically 1-4 weeks)
  • Eligible for all employee benefits and programs

Part-Time Employees:

  • Regular guaranteed hours (e.g., 20 hours per week)
  • Pro-rata annual leave based on hours worked
  • Pro-rata personal/carer’s leave based on hours worked
  • Entitled to public holidays (pro-rata)
  • Notice period as per Fair Work Act or contract
  • Eligible for employee benefits (may be pro-rata)

Casual Employees:

  • Casual loading (typically 25%) in lieu of leave entitlements
  • No annual leave or personal/carer’s leave
  • Not entitled to paid public holidays (receive loading instead)
  • Minimum notice periods may not apply (check Modern Award)
  • May convert to permanent after 12 months (Casual Conversion provisions under Fair Work Act)
  • System access and training may be limited to essential requirements only

Pre-Start Administrative Setup

Once the contract is signed, HR Lead commences administrative setup before the employee’s start date.

Xero Payroll Setup

  1. Create new employee record in Xero
  2. Enter personal details (name, DOB, address, contact details)
  3. Record TFN and tax-free threshold election
  4. Set up superannuation details (fund name, member number, contribution rate)
  5. Configure pay template:
    • For full-time/part-time: ordinary hours, salary rate
    • For casual: casual hourly rate with loading
  6. Set up leave entitlements (if applicable)
  7. Record bank account details for salary payments
  8. Assign to appropriate pay calendar
  9. Configure any automatic deductions or allowances

Required Documentation

Ensure the employee provides the following before commencing:

  • Tax File Number Declaration (ATO form)
  • Superannuation Standard Choice Form (if choosing their own fund)
  • Bank account details for salary payments (BSB, account number, account name)
  • Proof of identity (certified copy of passport, driver’s license, or birth certificate)
  • Work eligibility documents:
    • Australian citizens: Birth certificate or passport
    • Permanent residents: Visa evidence
    • Temporary visa holders: Valid work visa with appropriate conditions
  • Academic qualifications (original certificates or certified copies)
  • Professional memberships (if relevant to role)
  • Working with Children Check (if role requires contact with minors)
  • Driver’s license (if role requires driving)

Insurance & Workers Compensation

  • Ensure employee is covered under Vaxa’s workers compensation insurance
  • Add employee to professional indemnity policy if required
  • Update public liability insurance if employee numbers change significantly

IT & Systems Setup

IT setup cannot commence until the employment contract is signed, per our Information Security Policy.

Once the contract is signed, HR Lead notifies IT to commence system provisioning. IT will reference the contract and onboarding information provided by the Hiring Manager.

Entra / M365 Accounts

Step 1: Create User in M365 Admin Portal

  1. Visit admin.microsoft.com and log in with an admin account
  2. Navigate to UsersActive Users
  3. Click Templates and select Employee (Business Premium) template
  4. Complete the form with:
    • First name and last name (as per contract)
    • Display name (First Last)
    • Username: first.last@vaxagroup.com
    • Position title (as per contract)
    • Department (as applicable)
    • Office location (if relevant)
    • Mobile phone (as provided)
  5. Click Add user to create the account
    • This automatically assigns an M365 Business Premium license
    • Verify sufficient licenses are available before creation
  6. Locate the newly created user and assign their manager (usually the Hiring Manager)
  7. Navigate to Groups and click Manage groups
  8. Assign to OS_x_Employees group at minimum
  9. Assign to any additional role-based groups:
    • OS_x_Finance (for finance team members)
    • OS_x_Technical (for engineers and technical staff)
    • OS_x_Consultants (for client-facing consultants)
    • Client site access groups (as specified by Hiring Manager)

Step 2: Configure Authentication in Entra

  1. Visit entra.microsoft.com and log in with an admin account
  2. Navigate to UsersAll Users and select the new employee
  3. Click Authentication methods in the left menu
  4. Click Add authentication method
  5. Select Temporary Access Pass and configure:
    • Lifetime: As short as practical but long enough for employee to set up (recommend 24 hours)
    • Start time: Immediate or delayed to start date
    • One-time use: Set to No (allows multiple setup attempts if needed)
  6. Click Add and copy the TAP code
  7. Save the TAP into a Bitwarden Send with:
    • Expiration matching TAP lifetime
    • Deletion on first access for security
  8. Copy the Bitwarden Send link for the welcome email

Step 3: Send Welcome Email

Draft an email to the employee’s personal email address (not their Vaxa email, as they can’t access it yet) and CC the Hiring Manager and IT team:


Subject: Welcome to Vaxa - Setting up your account

Hi [Employee Name],

Welcome to the Vaxa team! We’re excited to have you joining us on [Start Date].

Your Vaxa account has been created and requires a few setup steps from you. Please follow these instructions to set up your authentication.

Important: This is a time-sensitive process - your Temporary Access Pass expires in 24 hours, so please complete the setup as soon as possible.

Your Temporary Access Pass: [Bitwarden Send Link]

Once you’ve completed the authentication setup, you’ll be able to access:

  • Email and Microsoft 365: Your Vaxa email is first.last@vaxagroup.com
  • Productive: Our project management and time tracking tool - access via Cloudflare Access
  • Teams: For communication and collaboration
  • SharePoint: For document management and client sites

[If applicable: We’ve also provisioned your access to:

  • [List any additional systems, client sites, or specialized tools]]

Before your first day, please:

  1. Complete the authentication setup (instructions linked above)
  2. Set up your email signature (template will be provided on your first day)
  3. [Complete any pre-start training modules assigned in the LMS - we’ll send separate instructions]

If you have any questions or encounter any issues, please don’t hesitate to reach out to me directly.

We look forward to seeing you on [Start Date]!

Warm regards, [IT Team Member Name] IT Team, Vaxa


System Access Provisioning

By being assigned to the OS_x_Employees group, the employee will automatically receive access to core systems. Additional access is provisioned based on role and screening level:

All Employees:

  • M365 Services: Email, Teams, SharePoint, OneDrive, Office apps (online and desktop)
  • Productive: Project management and time tracking (accessed via Cloudflare SSO)
  • Cloudflare Access Portal: vaxagroup.cloudflareaccess.com
  • BitWarden: Password manager (all employees receive access)
  • LMS: Learning Management System for training and compliance

Role-Based Access (as specified by Hiring Manager):

  • Client SharePoint sites: Specific client workspaces as required
  • Productive project budgets: View/edit access to project budgets for time/expense tracking
  • Scheduling software (Cal.com): For client-facing staff requiring appointment scheduling
  • Production IT environments: Engineers only (Google Cloud, AWS, Azure, etc.) - requires Level 3 screening minimum
  • Finance systems (Xero, banking): Finance team only - requires Level 3 screening minimum

Access Approval Process:

Device Provisioning

For eligible employees, IT will provision corporate devices:

Full-Time Employees:

  • MacBook (model based on role requirements) - standard issue
  • Mobile phone if required for role
  • Security key/hardware token for Level 3/4 employees
  • Peripherals as required (monitor, keyboard, mouse, headset)

Part-Time Employees:

  • Device provisioning based on role requirements and hours worked
  • Generally provided for 20+ hours per week roles

Casual Employees:

  • Device provision rare - usually BYOD arrangements
  • If provided, must be returned immediately upon cessation

Device Setup:

  • Configured per macOS Software Management policy
  • Enrolled in MDM (Mobile Device Management)
  • Standard software suite installed
  • Added to asset register
  • Asset tag applied
  • Employee signs device acceptance form

Security & Compliance Onboarding

Security onboarding is mandatory for all employees and must be completed before they can access systems containing OFFICIAL or higher classified data.

Mandatory Security Training

All employees must complete the following training, ideally before their start date or on day one:

  1. Information Security Awareness (LMS module)

    • Understanding Vaxa’s security framework
    • ISO27001 and DISP requirements overview
    • Your role in maintaining security
  2. Data Classification Training (LMS module)

    • Understanding data classification levels
    • Applying protective markings
    • Handling requirements by classification
    • See Data Classification Policy
  3. Insider Threat Awareness (In-person or recorded briefing)

    • Understanding insider risk indicators
    • DISP compliance requirements
    • Reporting obligations and processes
    • See Insider Threat Statement
  4. Privacy & Confidentiality (LMS module)

    • Personal information handling
    • Privacy Act obligations
    • Client confidentiality requirements
    • See Privacy Policy
  5. Cyber Incident Response (LMS module)

Policy Acknowledgments

All employees must read and acknowledge the following policies before commencing work. HR will track acknowledgments and maintain records:

Additional policy acknowledgments for specific roles:

  • Privileged Access Policy - for Level 3/4 employees with elevated access
  • Finance-related policies - for those with financial system access

Security Briefings

The Security Officer (or delegate) will conduct:

Initial Security Briefing (Day 1 or Week 1):

  • Identity and access management (IAM) requirements
  • Multi-factor authentication (MFA) setup and usage
  • Password manager (BitWarden) setup and best practices
  • Physical security (office access, visitor management, clean desk)
  • Reporting security incidents and concerns
  • Social engineering and phishing awareness
  • Secure communication practices

DISP Insider Threat Briefing (if handling Defence-related work):

  • Enhanced insider threat awareness
  • Reporting obligations specific to Defence contracts
  • Security clearance requirements (if applicable)
  • Contact procedures for Defence Security incidents

First Day Induction

The Hiring Manager coordinates the first day experience to ensure the employee feels welcomed and prepared.

Welcome & Orientation

Morning:

  • Welcome by Hiring Manager and team
  • Office tour (if office-based) including:
    • Workstation/desk allocation
    • Kitchen and amenities
    • Meeting rooms and bookable spaces
    • Emergency exits and assembly points
    • First aid facilities
  • Introduction to team members and key stakeholders
  • Overview of probationary period expectations

IT Equipment Handover:

  • If devices were shipped to employee: Unboxing and setup assistance
  • If devices issued in-office: Handover and asset acknowledgment signing
  • Login credentials verification
  • MFA device setup confirmation
  • Email signature configuration
  • Calendar and scheduling setup

Operational Setup

Productive Training:

  • How to log time to projects
  • Expense claiming process
  • Project budget visibility
  • Time approval workflows
  • Mobile app usage (if applicable)

Communication Tools:

  • Teams channels and etiquette
  • Email best practices
  • SharePoint site navigation
  • File storage structure (OneDrive vs SharePoint vs local)
  • Video conferencing setup and protocols

Work Processes:

  • Project management workflows
  • Client communication protocols
  • Documentation standards
  • Code of conduct practical applications
  • Escalation procedures

Administrative Completion

Health & Safety:

  • WHS induction
  • Emergency procedures and evacuation plan
  • First aid officer identification
  • Incident reporting procedures
  • Ergonomic workspace setup
  • Mental health and wellbeing resources

Physical Access:

  • Building access cards/keys issued
  • Parking arrangements (if applicable)
  • After-hours access procedures (if required)
  • Visitor sign-in process

Additional First Day Tasks:

  • Employee photo for directory (if not provided earlier)
  • Completion of any outstanding forms
  • Super fund enrolment confirmation
  • Banking details verification
  • Emergency contact confirmation

Probationary Period Management

All employees are subject to a 6-month probationary period during which performance and suitability are assessed.

30-Day Review

Conducted by: Hiring Manager
Purpose: Early check-in and course correction

Review areas:

  • Settling in and cultural fit
  • System access is complete and functional
  • Initial training completion status
  • Early performance indicators
  • Any support needs or concerns
  • Access rights are appropriate for role

Documentation: Brief notes in personnel file

90-Day Review

Conducted by: Hiring Manager with HR input
Purpose: Mid-probation formal assessment

Review areas:

  • Performance against initial goals
  • Competency development
  • Training and development needs
  • System access audit - confirm appropriate privileges
  • Cultural alignment and team integration
  • Any performance concerns requiring action

Documentation: Formal review meeting notes, performance feedback record

6-Month Probationary Review

Conducted by: Hiring Manager with HR Lead
Purpose: Confirm permanent employment or extend/terminate probation

Review areas:

  • Overall performance against position requirements
  • Achievement of probationary goals
  • Competency levels
  • Cultural fit and values alignment
  • Attendance and conduct
  • Recommendation: Confirm, extend, or terminate

Outcomes:

  • Confirm employment: Probation successfully completed, becomes permanent employee
  • Extend probation: Further time needed (typically 3 months), with clear improvement plan
  • Terminate employment: Not suitable for role, notice given per Fair Work requirements

Documentation: Formal probation completion letter or extension/termination notice

During Probation

Reduced notice periods apply:

  • First month: 1 day notice (either party)
  • After first month: 1 week notice (either party)

Access Reviews:

  • IT conducts access audit at 30 days to confirm appropriate provisioning
  • Any changes to access based on evolving role understanding

Ongoing Compliance & Monitoring

Access Reviews

Per our IAM Policy, access must be regularly reviewed:

  • Privileged access (Level 3/4, production systems, finance): Quarterly review by System Owners
  • Standard access (general employees): Bi-annual review
  • Role changes: Immediate access review and re-provisioning

Continuous Monitoring

The Security Officer monitors for insider threat indicators including:

  • Unusual system access patterns
  • Data exfiltration attempts
  • Policy violations
  • Performance issues or behavioural changes
  • Financial distress indicators
  • Unexplained affluence

See Insider Threat Statement for reporting procedures.

Ongoing Training & Awareness

  • Annual security awareness refresher: All employees (LMS)
  • Data classification updates: As policy evolves
  • Role-specific training: As technologies and processes change
  • Privacy Act updates: When legislation changes
  • Ad-hoc security bulletins: As threats emerge

Re-Screening

Per the Personnel Screening Policy:

  • Level 3/4 employees: Periodic re-screening at intervals determined by risk assessment
  • All employees: May be re-screened if:
    • Significant role change requiring elevated access
    • Security concern arises
    • Extended international travel to sensitive countries
    • Required by client contracts

Performance Management

  • Regular 1-on-1 meetings with manager
  • Annual performance reviews
  • Development plans and training opportunities
  • Promotion and progression pathways
  • Documented performance concerns and improvement plans

Exceptions

Some employees may require modified onboarding procedures due to:

  • Remote/interstate location requiring different logistics
  • Specialized roles with unique system requirements
  • Expedited onboarding for urgent business needs (screening still mandatory)
  • Client-specific requirements or clearances

Exception Process:

  1. Hiring Manager documents the exception requirement and justification
  2. HR Lead reviews for compliance implications
  3. Security Officer assesses for security risks
  4. Documented approval required before proceeding
  5. Exception and mitigating controls recorded in personnel file

Emergency Access: In rare cases where urgent access is required before full onboarding completion:

  • Screening must still be successfully completed
  • Contract must be signed
  • Temporary limited access may be granted pending full provisioning
  • Security Officer must approve emergency access requests
  • Full onboarding must be completed within 2 weeks

Compliance & Monitoring

Responsibilities

  • HR Lead: Monitors completion of all administrative onboarding steps, tracks policy acknowledgments, maintains onboarding documentation
  • IT: Monitors system provisioning timeliness, tracks access requests, conducts access reviews
  • Security Officer: Monitors screening completion, tracks security training completion, oversees DISP compliance
  • Hiring Manager: Ensures timely onboarding progression, conducts probationary reviews, provides onboarding experience feedback

Metrics & Reporting

The following metrics should be tracked quarterly:

  • Time from offer acceptance to screening completion
  • Time from contract signing to first day access provisioning
  • Security training completion rates (target: 100% within first week)
  • Policy acknowledgment completion rates (target: 100% before day one)
  • Probationary period success rate
  • Employee onboarding satisfaction scores

Audit & Review

  • Annual procedure review: Ensure process remains compliant with evolving legislation and standards
  • Quarterly compliance audit: Sample recent onboardings for procedural adherence
  • Access provisioning audit: Verify Access aligns with approved requests and role requirements
  • Screening compliance check: Confirm all employees have appropriate screening for their level

Non-Compliance

Failure to follow this procedure may result in:

  • Delayed employee start dates
  • Compliance violations (Fair Work, privacy, security)
  • Insider threat risks
  • Audit findings
  • Regulatory penalties

Non-compliance should be reported to HR Lead and Security Officer for remediation.

References