This guide explains how accounts are created using the appropriate ACG records. Using these sources helps ensure that access is set up accurately and consistently.
- For staff and faculty, accounts are created after the HR system confirms employment.
- For students, accounts are created after the Student Information System confirms enrolment.
- For contractors and guests, the sponsored account request process is used (see AID 05).
- Each account is created with only the access required for the person’s role. Additional access can be added when there is a documented business need.
- The documented naming convention is used so every account remains unique and easy to identify.
Example Account naming conventions
Staff and faculty: first letter of first name + last name @acg.edu (for example, mpapadopoulou@acg.edu)
Students: first letter of first name + first letter of last name + ID (for example, mp192122)
Admin accounts: first letter of first name + first letter of last name + admin. Use a separate admin account from the user’s daily account (for example, psadmin).
Guests: first letter of first name + last name @acg.edu, with an expiry date recorded for the account.
Staff and faculty: first letter of first name + last name @acg.edu (for example, mpapadopoulou@acg.edu)
Students: first letter of first name + first letter of last name + ID (for example, mp192122)
Admin accounts: first letter of first name + first letter of last name + admin. Use a separate admin account from the user’s daily account (for example, psadmin).
Guests: first letter of first name + last name @acg.edu, with an expiry date recorded for the account.
Example Onboarding workflow
- Day -5: HR records the new hire and start date in the HR system, then informs IT.
- Day -3: IT receives the provisioning request.
- Day -2: IT creates the account, assigns the required access groups, prepares an initial password, and readies equipment.
- Day 0: The manager provides the credentials. The new hire changes the password and enrols in MFA at first sign-in.
- Day 1: Assign security awareness training (see SOP 03).
- Day 30: The manager reviews access and requests any necessary adjustments.