When we started working with a Boston-area company last year, their new hire onboarding process looked like this.
HR would send an email to IT with the new starter’s details. IT would manually create accounts in Active Directory, then work through a checklist of SaaS applications: email, project management, Slack, your CRM, your file storage, your HR platform, your finance tools, and so on. Each application had to be configured individually. Each had its own provisioning process. Some could be done in a few minutes. Others took longer if the right person wasn’t available, or the vendor’s admin portal was being difficult that day.
By the time a new hire arrived on their first Monday, setup was usually incomplete. Access requests came in throughout the first week. Some applications took days. A few fell through entirely until the employee noticed they couldn’t get in and submitted a ticket.
Multiply that across a company of 500 people growing fast enough to bring on dozens of new hires per quarter, and you have a significant operational drain that nobody had formally calculated.
We ran the numbers. Their IT team was spending more than six hours of combined labor on every single onboarding. The problem wasn’t the IT team. They were doing exactly what the environment required. The problem was that no one had ever built the environment to not require it.
What Manual Onboarding Actually Costs
The six-hour figure sounds like an IT problem. It isn’t. It’s a business problem.
Research puts the combined cost of manual onboarding at $4,000 to $7,000 per employee when you include HR time, IT labor, manager involvement, and the productivity delay of a new hire who can’t fully function on day one. For a company hiring 50 people a year, that’s somewhere between $200,000 and $350,000 annually in direct and indirect cost, most of it invisible on any single budget line.
Beyond cost, there’s a security exposure that most organizations underestimate. Fewer than one in ten companies have automated application assignments for employee onboarding. The majority are still running manual processes, which means inconsistent provisioning, access granted beyond what a role requires, and offboarding that depends entirely on someone remembering to do it.
That last point matters more than most people realize. At this company, we found over 50 user accounts that were still active for people who had left. Some had been gone for weeks. A few for longer. Every one of those was an unlocked door into their systems, sitting open because no one had a reliable process for closing it.
What We Found When We Got Involved
The technical environment had the right ingredients. An Okta deployment that had been purchased and partially configured. Active Directory on-premise. Microsoft 365. A reasonably modern SaaS stack just not integrated.
The gap wasn’t tools. It was architecture and the leadership to build it properly.
Here’s what the environment looked like before we started:
150 laptops with no unified device management. New machines had to be configured manually by IT staff before being handed to a new hire, a process that took hours per device. 65 SaaS applications being provisioned individually for each new hire. No multifactor authentication on any of them. Former employees retaining access because offboarding was a manual checklist that regularly got skipped during busy periods. HR and IT operating as separate workflows with no automated connection between a hire in the HR system and account creation in IT.
Account creation was a 20-minute manual process per application, and that’s before accounting for the coordination overhead, the access request tickets, and the back-and-forth between HR and IT. Across 65 applications, you’re looking at a significant chunk of IT capacity being consumed by something that should happen automatically.
The Fix: 90 Days, One Coherent Architecture
The work split into four areas. Each one built on the last.
Identity as the foundation. We upgraded Okta from its basic configuration to a properly deployed Identity Engine. Passwordless authentication across the entire organization, geofencing, threat detection, and integration with SentinelOne so that a compromised device automatically triggers account suspension rather than waiting for someone to notice. 600 users moved from password-based to passwordless authentication during the engagement.
Connecting HR to IT. The single biggest operational change was a daily sync between their HR system and their identity platform. When a new hire is added to HR, the trigger fires automatically. An account is created, role-based access groups are applied, and application provisioning begins without anyone in IT touching it. When someone leaves or changes roles, the same logic runs in reverse. Job title changes now propagate to Microsoft 365 within 24 hours. Contractor accounts deactivate automatically when they go inactive.
Zero-touch device provisioning. New starters log in for the first time, and the laptop builds itself. Intune and Autopilot for Windows machines, Kandji for Macs. The IT team ships a machine; the new hire does the rest. No imaging, no manual configuration, no waiting for IT to be available.
Application rationalization. Consolidating 65 applications behind a single identity layer forced a conversation about what they actually needed. Some applications had been running for years with overlapping functions. The cleanup process reduced licensing costs while the consolidation eliminated the per-application provisioning problem entirely.
The full case study, independently published by ZeroTek, is here if you want the technical detail: zerotek.com/okta-implementation-case-study-boston-tech-advisors
The Outcomes, Specifically
At the end of 90 days:
600 users on passwordless authentication. New hire onboarding down from 6 hours to under 20 minutes, with most of that time being the new hire completing their own setup rather than IT doing it for them. 50 inactive accounts deprovisioned. Application access now provisioned automatically based on role. The IT team, which had been spending a significant portion of its capacity on onboarding and access management, shifted that time to proactive infrastructure work they’d been deferring for months.
The internal team runs all of it without support. That was a deliberate design decision. An IT transformation that creates dependency on the people who built it isn’t a transformation. It’s a service contract.
Why Most Organizations Don’t Get Here
The tools exist. Okta has been capable of this for years. A modern automated approach to identity lifecycle management is well-documented, and the integration capabilities between HR systems and identity platforms are mature. So why do so many mid-market companies still run manual onboarding in 2026?
Three reasons, consistently.
Nobody owns the problem at the right level. IT manages the tools. HR manages the people process. Neither team has the authority or the mandate to redesign the system that sits between them. A decision that touches both departments and requires budget, coordination, and a clear outcome owner tends to stay on the backlog indefinitely.
The tools get purchased before the architecture gets designed. Okta was already installed at this company. It just hadn’t been configured to do what it was capable of. Buying the right tool and deploying the right tool are different problems, and the gap between them usually persists until someone with the full picture decides to close it.
Nobody calculates the cost of the status quo. Forty-three percent of new hires have to wait more than a week just for their workstation and tools to be ready. That’s a week of a fully-salaried employee who can’t do their job. For most companies it’s just accepted as normal. Once you put a number on it, the case for fixing it becomes straightforward.
What This Means for Your Business
If your onboarding process involves IT staff manually provisioning accounts, if your offboarding depends on someone remembering a checklist, or if former employees regularly retain access beyond their last day, you have the same problem this company had.
The cost of it isn’t concentrated in any single incident. It distributes across hundreds of small inefficiencies, security exposures that never become incidents, and IT capacity that gets consumed by work that should be automatic.
Fixing it properly takes 60 to 90 days. It requires someone who understands both the identity architecture and the organizational dynamics well enough to connect HR and IT into a single automated workflow. And it leaves your internal team fully capable of running it independently when it’s done.
If you want to understand what this would look like for your specific environment, the first step is a conversation.
Book a free 30-minute consultation
Benjamin Katz is the Founder and CIO of Boston Tech Advisors. He has served as CIO at EF Educational Tours, Rue La La, and dataxu (acquired by Roku), and holds patents in internet commerce. Boston Tech Advisors delivers Fractional CIO services, Managed IT, and Security Assessments for growing Boston-area businesses.