## TL;DR
Enroll the Mac in Apple Business Manager and Jamf (zero-touch if possible), deploy the standard app set and configs via policy, create the user's accounts (IdP, email, Slack), verify FileVault and security baselines, then hand off with a setup guide. The checklist below is the order of operations.

## The error
```text
(New hire starting; no error. Provisioning request.)
```

## Steps
1. Confirm the hire details: name, start date, team, manager, and any special software. Expected: ticket complete. Missing details cause the most provisioning delays.
2. Assign the device in Apple Business Manager and confirm Jamf enrollment (Automated Device Enrollment). Expected: device assigned. Zero-touch enrollment should trigger on first boot.
3. Boot and step through enrollment; verify the Jamf management profile installs. Expected: managed. Check Jamf inventory shows the device.
4. Confirm policy-deployed apps and configs: browser, VPN, EDR, chat, and Wi-Fi/VPN profiles. Expected: all installed. Spot-check one app launches.
5. Create accounts: IdP (Okta/Entra), email, Slack/Teams, and team tools. Expected: user can sign in everywhere. Verify FileVault is enabled and the recovery key is escrowed.
6. Hand off: send the welcome guide with first-day setup steps and support contact. Expected: user acknowledges. Log the asset tag against the user in inventory.

## When to use
- Every macOS new hire
- Re-provisioning for role changes

## When not to use
- Windows provisioning (separate checklist)
- Contractor devices (scoped-down variant)

## Compatibility
- Apple Business Manager, Jamf Pro, Okta/Entra ID

## Variants
### Remote hire
Ship the device after steps 1-2; enrollment completes over the internet on first boot.
### Executive hire
May need additional software or a different hardware tier; confirm with the manager.

## Why it happens
Provisioning touches purchasing, MDM, identity, and apps. The checklist exists because the failure mode is always "we forgot the X", and X blocks the new hire's first day.

## Edge cases
- Start-date changes: keep the device staged, not assigned, until confirmed.
- Reused devices: wipe via Erase All Content and Settings, then follow the same checklist.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_T2gCRVFv61dADk0HAmddSw
