An employee onboarding app should collect the paperwork once and then forget it on purpose.
Day one has a shape no other week has. Someone who does not have an account yet has to hand over a tax form, prove they are allowed to work, read four policies, meet a team and find the kitchen, and most of it has to happen before they can log in to anything. An employee onboarding app is what carries them through that, and like most internal business apps it succeeds or fails on the boring parts: who owns each step, when it is due, and where the sensitive files end up.
This page covers the four tracks onboarding actually runs on, the rules attached to the identity documents you collect, what should never be stored on the device and why, and what the first week needs once the paperwork clears.
See what belongs on the phoneThe short version
Collecting the documents is the easy half, deciding where they rest is the hard one.
Any tool can show a checklist. What separates a working app from a liability is what happens to a photograph of a passport between the second the camera takes it and the day, three years later, when somebody has to produce it.
Two rules cover most of the design. Sensitive documents travel through the phone and do not live on it. And every step has exactly one named owner, because a task assigned to a department is a task nobody does.
Onboarding runs four tracks, not one checklist
A new hire onboarding app that models the process as one flat list feels wrong within a week, because the items are not comparable. Paperwork is a legal obligation with a fixed deadline. Access provisioning is a queue with a dependency chain: the mailbox has to exist before the sign on group can be set, and the group has to be set before the payroll system will open. Training is a sequence of sign offs that has to be evidenced later. The human track, a buddy and a first lunch and a tour of the building, has no deadline at all and is the part people actually remember.
Each track has a different owner, and owner is the field most homemade tools leave out. HR is not an owner. The unit of work is one person plus one date, and the app should refuse to save a step that has neither. That single constraint removes most of the chasing that onboarding usually generates.
Onboarding is also where a new employee meets the systems they will use for years. The account created on day one is the same account they will use to book leave and change a bank detail in an employee self service app, so it is worth creating it properly rather than as something temporary to be tidied up later.
The rules attached to the documents you collect
In the United States, Form I-9 sits at the middle of onboarding paperwork, and two of its rules shape the app directly. The first is that the employee chooses which documentation to present from the Lists of Acceptable Documents, and the employer cannot specify which documentation an employee will present. An upload screen with a passport slot and nothing else is steering the person toward a choice the employer is not allowed to make for them. The screen has to offer the lists, not a preference.
The second rule is about copies. Outside E-Verify requirements, copying or scanning the documents is optional. If you do choose to copy them you must retain the copies, and you must do so for all employees, regardless of actual or perceived national origin, citizenship or immigration status, or you may violate anti-discrimination laws. The copies have to be kept with the Form I-9 or the employee record, and be retrievable in line with the electronic retention standards. So document upload cannot be a feature some managers use and others skip.
Retention is the other constraint worth designing around. A Form I-9 has to be retained for three years after the date of hire, or one year after the date employment ends, whichever is later. The record therefore outlives the session, outlives the handset, and often outlives the employee's own account. That is the plainest argument for the file living in storage you control, with an audit trail, rather than anywhere on a phone.
Other countries run the same shape of check with their own list and their own deadline, so the document step should be configurable rather than hard coded to one jurisdiction. If you hire in more than one country, the safest structure is a document requirement per location, with the list of acceptable evidence as data rather than as screens.
USCIS Handbook for Employers M-274, retaining copies of Form I-9 documents
What should never be stored on the device
A phone is the right place to capture an identity document and the wrong place to keep one. The camera makes the file, so for a moment the scan exists on the handset by definition. The design job is to make that moment short: upload it, confirm the server accepted it, delete the local file, and never write it to the shared photo library, where it will sync to a personal cloud account and outlast the job.
People reach for the encrypted store at this point, and it does not fit. In an Expo project, expo-secure-store encrypts key value pairs locally, using Android's Keystore system and, on iOS, keychain services. It is built for short strings: large payloads can be rejected by the platform, and historically some iOS releases refused values above roughly 2048 bytes. A photograph of a driving licence is hundreds of times larger than that. The secure store is where a session token belongs, not a document.
One more detail catches teams out. Because of how the iOS keychain works, values stored with expo-secure-store persist across app uninstallation when the app is reinstalled with the same bundle identifier. Deleting the app is therefore not a deletion story you can offer anyone. Deletion has to be something your server performs on request, and the app needs a button that asks for it.
So the list of things that should never be on the handset after the step is finished: the document image, a national identity or tax number in any local store, bank details for payroll, and any of those repeated into a log line or a crash report. What can sit there safely is a session token, which checklist items are ticked, and draft answers nobody would care about.
Expo documentation, expo-secure-store storage and platform limits
Try it
Phone or server
Pick where each piece of onboarding data should rest once the step is finished.
Photo of a passport or driving licence
National identity or tax number
Bank details for payroll
The signed in session token
Which checklist items are done
After the paperwork comes the part people judge you on
A staff induction app that stops when the forms are signed has solved the employer's problem and left the employee's alone. Week one questions are small and constant: where do I park, who approves this, what is the wifi password, when is the stand up, am I meant to be in that meeting. The answers live in scattered documents and in the heads of three people, and a new hire will ask the same three people separately rather than interrupt a fourth time.
The first shift is also the first real transaction. Someone has to be told when they start and someone has to record that they did, which in shift work means the rota and the clock, and that is why onboarding tends to end up sitting next to an employee time clock app rather than away from it.
The number worth putting on the screen is not percentage complete. It is time to first useful day: the date on which every blocking item was cleared. That figure tells a manager whether onboarding is working, it is comparable between hires, and it falls straight out of data an HR onboarding app already holds.
What each way of onboarding actually gives a new hire
| Approach | Day one paperwork | Access steps tracked | One place for documents | Fits your own process |
|---|---|---|---|---|
| Email with a PDF pack | the person prints it | No | No | No |
| Shared spreadsheet checklist | manual | if someone updates it | No | Yes |
| Onboarding module in an HR suite | Yes | with integrations | Yes | within its template |
| Payroll provider onboarding tab | Yes | No | Yes | No |
| An onboarding app you build | Yes | Yes | if you design it that way | Yes |
Building one around your own first week
HR platforms are built for HR departments, priced per employee per month, and shaped around the modules the vendor already sells. A company hiring twenty people a year needs a fraction of that, plus two or three things the platform will not do: an induction step that applies to one site only, a signature a named partner has to collect in person, a training video that must be watched before a door code is issued.
Newly is an AI app builder. You describe the app you want, including the steps your onboarding really has, and it writes a React Native and Expo project you own and runs it on a cloud simulator while it builds. Plans are $25 a month and there is no free plan. iOS ships through TestFlight with your own Apple Developer account, and Android publishes to Google Play internal testing from the Deploy tab, with a standalone production APK as well. There are no built in payments, so payroll stays exactly where it is.
Before drawing a single screen, settle what a new hire may see. Onboarding is the one workflow where three roles touch the same record on the same day, and a permission model added afterwards is the thing that leaks a document.
Questions people ask about employee onboarding apps
It is the app that carries a new hire from offer accepted to productive, covering four things at once: the legally required paperwork, the accounts and access they need, the training they have to sign off, and the human introductions. The distinguishing feature is not the checklist, it is that each step has one owner and one date.
Write down your own first week, then build that
List every step a new hire has to clear, who owns it and when it is due, then build the app around that list instead of around somebody else's template.
Start building