Blog/Operations
OperationsSeptember 10, 2026·10 min read

Employee onboarding SOP: the first 30 days

Most onboarding advice is about welcome and culture. The part that actually costs money is access: what you grant on day one, and what you claw back on the last day.

AY
Anand Yadav · Founder, ReccordSOP
·Last reviewed September 10, 2026

The short answer

An employee onboarding SOP is the written procedure for turning a signed offer into someone who can do the job without supervision. It names who owns each step, what gets set up before the start date, what happens in the first four weeks, and how you know the person is ready.

For a small ecommerce team, most of that document is about access. Which systems the new person gets, at what permission level, granted by whom, and on what day. The welcome lunch is not the part that goes wrong.

If you are onboarding a support hire specifically

This article covers onboarding any role. The support case has its own ramp: ticket queues, macros, brand voice and escalation tiers. That is covered separately and linked below.

What belongs in the document

Six blocks. Anything else is padding a small team will not maintain.

BlockWhat it holds
TriggerA signed offer with a confirmed start date. Not a verbal yes
OwnerOne named person who runs onboarding, usually not the hiring manager
Pre-start checklistAccounts, hardware, paperwork, and who raises each request
Access matrixWhich systems this role gets, at what permission level
Week-by-week planWhat they watch, do supervised, then do alone
Ready testOne piece of real work, checked. Not a quiz

The owner field is the one people skip because it feels obvious. It is not obvious the week two people start at once and the hiring manager is on holiday. Name a role, not a person, so it survives that person leaving.

Before day one: the access list

This is where a DTC onboarding SOP earns its keep, and where the generic advice is least useful. Your new hire does not need a laptop and a company handbook so much as they need correctly scoped access to five or six systems that hold customer data and can move money.

Write the access matrix by role before anyone starts, so it is a lookup rather than a judgement call at eight in the morning:

SystemWhat to decide in advance
Shopify adminStaff permissions are granular. Decide whether the role can issue refunds, edit products, or view payouts. Most new hires need none of the three
HelpdeskAgent versus admin. Whether they can delete tickets or edit macros other people rely on
Email and SMS platformWhether they can send to the whole list, or only build drafts for review. This one has no undo
3PL or warehouse portalRead-only until they have run the process supervised. A wrong click here moves physical stock
Analytics and finance toolsUsually view-only. Rarely needed on day one at all
Password managerWhich vaults, and the rule that nothing is ever shared outside it
The default that costs you

Granting admin because it is faster than working out the right permission level. It is faster on day one and it is the reason nobody can answer, six months later, who changed the refund policy or sent the campaign to the full list.

Raise the requests three business days before the start date, not the morning of. Accounts that need a seat purchased, an approval, or a vendor to action something will not be ready otherwise, and a first day spent waiting for logins sets the tone for everything after it.

Try it on one of your own procedures.

Record a process once, AI writes the structured SOP. 3 free SOPs, no credit card.

Start for free →

The first 30 days

Keep the structure the same regardless of role, and change what fills it. The progression matters more than the content, because it is what moves someone from watching to working unsupervised.

  1. Week one, watch. They shadow whoever runs the process now, with no expectation of output. Record those sessions if you can, because they become the training material for the next hire.
  2. Week two, do supervised. They run real tasks while someone watches and stays quiet unless something is about to go wrong. Prompting produces someone who can be prompted.
  3. Week three, do alone with a check. They work unsupervised, and the output gets inspected afterwards rather than the process being watched during.
  4. Week four, widen. Add the second and third processes, and the exceptions that were deliberately kept off the table in week one.
  5. Day 30, review. Not a performance review. A documentation review: which steps did they get stuck on, and what does that say about the SOP rather than about them.

That last one is the step that pays for the whole exercise. A new hire is the only person who will ever read your procedures with fresh eyes. Every question they had to ask is a defect in a document, and the window for collecting those closes after about a month, once they have learned the workarounds and stopped noticing.

Training SOP: how to document the way you train

The watch, do, teach progression in full, and why a quiz is the wrong way to check somebody is ready.

Customer support onboarding SOP for DTC teams

The support-specific version: ticket queues, macros, brand voice, and the escalation tiers a new agent needs on day one.

The offboarding mirror

Almost nobody writes this half, and it is the half with real exposure. Every line in your access matrix is a line that has to be reversed, and unlike onboarding, nothing forces the issue. Onboarding fails loudly, when somebody cannot log in. Offboarding fails silently, for months.

Write it as the same list, read backwards:

  • Revoke access effective end of the last working day, scheduled in advance rather than remembered on the day.
  • Shopify admin and helpdesk first. Those two hold customer data and can move money.
  • Rotate any shared credential that person knew, even one in the password manager. Access removal does not un-know a password.
  • Reassign ownership of anything they owned: SOPs, recurring tasks, vendor relationships, scheduled reports that will now silently fail.
  • Check third-party seats you pay for. A contractor whose Shopify account is closed may still hold a login to your 3PL portal or your review platform, because those were granted by someone else.

The contractor case is the one that catches DTC brands. Seasonal support hires and agency freelancers accumulate access across five or six vendor systems over a busy quarter, granted ad hoc by whoever needed them productive that week. If the grant was not written down, the revoke will not happen.

How it goes stale

An onboarding SOP rots faster than most documents because it points at more systems than most documents. Every tool in the access matrix is a vendor who can redesign a permissions screen without telling you.

Three triggers for a review, none of them a calendar date:

  • You add or drop a tool. The access matrix is wrong the day the contract is signed, not the day someone notices.
  • A permission model changes. Platforms restructure staff roles periodically, and a permission level named in your SOP can stop existing.
  • A new hire gets stuck. Treat every question during onboarding as a defect report, because it is the cheapest feedback you will ever get on your documentation.

Whose job is it to update outdated documentation?

The ownership problem underneath this. An onboarding SOP with no named owner is the one that quietly grants admin to everybody.

Start with the access matrix. It takes an afternoon, it is the part with real financial exposure, and once it exists the rest of the onboarding SOP is mostly a schedule.

Frequently asked questions

What is an employee onboarding SOP?

A written procedure for turning a signed offer into someone who can do the job unsupervised. It names the owner, what gets set up before the start date, which systems the role gets and at what permission level, the week-by-week ramp, and the test that says they are ready. For a small ecommerce team most of it is access control, since that is the part with real cost attached when it goes wrong.

What should be set up before a new hire's first day?

Accounts and permissions for every system the role touches, raised at least three business days ahead so anything needing a seat purchase or vendor action is ready. Hardware, paperwork and payroll setup alongside it. The specific decision worth making in advance is permission level per system, because deciding it on the morning produces admin access granted for speed.

How long should employee onboarding take?

About four weeks to unsupervised work on the first process, structured as watch, do supervised, do alone, then widen. That is a ramp rather than a deadline, and it varies by role. What should not vary is the checkpoint: one piece of real work inspected at the end of week three, before anyone declares the person ready.

What is the difference between onboarding and training?

Onboarding is the whole arc from signed offer to unsupervised work, including access, paperwork, introductions and context. Training is one part of it: teaching a specific process. A team can have excellent training and terrible onboarding, which usually shows up as a competent new hire who spent their first week unable to log into anything.

Do you need an offboarding SOP too?

Yes, and it is the same document read backwards. Every access grant needs a matching revoke, scheduled for the last working day rather than remembered afterwards. Rotate shared credentials the person knew, reassign whatever they owned, and check third-party vendor seats separately, since those are often granted ad hoc and sit outside your main systems.

Ready to record your first SOP?

3 free SOPs to start. No credit card required. See if drift detection keeps your docs honest.

Start for free
AY
Anand YadavFounder, ReccordSOP

I built ReccordSOP after watching too many DTC ops teams lose months to undocumented workflows. These SOPs are battle-tested with Shopify operators running $1M to $50M brands.

Last reviewed September 10, 2026

Related reading