The provider's service levels are conditional on the following. Where a dependency fails, the affected task is recorded as client-caused and excluded from SLA measurement — but the provider must still flag it in writing on the day, not in the monthly report.
The provider accepts provisioning, access-change and revocation instructions from named authorisers only, through the agreed ticket channel. A request made by WhatsApp, by phone or by a line manager directly is not an authorisation. It must be politely refused and redirected to HR, and the refusal logged. This single rule is the strongest protection both parties have against social-engineering attacks and against disputes over who granted what.
| Authority | May instruct | Held by |
|---|---|---|
| Primary HR authoriser | All provisioning, access change and revocation | HR Director |
| Delegated HR authoriser | Standard joiner and leaver processing | Recruitment Lead |
| Admin authoriser | Device release, asset movement, hardware faults | Admin Manager |
| Exception approver | Any access outside the Role Access Matrix | HR Director |
| Emergency authoriser | Immediate revocation, out of hours, by phone with written confirmation within 1 hour | HR Director or Managing Director |
| Final escalation | Service disputes and unresolved P1 incidents | Managing Director |
The named holders of each authority are recorded on the signature page and re-confirmed at every quarterly service review. The provider must not act on an instruction from a person not on the current list.
| Role | Responsibility | Name / contact |
|---|---|---|
| IT Account Manager | Single point of accountability for this SOP and all service levels | |
| Provisioning engineer | Day-to-day joiner, leaver and access work | |
| Escalation contact | P1 incidents and out-of-hours revocation | |
| Service desk | Ticket intake channel and reference numbering |
To be completed and countersigned before this procedure takes effect.
| Priority | Definition and typical examples | Response | Resolution | Updates | Hours |
|---|---|---|---|---|---|
| P1 | Critical. Company-wide loss of a core service, or a confirmed or suspected security incident. Bitrix24 or email unavailable to all users; account compromise; suspected data exfiltration; leaver revocation instruction. | 15 min | 4 hours | Hourly | 24/7 |
| P2 | High. A department cannot work, or a joiner cannot start on time. A team locked out of Bitrix24; mail flow broken for a group; Day −1 provisioning incomplete at 17:00; device build failed the night before a start date. | 1 working hr | 8 working hrs | Twice daily | Service hours |
| P3 | Medium. A single user impaired with a workaround available. Login failure, password reset, permission correction, application fault, printer or peripheral failure. | 4 working hrs | 1 working day | Daily | Service hours |
| P4 | Service request. Planned work with a known date. New joiner provisioning, device build, access change, role change, scheduled offboarding, reporting and reviews. | 1 working day | Per SOP date, else 3 working days | On completion | Service hours |
| Obligation | Trigger | Deadline | Evidence returned to client |
|---|---|---|---|
| Acknowledge New Joiner Notification | Notification received | 1 working day | Reference number and confirmed access profile |
| Microsoft 365 account and licence | Notification received | Day −1 by 12:00 | UPN, licence type, MFA state |
| Bitrix24 user and permission set | Notification received | Day −1 by 12:00 | User ID, department, role, supervisor |
| Drive, groups and role systems | Notification received | Day −1 by 15:00 | Access list per matrix item |
| Device build and security baseline | Device released by Admin | Day −1 by 17:00 | Signed build sheet with asset tag and serial |
| Readiness confirmation to HR | All of the above complete | Day −1 by 17:00 | Written readiness statement (Annex 2) |
| Day-one login and MFA walkthrough | Joiner arrives | First 2 hours | Successful first sign-in logged |
| Revocation — identity and CRM | Authorised leaver instruction | 2 clock hours | Timestamps per system |
| Revocation — mailbox, drive, groups | Authorised leaver instruction | 4 clock hours | Delegation and transfer confirmation |
| Access Revocation Certificate | Revocation complete | 1 working day | Signed certificate (Annex 2) |
| Device wipe and return to stock | Device received from Admin | 5 working days | Wipe confirmation and register update |
| Monthly service report | Month end | By the 5th | Report pack per Section 10 |
| Quarterly access reconciliation | Quarter end | Within 10 working days | Exception list signed by both parties |
Why this matters: the provisioning record is what makes revocation provable later. An account created without a written record is an account nobody can be certain was removed.
| Role | Record visibility | Export | Admin rights |
|---|---|---|---|
| Sales agent | Own leads, deals and contacts only | Disabled | None |
| Sales manager | Own plus subordinate records in the department | On approval, logged | None |
| CRM officer | Department or all, per appointment | On approval, logged | CRM settings only |
| Marketing | Read access for campaign purposes | Disabled | None |
| Admin | As appointed | On approval, logged | Limited, named |
| Accounts | Deal financial fields only | On approval, logged | None |
| HR | No CRM record access | – | HR module only |
| Conveyancer | Deals assigned to conveyancing | Disabled | None |
Elevated rights — administrator, full export, cross-department visibility — are granted to named individuals only, with written HR Director approval and a quarterly re-justification.
Passport, Emirates ID, visa and bank details are held on the HR employee record with restricted visibility — HR and the authorised approver only. The provider must confirm at build time that:
Where the provider finds personal data outside the HR record, it is reported to the HR Director as a finding — it is not quietly deleted, because a copy may be the only record.
| # | Step | Confirmed |
|---|---|---|
| 1 | Record asset tag, make, model and serial number; match to the Asset Register entry | |
| 2 | Clean operating system install or verified factory reset — never a hand-me-down profile | |
| 3 | All operating system and firmware updates applied | |
| 4 | Full-disk encryption enabled and the recovery key escrowed to the tenant | |
| 5 | Endpoint protection installed, updated and reporting to the console | |
| 6 | Local firewall enabled | |
| 7 | The employee account is a standard user, not a local administrator | |
| 8 | Separate, named local administrator account with a managed password | |
| 9 | Screen lock enforced at 5 minutes with a password on wake | |
| 10 | Microsoft 365 apps installed and signed in; mail, calendar and contacts syncing | |
| 11 | Bitrix24 desktop app installed and signed in; chat and drive verified | |
| 12 | Browser installed with company bookmarks and the portal shortcuts for the role | |
| 13 | Role applications installed per the Role Access Matrix | |
| 14 | Printer and network resources mapped | |
| 15 | VPN or remote access configured where the role requires it | |
| 16 | Manufacturer bloatware and any trial software removed | |
| 17 | Backup or sync of the documents folder configured to the company drive | |
| 18 | Every provisioned account signed into once to prove it works before handover | |
| 19 | Device labelled and packaged; build sheet signed by the engineer | |
| 20 | Written readiness confirmation issued to HR by 17:00 |
Signing into every account once on Day −1 costs ten minutes and catches the three failures that account for most bad first days: a licence that was never actually assigned, a permission set applied to the wrong department, and a password that expired between creation and the start date. A build is not complete because the accounts exist. It is complete because they were used.
When an employee moves role or department, the matrix is re-applied in full. The single most common access failure in any company is the internal mover who accumulates every permission they have ever held. The provider must therefore:
A role change ticket that only contains additions is returned as incomplete.
Every grant outside the matrix is an exception. Exceptions are not refused on principle — the business sometimes needs them — but they are never invisible.
| Field | Requirement |
|---|---|
| Employee and role | Named, with the current access profile |
| Access granted | The specific system, scope and level |
| Business justification | Written by the requesting Department Head |
| Approver | HR Director, in writing |
| Grant date | Recorded by the provider |
| Review date | Mandatory; maximum 90 days |
| Outcome at review | Extended with fresh approval, or removed |
Data is lost when access is removed before ownership is transferred. Removing a licence deletes the mailbox after the grace period. Deleting a user can orphan their drive content and detach their CRM history. The provider therefore always performs transfer before removal, in the order below . A user account is never deleted as part of routine offboarding: disable, preserve, then reclaim.
| Order | System | Action | Deadline | Evidence |
|---|---|---|---|---|
| 1 | Microsoft 365 identity | Disable sign-in, reset the password to a value nobody holds, revoke all refresh tokens and terminate active sessions | T + 2 hrs | Timestamp and admin action log |
| 2 | Multi-factor authentication | Revoke registered methods so a retained phone cannot re-authenticate | T + 2 hrs | Timestamp |
| 3 | Bitrix24 | Confirm zero owned records remain, then deactivate the user and remove all permission sets. Do not delete the user | T + 2 hrs | User ID and deactivation timestamp |
| 4 | Mobile and remote access | Remove company data from the mobile profile; disable VPN and any remote access | T + 2 hrs | Confirmation of removal |
| 5 | Drive and documents | Transfer ownership of personal drive and document libraries to the named manager | T + 4 hrs | Transfer confirmation with target owner |
| 6 | Mailbox | Convert to a shared mailbox, apply the agreed delegation, and set any approved forwarding with an end date | T + 4 hrs | Delegation confirmation |
| 7 | Groups and lists | Remove from all distribution lists, security groups, workgroups and chat channels | T + 4 hrs | Itemised removal list |
| 8 | Role systems and portals | Disable or reassign the property system, portal accounts, design and finance tools per the matrix | T + 4 hrs | Per-system confirmation |
| 9 | Telephony | Release the extension, reroute the direct line, and preserve call recordings per policy | T + 4 hrs | Extension released |
| 10 | Licences | Reclaim all licences only after steps 5 and 6 are confirmed complete | T + 8 hrs | Licence count returned to Accounts |
| 11 | Certificate | Issue the signed Access Revocation Certificate listing every system and the time revoked | 1 working day | Certificate to HR (Annex 2) |
| 12 | Device | Recover from Admin, back up any local business data, wipe, re-image and return to stock | 5 working days | Wipe confirmation and register update |
| 13 | Residual review | Re-run the access check across every matrix system and confirm nothing remains | 30 days | Nil-return statement to HR |
| 14 | Retention | Review the shared mailbox, end forwarding and archive per the retention policy | 30 days | Archive confirmation |
Instructed by the HR Director or Managing Director, by phone if necessary, confirmed in writing within one hour. Applies to gross misconduct, a hostile departure, or any suspicion that company or client data is at risk. The order inverts: access is removed before the individual is informed.
The provider does not contact the individual, does not respond to them, and does not restore any access on their request — only on written instruction from the HR Director.
A suspected account compromise, phishing success, malware infection or data exposure is a P1 and follows this sequence regardless of the hour.
The provider must not attempt to resolve a suspected breach quietly before telling the client. Where client or customer personal data may have been exposed, the client may carry notification obligations with statutory deadlines, and those deadlines run from the moment of awareness — not from the moment the provider finishes investigating. Late notice removes the client's ability to comply.
| Control | Standard | Verification |
|---|---|---|
| Multi-factor authentication | Mandatory on every account, including shared, role and administrator accounts | Monthly report, 100% target |
| Password policy | Minimum length enforced, no forced periodic expiry, breached-password blocking enabled | Tenant policy screenshot |
| Administrator accounts | Separate named admin accounts, MFA enforced, never used for daily work, reviewed quarterly | Quarterly review |
| Legacy authentication | Blocked at tenant level | Tenant policy |
| External auto-forwarding | Blocked at tenant level; exceptions individually approved | Monthly report |
| Conditional access | Sign-in risk and location policies applied per client instruction | Policy list |
| Device encryption | Full-disk encryption on every company device, keys escrowed | Build sheet and device report |
| Endpoint protection | Installed, updating and reporting on every device | Monthly console report |
| Patching | Operating system and application updates applied within the agreed window | Monthly compliance percentage |
| Local administrator rights | Removed from standard users; exceptions approved and time-limited | Quarterly review |
| Backup and sync | Company data held in Microsoft 365 or Bitrix24, not solely on the device | Configuration check at build |
| Screen lock | 5 minutes with password on wake, enforced by policy | Policy state |
| Audit logging | Enabled and retained for the agreed period across both platforms | Retention setting |
| Licence position | Assigned, unassigned and reclaimable licences tracked | Monthly report |
| Asset accuracy | Every device attributable to a named holder or to stock | Monthly reconciliation with Admin |
All of the above are the client's records. On termination of the engagement they are handed over in a usable format, together with administrative control of both platforms, within ten working days.
The provider will encounter employee personal data, client contact data and commercial information. Access is on a least-privilege, task-necessary basis only. Data is not copied to provider systems beyond what is needed to deliver the service, is not retained after the task, and is never used for any other purpose. Any access to a mailbox or record outside a specific authorised ticket must be logged and reported.
| Section | Content |
|---|---|
| Service level performance | Tickets by priority, response and resolution attainment, every breach with its cause and the recovery action |
| Joiners | Each joiner processed, each fixed obligation met or missed, and the provisioning evidence reference |
| Leavers | Each leaver processed, time from instruction to full revocation, certificate reference |
| Access position | Total active accounts by platform, accounts created, changed and removed, licence position |
| Exceptions | Open exceptions with review dates, and any overdue for review |
| Security | MFA coverage, patch compliance, endpoint coverage, incidents and near-misses |
| Assets | Devices in stock, deployed and pending wipe; reconciliation differences with Admin |
| Risks and recommendations | Anything the provider believes the client should act on, with a stated impact |
| Client-caused delays | Late notifications, late device releases and missing approvals, with dates |
| Indicator | Target |
|---|---|
| Fixed onboarding obligations met on time | ≥ 98% |
| Joiners with complete provisioning evidence | 100% |
| Day-one failures attributable to the provider | 0 |
| Revocations completed within 2 hours of instruction | 100% |
| Revocation certificates issued within 1 working day | 100% |
| P1 response within 15 minutes | 100% |
| P2 and P3 SLA attainment | ≥ 95% |
| MFA coverage across all accounts | 100% |
| Quarterly reconciliation findings closed within 5 working days | 100% |
| Monthly report delivered by the 5th | 100% |
Attended by the IT Account Manager and the HR Director, with the Managing Director invited. Standing agenda:
The purpose is not to catch the provider out. It is to make the service provable — so that when the client is asked who had access to what and when, the answer exists in writing rather than in someone's memory. Every requirement here produces a record, and every record protects both parties.
| Item | Convention | Example |
|---|---|---|
| User principal name | firstname.lastname@domain, lowercase, no accents or apostrophes | ahmed.hassan@… |
| Duplicate name | Append a middle initial; a number only as a last resort | ahmed.k.hassan@… |
| Display name | Firstname Lastname, as per passport | Ahmed Hassan |
| Shared mailbox | Function based, never person based | accounts@… |
| Distribution list | dl- prefix and function | dl-sales-offplan |
| Security group | sec- prefix, system, role | sec-crm-agent |
| Drive folder group | grp- prefix and department | grp-marketing |
| Device asset tag | LPH-DEPT-NNN | LPH-SLS-042 |
| Device hostname | Matches the asset tag | LPH-SLS-042 |
| Bitrix24 login | Identical to the company email address | ahmed.hassan@… |
| Bitrix24 position | The approved standard job title only | Property Consultant |
| Bitrix24 department | The company structure node, with a supervisor set | Sales — Off-plan |
| Ticket reference | Provider format, quoted in all correspondence |
Access profiles are driven by job title. The provider must reject any notification carrying a free-text or improvised title and request the approved standard title from HR. This is not pedantry — a title that does not appear in the Role Access Matrix has no defined access profile, which means the engineer would be guessing at what the person should be able to see.
A build with blank directory attributes is incomplete. These fields drive the address book, the email signature, approval routing in Bitrix24 and the quarterly reconciliation.
The New Joiner Notification states an access profile taken from the Role Access Matrix. The provider provisions that column exactly.
| Profile | Matrix column |
|---|---|
| A | Sales agent |
| B | Sales manager |
| C | CRM officer |
| D | Marketing |
| E | Admin |
| F | Accounts |
| G | HR |
| H | Conveyancer |
| X | Non-standard — requires an HR Director exception before any account is created |
Where a notification is ambiguous, the provider provisions the lesser access and asks. Under-provisioning creates a ticket. Over-provisioning creates an exposure that may not be found for months.
To: HR / Recruitment From: IT Service Provider Ref: ______________
Joiner: ____________________ Standard title: ____________________
Department: ______________ Access profile: ______ Start date: ____________
| Item | Provisioned | Identifier / note | Tested |
|---|---|---|---|
| Microsoft 365 account and licence | |||
| Multi-factor authentication enforced | |||
| Mailbox, distribution lists and groups | |||
| Shared drive and document permissions | |||
| Bitrix24 user, department and supervisor | |||
| Bitrix24 role permission set | |||
| Bitrix24 workgroups and chat | |||
| Telephony extension (if applicable) | |||
| Role systems and portals per matrix | |||
| Device build and security baseline | |||
| Exceptions applied (with approval ref.) |
I confirm every item above was provisioned per the Role Access Matrix and signed into successfully before handover.
To: HR Director From: IT Service Provider Ref: ______________
Leaver: ____________________ Last working day: ____________
Instruction received: ______________ (date/time) Authorised by: ______________
Exit type: Standard □ Immediate □
| System | Action taken | Time revoked |
|---|---|---|
| Microsoft 365 sign-in and sessions | ||
| Multi-factor authentication methods | ||
| Bitrix24 user | ||
| Bitrix24 records reassigned to | ||
| Mailbox — converted / delegated to | ||
| Drive and documents — transferred to | ||
| Groups, lists and chat channels | ||
| Role systems and portals | ||
| Telephony extension | ||
| Mobile and remote access | ||
| Licences reclaimed | ||
| Device received and wiped |
I certify that all access listed above has been revoked, that company data was preserved and transferred before removal, and that no residual access remains known to the provider.
Both parties confirm this procedure, its service levels and its authoriser list.