Documentation.
The runbooks, not the resume
Descriptions of work are easy to write and hard to check. Documentation is the opposite, so here is some of mine. These are generalised versions of procedures I have written and run, free of anything confidential, and you are welcome to take them.
Runbooks
Employee onboarding runbook
How a new hire gets a working laptop and the right access on day one, without anyone filing a ticket. Covers the HR trigger, role-derived access, device baseline, and the failure modes worth designing for.
Offboarding and rehire runbook
Removing access the moment somebody leaves, handling the data they leave behind, and the path back when they return. The rehire section exists because this is the case lifecycle automation usually gets wrong.
User access review
A repeatable campaign for proving who has access to what, and removing what is no longer justified. Written so that each round costs less than the one before it.
Phishing response checklist
What to do in the first minutes after somebody reports, or admits, that they clicked. Contain first, investigate second, and close it with a change rather than a shrug.
Device lifecycle and buy-out policy
Seven policy statements, then the procedure that carries them out: how hardware is issued, tracked, refreshed and retired, including the conditions under which staff can buy the device they have been using.
Guides
A complete guide to VoiceMeeter
Fifteen pages on routing audio on Windows with VoiceMeeter, written for people who had been told it was too complicated to bother with.
About these documents
They are deliberately tool-agnostic: they name an HR system of record and an identity provider rather than the specific products behind them, because the shape of the process is the part worth keeping and the products change.
They contain no employer data, no configuration, no hostnames and nothing confidential. Nothing here was lifted from an internal system. If you want to know how a particular one worked in practice, ask me and I will talk you through it.
Each one carries the document control block a real governance system expects: owner, approver, version, review cycle, and the SOC 2, ISO 27001 and NIST controls it addresses. Service levels are written as committed numbers, not as words like promptly.
Take them and adapt them if they are useful to you.