Banker Workstation Setup and Provisioning SOP
Banker Workstation Setup and Provisioning SOP
Standard procedure for imaging, configuring, and provisioning a new banker workstation with core banking access, least-privilege permissions, and required verification steps.
Steps
-
Verify the provisioning request
The IT support technician verifies that the provisioning request includes: - Banker identity and role - Manager or authorized approver approval - Device assignment or asset number - Required core banking and business application access - Any time-bound or exception-based access If any required field is missing, the technician escalates the request to the requester or manager before continuing.
-
Prepare and image the workstation
The IT support technician applies the approved operating system image to the workstation. The technician verifies that the build includes the standard security baseline, endpoint protection, and required enterprise settings. If the image fails or the build deviates from the approved standard, the technician records the deviation and escalates to the endpoint management owner.
-
Enroll the device in endpoint management
The IT support technician enrolls the workstation in the endpoint management platform. The technician confirms that the device is linked to the correct asset tag, owner, and location. If the device cannot be enrolled or the asset record does not match, the technician stops the setup and escalates the discrepancy.
-
Configure standard user access
The IT support technician creates or activates the banker's standard user profile according to the approved request. The technician assigns only least-privilege permissions required for the role and excludes administrative rights by default. The technician documents any exception access separately and routes it for approval if it is not already authorized.
-
Provision core banking and business applications
The IT support technician provisions access to the approved core banking system and any required business applications. The technician confirms that each entitlement matches the approved role matrix and that no unapproved modules are enabled. If the requested access exceeds the role matrix, the technician records the deviation and escalates for manager or system owner review.
-
Validate least-privilege permissions
The IT support technician verifies the final permission set against the approved access request and role matrix. The technician confirms that: - Local administrator rights are not assigned unless approved - Shared credentials are not used - Unused applications are not installed or are disabled - Any exception access has documented approval and expiration, if applicable If the verification fails, the technician removes the excess access and rechecks before release.
-
Complete functional login testing
The IT support technician performs a test login using the assigned user account or a controlled validation method approved by policy. The technician verifies that the workstation can: - Sign in successfully - Reach required network resources - Launch the core banking application - Access approved business tools If any test fails, the technician records the issue as a non-conformance and escalates to the appropriate support queue.
-
Document completion and release the workstation
The IT support technician records the completion details in the service ticket or provisioning log. The technician includes the asset identifier, date, completed configuration actions, exceptions, and verification results. The technician then releases the workstation to the banker or manager only after all required checks are complete.
Ask AI
Template Studio