Customer Support Agent Onboarding Checklist Template

Support agents answer in writing, sometimes in public, and every reply stays on the record. A new agent who learned the product from slides and the helpdesk by trial and error sends confident answers that turn out to be wrong.

This free customer support agent onboarding checklist is for support leads at SaaS and software companies hiring agents to work email, chat, in-app messages and social channels. It starts with the product, used hands-on in a sandbox the way a customer would use it, before the agent touches the helpdesk. Then come macros and tone of voice, triage against your SLAs, bug reports engineering can act on, and the privacy and security requests that must never be handled alone. Agents work a reviewed queue before an independent one, and write their first knowledge base article on the way. For voice agents working scripts, telephony and live-call nesting, use the Call Centre Agent Onboarding Checklist. HR paperwork and payroll sit in the Employee Onboarding Checklist.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Learn the Product Before the Helpdesk

The usual first week in SaaS support is a tour of the helpdesk, a folder of macros and a pile of tickets to read. The agent learns how to answer before they know what the product does, so they lean on macros and send replies that are polite, fast and slightly off. Customers notice, and the senior agents spend their time correcting drafts instead of handling the hard tickets.

A better order is to make the new agent a customer first. They sign up on a sandbox account, complete the jobs most tickets are about, and reproduce the problems customers report. Once they have broken the product themselves, the knowledge base reads differently and the macros make sense. Because written support is mostly asynchronous, there is also room for a reviewed queue: the agent drafts real replies, a reviewer checks them before they are sent, and nothing wrong reaches a customer while they learn. Each channel then asks for something slightly different.

Channel What the new agent has to learn
EmailA complete answer in one reply, with the steps numbered and the right article linked
Live chatShort messages, how many chats to hold at once, and when to move a chat to a ticket
In-app messagesUsing what the customer was doing on screen when they wrote in, without asking them to repeat it
Social mediaReplying in public without account details, then moving the conversation to a private channel

What the Customer Support Agent Onboarding Checklist Covers

Seven phases run from a sandbox account to the independent queue. Identity verification appears only for agents who will change customer accounts, and the social media task only for agents who reply in public.

Phase 1

Phase 1: Accounts & Access Before Day One

  • Record the start date, team lead, buddy and reviewer — the reviewer checks every reply in the reviewed queue
  • Answer the account changes and social media questions — will the agent change customer accounts, and will they reply on public channels?
  • Set up helpdesk, chat and bug tracker access — an agent role, not an admin one, and the least access to the customer admin console that the job needs
  • Create a sandbox account on the product — signed up the way a customer would, never on a real customer’s account
  • Send the first-week plan and reading list — tone of voice guide, the most-used articles and recent release notes
Phase 2

Phase 2: Learn the Product as a Customer

No tickets yet. The agent uses the product before reading about it.

  • Complete the core customer jobs in the sandbox — the handful of tasks most tickets are about, from sign-up to billing
  • Reproduce the most common ticket problems — using last quarter’s top ticket tags as the list
  • Read the most-used knowledge base articles and note gaps — anything out of date or missing goes on a list for Phase 6
  • Join a product walkthrough with a product manager — what is planned, what is known to be broken, and why
  • Pass the plans, pricing and limits quiz
Phase 3

Phase 3: Helpdesk, Macros & Tone of Voice

  • Learn the helpdesk views, statuses and tags — what pending, on-hold and solved mean here, and which tags feed the reports
  • Use macros as a starting point and personalise every reply — answer the question asked, not the one the macro expects
  • Draft replies to solved tickets for buddy review — compared with the reply that was actually sent
  • Apply the tone of voice guide in each channel — plain words, no blame, and an apology only when something went wrong
  • Train public social replies and moving them to private — shown for agents who reply on social media
Phase 4

Phase 4: Triage, SLAs & Escalation

  • Explain the priority levels and SLA targets — first response and resolution, business hours, and what pauses the clock
  • Triage a batch of real tickets with the team lead — priority, tags and owner, then compare decisions
  • Write a bug report engineering can act on — steps to reproduce, expected and actual result, account ID, browser and screenshots, after searching for an existing issue
  • Learn the escalation paths and incident process — engineering, billing and account management, plus the status page during an outage
  • Route privacy requests to the privacy team the same day — requests for a copy of data, deletion or opting out, in whatever words they arrive
Phase 5 — If Changing Accounts

Phase 5: Identity Verification & Account Changes

Shown only for agents who will change customer accounts. It closes with the team lead’s sign-off, which holds the checklist until given.

  • Walk through the identity verification procedure — which check each change needs, carried out through a channel already on the account
  • Practise refusing an unverified account change — urgency, a new email address and a convincing story are the usual signs
  • List the changes that always need a second person — such as ownership transfer, removing two-factor authentication or changing an admin’s email
  • Report suspected account takeover attempts to security
  • Team lead approves the agent for account changes
Phase 6

Phase 6: Shadowing & the Reviewed Queue

The move to the independent queue is an approval, given when the review log shows few corrections, not when a set number of days has passed.

  • Shadow a senior agent working the live queue — including how they choose which ticket to take next
  • Work the reviewed queue with every reply checked before sending
  • Keep a log of review feedback — ticket, what was corrected and whether it recurs
  • Write or update one knowledge base article — from the gap list in Phase 2, reviewed and published
  • Team lead approves the move to the independent queue
Phase 7

Phase 7: Independent Queue & First Review

Spot checks carry on until the reviewer is satisfied. The 30-day review is due a month after the start date, whichever day the agent left the reviewed queue.

  • Start the independent queue with weekly spot checks — a sample of sent replies scored by the reviewer
  • Read the first customer satisfaction comments with the team lead — the comments, not only the score
  • Add a second channel or a harder ticket category
  • Hold the 30-day support onboarding review — quality, SLA performance and articles written, with goals for the next month

Four Tickets a New Agent Should Never Close Alone

Most tickets are questions about the product. A few look the same in the queue but carry a legal deadline or a security risk, and the new agent is often the first person to read them. Training should focus on spotting these four and passing them on fast. This is process guidance, not legal advice; your privacy and security leads own the rules.

Privacy request

“Delete my data” or “What do you hold on me?”

  • UK: the ICO says a request can be made verbally or in writing, including on social media, to any member of staff, without using any particular words
  • UK: the response is normally due within one month, extendable by up to two more for complex requests
  • California: covered businesses respond within 45 days, and staff who handle privacy questions must know how to direct consumers to their rights
Account takeover

“I’ve lost my phone, please remove two-factor”

  • Attackers phone and message help desks to get passwords and MFA reset, as the US CISA and FBI describe in their Scattered Spider advisory
  • Verify through a channel already on the account, never with details the requester supplies
  • Pass anything that feels rushed or odd to security instead of refusing it alone
Data sent wrongly

“Why can I see another company’s invoice?”

  • A reply to the wrong person, or a customer seeing someone else’s data, may be a personal data breach
  • Under UK GDPR, a notifiable breach goes to the ICO within 72 hours of becoming aware of it, so the clock may start with the agent
  • Tell the privacy lead at once; do not try to fix it quietly
Legal or payment dispute

“My lawyer will be in touch”

  • Legal threats, chargebacks and complaints to a regulator have their own owners
  • The agent acknowledges the message and passes it on without commenting on liability
  • The ticket stays open until the owner confirms they have it

California’s rules apply only to businesses that meet the CCPA thresholds, and several other US states have their own privacy laws with different deadlines. In the UK, the Data (Use and Access) Act 2025 amends parts of the subject access rules, so check the ICO’s current guidance before you write the training. Sources: the ICO on recognising a subject access request, the California Privacy Protection Agency regulations, the CISA Scattered Spider advisory and the ICO on reporting a breach.

Why Run Support Agent Onboarding in CheckFlow?

1

Account access only after approval

One answer on the first phase decides whether the identity verification phase appears at all. When it does, it ends in the team lead’s approval, and nothing after that task opens until the approval is in.

2

The queue moves on evidence

The buddy and reviewer are picked once, so drafts and reviewed replies go to the right person. The feedback log sits on the checklist as a table, and the move to the independent queue is an approval based on that log rather than a date on the calendar.

3

Every new agent, the same standard

Every due date is set from the agent’s start date, which lets a support lead hiring several agents at once see who is behind. Quiz scores, the first article link and the 30-day review notes are recorded with names and timestamps, and the reports compare one hire with the next.

Support teams grow in bursts after a launch or a funding round. CheckFlow’s onboarding software keeps a separate template for each role, with conditional phases, approvals and reports showing which new agents are still on the reviewed queue.

Frequently Asked Questions

When should a new support agent work the queue alone?

+

When the reviewed queue shows they no longer need it. Count the corrections in the review log: once replies go out with only minor edits across the ticket types they will handle, the team lead can approve the move. A complex product takes longer than a simple one, so a fixed number of days tends to be wrong in both directions. Keep spot checks going for the first weeks on the independent queue.

Should new agents use macros?

+

Yes, as a starting point. Macros keep facts, links and policy wording consistent, which matters most when someone is new. The risk is sending a macro that answers a slightly different question from the one the customer asked. Train agents to read the ticket twice, pick the macro, then edit it so the first line responds to what the customer actually wrote. Reviewers should flag unedited macros in the reviewed queue.

How should support agents verify a customer’s identity?

+

Use something the requester cannot simply know or invent. The safest checks run through a channel already linked to the account, such as a request made from the signed-in app or a confirmation sent to the registered email address. Details found in a signature, on LinkedIn or in an old invoice prove little. Write down which check each type of change needs, and require a second person for the riskiest ones, such as removing two-factor authentication.

What should an agent do with a request to delete a customer’s data?

+

Acknowledge it, tell the customer who will handle it, and route it to the privacy team the same day using your agreed process. The agent should not delete anything or promise a timescale themselves. Requests for a copy of personal data work the same way. Under UK data protection law these requests can arrive in any channel and in any wording, so agents need to recognise them even when the customer never uses a legal term.

How is this different from the call centre agent checklist?

+

This checklist is for written support, mostly asynchronous, where the agent can draft and have a reply checked before it is sent. It puts product knowledge, the knowledge base and engineering escalation at the centre. Teams that answer the phone in real time need something else. The Call Centre Agent Onboarding Checklist is built around the softphone and dialler, fixed script lines, taking payments without recording them, calling rules, and a supported first period on real calls.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

New Support Agents Who Know the Product Before They Answer

Free trial — no credit card required.