Client Onboarding Process

Last updated

Why onboarding sets the churn trajectory

Onboarding is where the client relationship is won or lost – months before any renewal conversation. The economics force the point: onboarding a 100-seat client typically costs roughly $10–15K in tool deployment, documentation, monitoring setup, and security baselining, and payback usually lands around month 9–10. A client who churns early is a straight loss, so everything about onboarding should be designed to make the first 90 days feel decisive: visible improvements the client can feel, clean communication, and no billing surprises. First impressions calcify – a client who experiences a crisp, structured start extends that trust for years; one who experiences 90 days of silence and mystery invoices starts comparing vendors. Onboarding is also when you have maximum permission to change things. "New provider, new standards" is expected on day 30 and resented on day 300.

Two structural decisions precede day 1: a signed agreement – see contracts and the MSA – and the commitment that this client moves to your standard stack during onboarding, priced into the onboarding fee or the first-year rate. Taking over whatever they have, as-is, indefinitely is a classic new-MSP mistake.

Phase 1 – days 1–30: discovery, documentation, quick wins

Kickoff meeting (day 1). Attendees: the client's decision-maker plus their day-to-day contact, and you (or the account lead plus lead tech). Cover: scope and what's explicitly out of scope, how to get support (channels, hours, what "P1" means), the 30/60/90 plan itself with dates, named contacts on both sides, and what will change for staff. Leave with access grants scheduled and the approved-requester list agreed – who may authorize changes and password resets.

Discovery and assessment. Run a full network assessment: topology, asset inventory, access validation (can you actually administer everything you're now responsible for?), licensing, backup viability check – verify backups exist and restore – and a security posture review. Deploy the RMM agents and endpoint protection early; monitoring data enriches everything after it.

Documentation capture. Everything discovery touches gets captured into your standard structure – diagram, credentials into the vault, ISP/vendor/licensing details, backup configuration – per your documentation standards. Completed documentation is an explicit onboarding deliverable with a due date, not something that accretes from tickets over the next two years.

Quick wins the client can feel. Don't wait for "stabilization" – triage the high-risk findings immediately: enforce MFA, get EDR on every endpoint, deploy email security, and patch the scary stuff. These matter twice: they close the riskiest gaps during the window when an incident would be blamed on you anyway, and they give the client visible evidence in week two that hiring you changed something.

Communication to client staff. End users decide whether onboarding "worked" as much as the owner does. Send (or have the client sponsor send) a short announcement: who you are, how to open a ticket, what will change and when. Announce each rollout – MFA enrollment especially – before it happens, with a deadline and a help path. Surprise security prompts generate a flood of suspicious-email reports and resentment; announced ones generate compliance.

Exit criteria for Phase 1:

  • Kickoff held; support channels and approved-requester list communicated to staff
  • Assessment complete; findings triaged with high-risk items remediated or scheduled
  • RMM/agents and endpoint protection deployed to all in-scope devices
  • Backup viability verified with at least one test restore
  • Core documentation set complete in the platform (diagram, credentials, vendors, licensing, backup config)
  • 30-day check-in call held with the sponsor

Phase 2 – days 31–60: standardization

This is the migration phase: move the client onto your standard stack – backup, AV/EDR, email security, and the rest of your one-of-each toolset – and remediate the remaining assessment findings. Every product you leave in place "for now" is a permanent special case that multiplies training, documentation, and error surface; margin leaks trace directly to stack sprawl.

Alongside the technical work: tighten process (ticket habits are forming now – reinforce "every request becomes a ticket"), and run user training where the assessment showed the need, security awareness first.

Exit criteria for Phase 2:

  • Client running on your standard backup, endpoint, and email security stack (or a dated exception documented per item)
  • Assessment findings remediated or explicitly accepted by the client in writing
  • Staff using standard support channels; walk-up/DM requests redirected to tickets
  • Documentation updated to reflect the migrated environment
  • 60-day check-in call held

Phase 3 – days 61–90: optimization and the first QBR

With the environment standardized, tune it: adjust alerting thresholds so the noise floor drops (a misconfigured environment announces itself as ticket volume), establish baseline reporting, and reconcile the asset inventory against what monitoring actually sees.

Then convert onboarding into an ongoing strategic relationship: schedule and hold the first QBR at roughly day 90. Present what was found, what was fixed, the baseline scorecard, and the agreed 12–36 month technology roadmap. This meeting sets the cadence that becomes your best long-term churn defense – the client's first quarter ends with proof of progress and a plan, not an invoice and silence.

Exit criteria for Phase 3:

  • Alerting tuned; monitoring noise at a sustainable level
  • Baseline service report produced (ticket volume, response attainment, endpoint counts)
  • First QBR held with the decision-maker; technology roadmap agreed
  • 90-day check-in complete; onboarding formally closed with the client

Cadence and roles summary

Element Rhythm Owner
Kickoff Day 1 Account lead + client sponsor
Check-in calls Days 30 / 60 / 90 Account lead
Assessment and remediation Days 1–30 Lead tech
Stack migration Days 31–60 Lead tech
First QBR ~Day 90 vCIO / founder

The 30/60/90 check-ins are not ceremony – they surface friction while it is still fixable, before it hardens into the quiet dissatisfaction that shows up eighteen months later as a termination notice.

Bottom line

Run onboarding as a project with three phases and hard exit criteria: discover, document, and deliver security quick wins by day 30; standardize onto your stack by day 60; optimize and hold the first QBR by day 90. Price it properly, communicate relentlessly with the people who live in the environment, and treat finished documentation as a deliverable. The MSPs with sub-5% churn didn't get there at renewal time – they got there in the first 90 days.