For HR and onboarding

Sending a new starter their password, without the welcome email that keeps it forever

Before someone’s first day, they need a password for their laptop or their work account. It usually goes in the welcome email to their personal address, where it stays long after they’ve changed it, or should have. ShareShield sends it as a link that opens once and then deletes the password.

01What usually goes wrong

The welcome email is the weak spot

The welcome email goes to a personal address you don’t control. Think about who can read it from there: anyone else who uses that phone or the family tablet it syncs to, the personal email provider’s backups, the partner it gets forwarded to so they know the start time. On your side, it sits in your sent folder, in the shared HR inbox if you sent it from there, and in your company’s mail archive. The password is still in all of those places next year, and so is anyone who later gets into one of them.

Text messages and chat apps aren’t much better: the message sits on the phone, often backed up to the cloud, and nobody deletes it.

The fix doesn’t need a new process. Keep the welcome email, take the password out of it, and put a link in its place that works once.

02Five steps for first-day passwords

Five steps, the same every time

Print this, or paste it into your onboarding checklist. It works the same for every new starter.

  1. 1

    One password per link.

    If there’s a laptop password and an email password, send two links. If one is opened by the wrong person, only one password needs changing.

  2. 2

    Send it to the person, locked to them.

    Add the new starter’s personal email address under “Email it to” and tick “Only these recipients can open it”. Anyone else who gets hold of the link is asked for a 6-digit code sent to that address, so a forwarded email isn’t enough.

    In the send form: Recipients

  3. 3

    Add a passcode and give it to them another way.

    Read it out on the welcome call, or send it by text message. The link and the passcode should never travel together; ShareShield never puts the passcode in the email. Five wrong passcodes destroy the secret.

    In the send form: Passcode

  4. 4

    Make the expiry fit the start date.

    Send it a day or two before they start and let it expire soon after day one. If they haven’t opened it by then, something is wrong and you want to know.

    In the send form: Time

  5. 5

    Ask to be told when it’s opened.

    You’ll get an email the moment they open it, so you can tick it off the onboarding list without asking.

    In the send form: Notify

03What if…

The awkward cases, answered

The start date moved.
Burn the link from your dashboard, then send a new one closer to the new date. A burned link stops working straight away.
They say the link doesn’t work.
Check the secret in your dashboard. If it shows as opened and they say they didn’t open it, treat the password as known to someone else: ask IT to reset it, then send a new link. If it expired, just send a new one.
I sent it to the wrong address.
Burn it. If it hasn’t been opened, nobody saw the password.
They opened it and then lost the password.
The link won’t open again; that’s the point. Ask IT to reset the password and send a new link.

04When someone leaves

Getting shared logins back from a leaver

People often leave holding passwords nobody else has: the company social accounts, the office Wi-Fi admin page, a supplier portal.

Before their last day, send them a secret request for each one. They fill in a one-time form, and each password arrives in your ShareShield account rather than in a handover document. Then change every one of them.

Read: offboarding shared credentials

05HR and IT, sharing the job

IT sets the rules, HR sends the links

Put HR and IT in the same ShareShield organisation. IT, as the organisation’s owner, sets the rules once: the longest a link can last, a passcode on everything, and which email domains links can go to. HR, as members, send the links, and the send form only offers what the rules allow.

Give IT’s other staff the admin role so they can see every link HR has sent (never the passwords in them) and burn one if needed. If your company signs in with Microsoft, IT can connect ShareShield to it so nobody needs another password.

Which feature does what

ShareShield features for HR and onboarding
You want toUse
Send a first-day passwordA one-view link, recipients only, with a passcode
Know it’s been receivedNotify on open
Cancel a linkBurn
Get a password back from a leaverA secret request
Make everyone follow the same rulesOrganisation policy, set by IT

06Further reading

Guides for onboarding and leavers

Take the password out of your next welcome email

Send one now without an account, or set up an organisation with IT so the whole team works the same way.