Article
7 min read
IT vs. HR: Who's Responsible for What During Onboarding and Offboarding? (Mid-Market / MM)
IT & device management

Author
Dr Kristine Lennie
Last Update
September 17, 2026

Table of Contents
Why the IT–HR boundary is structurally hard to draw at mid-market scale
Onboarding | Who owns device procurement at mid-market companies?
Onboarding | Who owns access provisioning at mid-market companies?
Role change | Who owns access updates at mid-market companies?
Offboarding | Who owns access revocation at mid-market companies?
Offboarding | Who owns device recovery at mid-market companies?
Offboarding | Who owns SaaS and application cleanup at mid-market companies?
IT vs. HR responsibility matrix: who owns what across the lifecycle
How Deel IT simplifies the IT–HR handoff for mid-market teams
Key takeaway
Mid-market growth often marks a transition point for HR and IT. The functions may now sit with separate teams, while the processes and handoffs between them still reflect a smaller, more informal organization.
Mid-market scale makes employee IT more complex to manage. More employees, applications, devices, and role changes create more points where access and equipment can fall out of sync with an employee’s current status.
Deel IT connects HR and IT workflows across the employee lifecycle. Mid-market teams can manage devices and access alongside employee changes, helping create more consistent processes from onboarding through offboarding.
As companies move into the mid-market, HR and IT often become more distinct functions. But the processes connecting them may still reflect how the company operated when the team was smaller, with responsibilities handled informally and handoffs happening through messages, conversations, or whoever knew what needed to happen next.
As the organization grows, that becomes harder to manage. This guide breaks down what HR should own, what IT should own, and where the two need to work together across onboarding, role changes, and offboarding.
Why the IT–HR boundary is structurally hard to draw at mid-market scale
At mid-market scale, a single employee change can set off work across multiple teams and systems. A new hire needs a device and application access. A promotion can require permissions to be added and removed. A departure means coordinating access revocation with device recovery.
HR usually holds the information that starts these processes, while IT handles many of the technical actions that follow. The more employees, applications, and devices involved, the more coordination those handoffs require.
The two functions may also work in different systems and on different timelines. Without a defined trigger between them, an update in one system doesn’t necessarily become an action for the other team. That’s why clear ownership matters: HR and IT need to know both what they own and when responsibility passes from one team to the other.
Onboarding | Who owns device procurement at mid-market companies?
At mid-market scale, device procurement depends on information that typically starts with HR. IT needs to know who is joining, when they start, where they’re located, and what equipment they need early enough to source, configure, and deliver the right device.
HR owns the trigger: Once a hire and start date are confirmed, HR should make sure IT receives the information needed to begin procurement, including the employee’s location, role, and device requirements.
IT owns device provisioning: IT takes it from there, sourcing the device, configuring it, enrolling it in Mobile Device Management (MDM), and coordinating delivery.
Where mid-market teams can get stuck: The company may have a defined hiring process without a defined IT trigger. If IT still learns about new hires through messages, emails, or calendar invites, procurement starts only when someone remembers to make the handoff. Longer lead times or international shipping can make that gap more visible.
How Deel IT helps: Deel IT gives HR and IT a shared way to manage device provisioning as hiring volume grows, helping teams move from informal requests to a more consistent process for procurement, configuration, enrollment, and delivery.
See also: Why new hires start without equipment
Onboarding | Who owns access provisioning at mid-market companies?
As mid-market companies add more roles, teams, and applications, deciding what a new hire should have access to becomes more complex. IT may own the technical setup, but it still needs accurate information about the employee’s role and responsibilities before it can provision the right access.
HR owns the employee information: HR should make sure IT has the employee’s role, team, manager, and start date before they join. The hiring manager may also need to confirm any role-specific applications or access requirements.
IT owns account and access setup: IT creates the necessary accounts, assigns appropriate permissions, and applies security requirements such as Single Sign-On (SSO) and Multi-Factor Authentication (MFA). Where defined Role-Based Access Control (RBAC) policies exist, they can help standardize access for similar roles.
Where mid-market teams can get stuck: Access that was once handled case by case becomes harder to manage as the number of roles and applications grows. Without defined access requirements, IT may still have to piece together what a new hire needs from individual requests, increasing the chance that access is incomplete on day one.
How Deel IT helps: Deel IT helps mid-market teams manage application access alongside employee information, making it easier for IT to act on role and team details without piecing together requirements across separate requests.
Read: Integrating IT lifecycle management with global HR
Role change | Who owns access updates at mid-market companies?
At mid-market companies, employees are more likely to move between roles and teams as the organization grows. Each change can affect what they need access to: new permissions may need to be added, while access tied to their previous role may need to be removed.
HR owns the trigger: HR records the role change and makes sure IT has the information it needs to act, including the employee’s new role or team and when the change takes effect.
IT owns the access update: IT reviews the employee’s existing permissions, removes access they no longer need, and grants access required for the new role. Defined Role-Based Access Control (RBAC) policies can help make those changes more consistent.
Where mid-market teams can get stuck: New access is often more visible than old access. If permissions are added for a new role without reviewing what the employee already has, access can accumulate as they move through the organization. Over time, that privilege creep can leave employees with access their current role no longer requires.
How Deel IT helps: Deel IT gives teams a centralized way to manage application access, helping IT maintain greater visibility into employee permissions as the organization grows.
See also: IAM best practices
Offboarding | Who owns access revocation at mid-market companies?
As mid-market companies add more applications and systems, removing access when someone leaves becomes a larger coordination task. HR knows when the employment relationship is ending, but IT needs that information early enough to identify the employee’s access and remove it at the appropriate time.
HR owns the trigger: HR confirms the departure and tells IT when the employee’s access should end. Planned departures can follow a defined offboarding process, while more sensitive exits may require closer coordination around timing.
IT owns access revocation: IT disables accounts and removes access to the applications, systems, and shared resources the employee used. It should also keep a record of what was revoked and when.
Where mid-market teams can get stuck: An employee’s access may extend well beyond a handful of core applications. As the company’s software environment grows, IT needs visibility into what the employee can access across SSO-managed applications, other business tools, and shared resources. Without that visibility, some access can remain active after the core accounts have been disabled.
How Deel IT helps: Deel IT helps HR and IT coordinate access removal around employee departures, giving teams a clearer way to manage the handoff between the departure information HR holds and the access actions IT needs to complete.
Learn what happens when access is not revoked on time.
Offboarding | Who owns device recovery at mid-market companies?
At mid-market scale, device recovery can involve more employees, more equipment, and more locations. Getting a laptop back from a departing employee is only part of the process: the return needs to be coordinated, the device tracked, and company data handled appropriately before the equipment can be stored, reassigned, or otherwise processed.
HR owns the employee communication: HR makes sure the departing employee knows which company equipment needs to be returned, when it’s due, and what the return process looks like.
IT owns device recovery: IT coordinates the return, tracks the device through the process, and handles the technical steps required once it is recovered, including secure data erasure where appropriate.
Where mid-market teams can get stuck: Device recovery becomes harder to manage case by case as the company grows, particularly across distributed teams. Return logistics, device status, and follow-up all need to stay connected so equipment doesn’t disappear from view once an employee leaves.
How Deel IT helps: Deel IT gives growing IT teams a more centralized way to coordinate device returns, track recovery status, and securely erase company data instead of managing each return through separate follow-ups.
See also: Certified data erasure for compliant device offboarding
Offboarding | Who owns SaaS and application cleanup at mid-market companies?
As mid-market companies add more teams and tools, an employee’s application access can extend beyond the systems IT manages centrally. Some applications may sit behind SSO, while others are managed by individual teams or application owners. That makes offboarding partly a visibility problem: IT can only remove access it knows exists.
HR owns the trigger: HR makes sure the departure reaches IT early enough for application access to be reviewed and removed at the appropriate time.
IT owns application cleanup: IT removes access to known applications and shared resources and identifies software access or accounts that need to be reassigned, removed, or otherwise updated.
Visibility may be shared: Managers and application owners may need to flag team-specific tools that aren’t centrally managed by IT. As the software environment grows, having a clear inventory of applications and who has access to them makes this easier to manage consistently.
Where mid-market teams can get stuck: Offboarding may cover the core applications IT manages while overlooking tools purchased or administered elsewhere in the organization. That can leave former employees with unnecessary access and make it harder to identify software that is no longer being used.
How Deel IT helps: Deel IT gives IT greater visibility into software and employee access, helping growing teams maintain a clearer view of applications and access across the organization.
Discover the 5 most common offboarding failures for remote teams.
IT vs. HR responsibility matrix: who owns what across the lifecycle
The exact split will depend on how your teams are structured, but the principle is consistent: HR typically owns the employee information that triggers a change, while IT owns the device and access actions that follow. Some steps also require input from managers or application owners.
| Responsibility | Stage | Owner | Handoff / trigger |
|---|---|---|---|
| Confirm hire and notify IT | Onboarding | HR | Hire and start date confirmed |
| Procure and configure device | Onboarding | IT | HR shares location, role, start date, and device requirements |
| Enroll device in MDM | Onboarding | IT | Device is prepared for employee |
| Provide role and team information | Onboarding | HR | Hire confirmed |
| Confirm role-specific access needs | Onboarding | HR + hiring manager | Role and responsibilities confirmed |
| Set up accounts and access | Onboarding | IT | Employee and access requirements provided |
| Confirm day-one readiness | Onboarding | Shared | Before the employee starts |
| Record and communicate role change | Role change | HR | New role, team, or responsibilities confirmed |
| Review existing access | Role change | IT | Role change communicated |
| Remove and add permissions | Role change | IT | New access requirements confirmed |
| Assess device requirements | Role change | IT + hiring manager | Role change requires different equipment |
| Confirm departure and access timing | Offboarding | HR | Departure confirmed |
| Revoke system and application access | Offboarding | IT | HR confirms when access should end |
| Flag team-specific applications | Offboarding | Manager / application owner | Offboarding begins |
| Communicate device return process | Offboarding | HR | Offboarding begins |
| Coordinate device recovery | Offboarding | IT | Return process communicated |
| Process returned device | Offboarding | IT | Device received |
| Confirm IT offboarding is complete | Offboarding | Shared | Access and device steps completed |
How Deel IT simplifies the IT–HR handoff for mid-market teams
Deel IT brings device, access, and employee workflows into one platform, giving HR and IT a more connected way to manage onboarding, role changes, and offboarding. As the organization grows, teams can manage the IT work that follows employee changes without stitching together separate processes for devices and access.
For mid-market teams, that can make increasingly complex IT operations easier to manage:
Equip new hires across locations: Procure, configure, and ship devices to employees, with device management built into the process.
Manage devices centrally: Keep track of company devices and apply security policies throughout the device lifecycle.
Coordinate access with employee changes: Manage application access as employees join, move between roles, or leave the organization.
Keep software and access more visible: Maintain a clearer view of applications and employee access as the company’s software environment grows.
Simplify device recovery: Coordinate returns and securely erase company data when devices come back.
Support employees across a distributed organization: Give employees access to IT support without every issue having to pass through an internal HR or IT team.
Book a demo to see how Deel IT can help your HR and IT teams manage employee IT as the organization grows.
Deel IT
Procure, deliver, manage, and secure devices anywhere

FAQs
Who is responsible for revoking system access when an employee leaves — IT or HR?
In most organizations, IT executes the technical steps of access revocation, but HR is responsible for triggering the process by notifying IT that a departure is happening. The problem at mid-market companies is that this trigger is rarely formalized, so access revocation depends on someone remembering to send an email or make a call — which means it sometimes doesn't happen on time.
What typically falls through the cracks during employee onboarding at mid-market companies?
The most common gaps involve steps that sit between HR and IT — like device provisioning that waits on HR to confirm a start date, or software access that IT can't set up until they know what role the person is filling. When neither team has a written handoff process, these in-between steps get delayed or skipped entirely, and the new hire arrives without the tools they need.
How do you create a clear IT and HR split for onboarding and offboarding without a large ops team?
The most practical starting point is documenting, for each step in the process, which team owns it and what event triggers it. Even a simple shared checklist that specifies who initiates device provisioning, who confirms role details, and who verifies access removal can eliminate most of the ambiguity that causes delays and security gaps.
What are the security risks of a poorly defined IT and HR offboarding process?
The biggest risk is that a departing employee retains active access to company systems after their last day because no one received a clear, timely signal to revoke it. This is especially common when role changes or terminations are communicated informally, and it can expose sensitive data to people who no longer have a business reason to access it.

Dr Kristine Lennie holds a PhD in Mathematical Biology and loves learning, research and content creation. She had written academic, creative and industry-related content and enjoys exploring new topics and ideas. She is passionate about helping create a truly global workforce, where employers and employees are not limited by borders to achieve success.











