Skip to main content

Onboard New Hires with Swif

Swif helps IT teams deliver a consistent, secure, and audit-ready onboarding experience across macOS, Windows, Linux, and mobile devices (iOS & Android).

This guide outlines the recommended end-to-end workflow for onboarding new employees using Swif.

Overview

A complete onboarding process typically includes:

  • Adding & syncing users via HRIS / Identity Providers

  • Enrolling employee devices via automated email workflows or zero-touch MDM

  • Applying security & compliance policies

  • Deploying required software

  • Running structured onboarding checklists

  • Verifying compliance before handoff

Swif allows you to standardize and automate each of these steps.

Step 1: Add & Provision the New User

Before device setup begins, ensure the new hire exists in your directory and in Swif.

You can:

  • Auto-Sync via Identity & HRIS Integrations: Automatically import and sync employees from Google Workspace, Microsoft Entra ID (Azure AD), Okta, Rippling, Deel, or Finch.

  • Automatic Onboarding Triggers: When a new user is created in your IdP/HRIS, Swif automatically provisions the user and triggers assigned onboarding templates.

  • Notification Rules: Configure Employee Event Notifications (e.g., New Hire Added) so IT managers, MSP admins, or team leads receive real-time alerts when a new employee joins.

  • Manually Add the User: If needed, create users directly within the Swif console.

Best practice: Assign users to the correct department or role-based group so policies and Smart Device Groups apply automatically upon enrollment.

Step 2: Enroll the Device

Swif supports multiple enrollment methods tailored to your hardware fleet and IT workflow.

Option A: Automatic Device Enrollment Emails (Recommended)

Swif can automatically deliver tailored device enrollment instructions directly to new hires through Onboarding Templates.

When configuring an Onboarding Checklist Template, admins can enable "Send enrollment email automatically" and select one or more delivery methods:

  1. Application Installer: Desktop installer for macOS and Windows.

  2. Apple Enrollment SSO: Streamlined web/SSO-based enrollment for Apple devices.

  3. QR Code (iOS & Android): Automatically generates and emails secure PDF instructions containing platform-specific QR codes:

    • Android: Fast enrollment into corporate work profiles.

    • iOS / iPadOS: Mobile Safari enrollment profile setup.

  4. NixOS Package: Automated enrollment scripts and configuration for NixOS enterprise fleets.

  5. Universal Blue (Bluefin) Package: Cloud-native client package for immutable Linux workstations.

Key Benefits:

  • Zero Admin Overhead: Emails trigger automatically when the employee account is created or when the onboarding template is assigned.

  • Multi-Method Support: Select multiple enrollment options simultaneously within a single template.

  • Backend-Managed Security: QR codes and PDF download tokens are generated dynamically by Swif's backend.

Option B: Automated Zero-Touch Enrollment (Company-Owned Devices)

For corporate-managed hardware:

Option C: Manual & Fleet Package Enrollment

If automated zero-touch or email flows are not used:

  • Manually download and run the Swif agent installer from the dashboard.

  • Use Linux package managers (deb, rpm, nix) for enterprise Linux servers and developer workstations.

Optional: Read-Only Enrollment (BYOD)

For contractor laptops, temporary workers, or personal BYOD devices:

Here is the proposed new section to add to the help article Onboard New Hires with Swif, structured to seamlessly integrate under Step 2: Enroll the Device (or as a standalone sub-section on device assignment) based on https://swifteam.atlassian.net/browse/ST-8637 and https://swifteam.atlassian.net/browse/ST-8638.

Optional: Automatic Device Assignment via Desktop App Sign-In

To streamline hardware handoffs and eliminate manual user-to-device mapping by IT admins, Swif can automatically prompt users to sign in on their desktop and link unassigned devices to their employee profiles upon authentication.

Why Use Auto-Assignment?

When laptops are deployed in bulk, pre-provisioned in an inventory pool, or enrolled via generic zero-touch installers, they often start in an unassigned state. With Prompt Sign-In and Auto-Assign Device enabled, Swif bridges this gap automatically as soon as the new hire begins using their machine.


Step 1: Enable Auto-Assignment in Admin Console

  1. Log in to the Swif Console as an Admin.

  2. Navigate to SettingsGeneral.

  3. Locate the Prompt Sign-In and Auto-Assign Device section.

  4. Toggle the switch to ON.

Step 2: How It Works for the New Hire

  1. Sign-In Prompt: When the user turns on an unassigned device running the Swif Desktop App, the app detects that the device does not yet have an assigned owner and prompts the user to log in.

  2. Authentication: The new hire signs in with their corporate identity credentials (Google Workspace, Microsoft Entra ID / Office 365, Okta, or Swif credentials).

  3. Automatic Ownership Sync:

    • The Desktop App performs periodic background check-ins with Swif APIs using the device identifier (mdmDeviceId) and the authenticated session token.

    • Swif resolves the employee profile in your directory and sets the logged-in user as the official device owner in your inventory.

  4. Policy & Software Binding: Once assigned, all role-based Smart Device Groups, department policies, and required software profiles bind to the device automatically.

Step 3: Apply Security & Compliance Policies

Once enrolled, Swif automatically evaluates and applies assigned security profiles:

  • Disk Encryption: FileVault (macOS), BitLocker (Windows), and LUKS (Linux).

  • Identity & Authentication: Password complexity, lock-screen timers, and Platform SSO.

  • OS & Patch Management: Enforced OS update schedules and compliance deadlines.

  • Security Baselines: Firewall settings, gatekeeper/antivirus, and app restriction policies.

Smart Device Groups: Policies automatically bind to devices based on OS, hardware specifications, extension attributes, or assigned user departments.

Step 4: Deploy Required Software

Deploy essential workplace software silently and automatically:

  • Productivity & Browsers: Chrome, Arc, Google Drive.

  • Collaboration: Slack, Microsoft Teams, Zoom.

  • Security & EDR Agents: Antivirus, DLP extensions, VPN profiles.

  • Custom Software: Deploy custom packages and run pre/post-install scripts.

Step 5: Use Structured Onboarding Workflows

Standardize role-specific onboarding across your organization using Swif's checklist engine.

  • Team Onboarding Checklists: Create department-specific checklists (Engineering, Sales, Finance, HR) with clear task owners, due dates, and completion tracking.

  • Integrated Device Enrollment Config: Embed auto-send enrollment rules directly inside your role-based templates.

  • SaaS & Account Provisioning Checklists: Track manual SaaS account creation, CRM permissions, and developer repository access (GitHub/GitLab) for complete audit compliance.

Step 6: Final Verification Before Handoff

Before marking the onboarding complete, verify that:

  • [x] User account is active and assigned to the correct team/department

  • [x] Device appears in the Swif inventory and reports healthy telemetry

  • [x] Disk encryption is active and recovery keys are securely escrowed

  • [x] All required security policies and configuration profiles are applied

  • [x] Required software and browser extensions are installed

  • [x] Compliance posture is green (NIST, CIS, SOC 2, ISO 27001 ready)

  • [x] Onboarding checklist tasks are marked as completed

Did this answer your question?