In modern organizations, technology environments change constantly as employees join, relocate, adjust roles, adopt new tools, or leave the business. These routine but important service activities are often grouped under the term Moves, Adds, and Changes, commonly shortened to MAC. Effective MAC management helps IT teams keep users productive, assets controlled, costs predictable, and security risks reduced.
TLDR: Moves, Adds, and Changes refers to the IT processes used to relocate users or equipment, add new services or assets, and modify existing technology configurations. Strong MAC management depends on clear request workflows, documentation, approvals, asset tracking, communication, and post-completion validation. When handled well, MAC activities reduce downtime, improve security, and support smoother organizational growth.
What Are Moves, Adds, and Changes?
All Heading
Moves, Adds, and Changes describe a category of IT service management activities related to adjustments in workplace technology. These activities may involve employees, hardware, software, network access, phone systems, cloud applications, user permissions, office locations, or digital workspaces. Although many MAC requests appear simple, they often affect multiple systems and departments.
A move usually refers to relocating a person, device, workspace, phone extension, network connection, or service from one place to another. This may include moving an employee to a different desk, transferring a department to another floor, migrating a user to a new device, or shifting workloads to a different environment.
An add refers to the introduction of a new user, service, device, application, license, mailbox, access group, phone line, or network connection. Common examples include onboarding a new employee, issuing a laptop, creating cloud accounts, assigning business software, or adding a printer to a department.
A change refers to modifying an existing configuration, access level, device setup, software license, user profile, or service arrangement. Examples include changing a user’s permissions after a promotion, updating a device configuration, replacing a monitor, modifying a distribution list, or altering a security policy.
Why MAC Management Matters
MAC activities are often repetitive, but they are not trivial. Poorly managed requests can result in lost productivity, security gaps, compliance issues, duplicate spending, and user frustration. For example, if a departing employee’s access is not removed correctly, sensitive data may remain exposed. If a new hire’s equipment is not prepared on time, the employee may lose valuable working hours during the first week.
Strong MAC management provides a structured approach to operational change. It gives IT teams a consistent way to receive requests, assess requirements, gain approvals, assign work, document outcomes, and verify completion. It also helps business leaders understand service demand, staffing needs, asset utilization, and recurring sources of inefficiency.
Common Examples of MAC Requests
Organizations typically encounter many types of MAC requests throughout the employee life cycle and daily operations. These may include:
- Employee onboarding: creating accounts, assigning devices, configuring email, and granting application access.
- Employee offboarding: disabling accounts, recovering assets, removing licenses, and preserving business data.
- Desk or office relocation: moving phones, monitors, docking stations, network connections, and user profiles.
- Role changes: updating permissions, group memberships, approval rights, and software access.
- Hardware additions: issuing laptops, mobile devices, printers, headsets, or specialized peripherals.
- Software changes: assigning licenses, installing applications, updating versions, or removing unused tools.
- Telephony updates: adding extensions, changing call routing, configuring voicemail, or moving numbers.
- Network changes: enabling ports, updating Wi Fi access, modifying VPN rights, or changing firewall rules.
The MAC Process in IT Service Management
A typical MAC process begins when a user, manager, human resources representative, facilities team, or department head submits a request. The request should include the required details, preferred completion date, business justification, affected users, location, devices, applications, and approval information. In mature environments, service catalogs and standardized request forms reduce ambiguity and help IT teams gather complete information from the start.
After submission, the request is reviewed and categorized. Some MAC requests may be low risk and handled as standard service requests. Others may require formal change management, especially when they affect security, infrastructure, networks, production systems, or large groups of users. The distinction between a routine service request and a formal change is important because each may require different approval, testing, and communication steps.
Once approved, the request is assigned to the appropriate technical team. Tasks may be divided among help desk staff, desktop support, systems administrators, network engineers, security teams, facilities personnel, procurement specialists, and application owners. Clear task ownership prevents delays and reduces the chance that critical steps will be missed.
Finally, the work is completed, tested, documented, and closed. The requester should confirm that the result meets the business need. Asset records, configuration management databases, license counts, and access records should be updated before closure.
Best Practice 1: Standardize Request Intake
Standardization is one of the most important MAC management practices. When requests arrive through email, chat, hallway conversations, spreadsheets, and phone calls, IT teams struggle to prioritize and track work. A centralized ticketing or IT service management platform allows requests to enter a consistent workflow.
Effective request forms should be specific enough to capture necessary details without becoming burdensome. For example, a new employee request may ask for job title, department, manager, start date, location, device type, required applications, security group requirements, and special equipment needs. A move request may ask for current location, destination, moving date, network needs, assigned assets, and telephony requirements.
Best Practice 2: Define Approval Workflows
Approvals protect budgets, security, and compliance. Not every employee should be able to request costly software, privileged access, or confidential data rights without oversight. Approval workflows should match the risk and cost of the request.
For low-risk requests, approval from a direct manager may be enough. For high-risk access changes, approval may be required from information security, data owners, compliance officers, or application administrators. For hardware purchases, procurement or finance may need to review the request. Automated approval routing can significantly reduce delays.
Best Practice 3: Maintain Accurate Asset and Configuration Records
MAC management depends heavily on accurate information. IT teams need to know which assets exist, where they are located, who uses them, what software is installed, and which services are connected. Without reliable records, moves and changes can create confusion, duplicate purchases, and security blind spots.
A strong asset management practice should track laptops, desktops, monitors, mobile devices, printers, network equipment, accessories, software licenses, and warranty details. A configuration management database, or CMDB, may also track relationships between users, devices, applications, services, and infrastructure components. These records should be updated whenever a MAC request is fulfilled.
Best Practice 4: Coordinate Across Departments
MAC activities regularly involve more than the IT department. Human resources may trigger onboarding and offboarding. Facilities may coordinate desk moves. Finance may approve purchases. Security may validate access changes. Department managers may define application requirements. Without cross-functional coordination, request fulfillment can become fragmented.
Organizations benefit from documented responsibilities and service level expectations. For example, human resources may be responsible for submitting onboarding requests five business days before a start date, while IT may be responsible for preparing standard equipment within three business days after approval. Clear timing expectations help prevent last-minute emergencies.
Best Practice 5: Classify Risk and Impact
Not all MAC requests carry the same level of risk. A monitor replacement has limited impact, while a firewall rule change or privileged access update may introduce major security exposure. IT teams should classify requests based on risk, complexity, urgency, user impact, and business criticality.
Low-risk, repeatable tasks can often be automated or handled through standard operating procedures. Higher-risk changes should receive additional review, testing, communication, rollback planning, and post-implementation validation. This balanced approach prevents unnecessary bureaucracy while still protecting critical systems.
Best Practice 6: Automate Repetitive Tasks
Many MAC tasks are ideal candidates for automation. User account creation, group membership assignment, software deployment, device enrollment, license allocation, and offboarding steps can often be automated through identity management, endpoint management, and IT service management tools.
Automation improves consistency and reduces manual error. It also allows support teams to focus on complex or high-value work rather than repeating routine steps. However, automation should be carefully governed. Automated workflows must include appropriate approvals, logging, exception handling, and periodic review.
Best Practice 7: Communicate Clearly With Stakeholders
Communication is essential during moves, additions, and changes. Requesters should know when work will begin, what information is needed, whether approvals are pending, and when completion is expected. Affected users should receive instructions, downtime notices, or setup guidance as needed.
For larger moves, such as office relocations or department restructuring, communication plans should include timelines, responsibilities, support contacts, equipment labeling instructions, and contingency procedures. Clear communication reduces confusion and helps users prepare for interruptions.
Best Practice 8: Validate Completion and Capture Feedback
A MAC request should not be closed simply because a technical task was performed. Completion should be validated against the original requirement. If a new employee was onboarded, the employee should be able to sign in, access required applications, use assigned equipment, and communicate through approved channels. If a user was moved, network connectivity, phone service, printing, and workspace equipment should be checked.
Feedback also helps improve the process. Repeated complaints about delays, missing access, unclear forms, or approval bottlenecks may indicate opportunities for refinement. Metrics such as completion time, reopened tickets, first-time success rate, pending approvals, and request volume can reveal patterns that support better planning.
Security Considerations for MAC Management
Security must be built into every stage of MAC management. Adds and changes often involve access rights, while moves can expose physical assets or network connections. Offboarding, although sometimes treated separately, is closely related because access removal and asset recovery are critical controls.
Best practices include enforcing least privilege, reviewing access after role changes, disabling accounts promptly after departures, encrypting devices, tracking asset custody, and maintaining audit logs. Privileged access should receive stricter review and periodic recertification. Any request involving sensitive systems or regulated data should follow compliance requirements and data governance policies.
Measuring MAC Performance
Organizations can improve MAC management by measuring performance over time. Useful metrics include average fulfillment time, number of requests by type, percentage completed within service level targets, approval cycle time, automation rate, inventory accuracy, user satisfaction, and security exceptions.
These measurements should not be used only to judge IT staff. They should help identify process issues, training gaps, resource constraints, and opportunities for automation. For example, if most delays occur while waiting for manager approval, the solution may involve better reminder workflows or delegated approval rules rather than additional technicians.
Conclusion
Moves, Adds, and Changes are a normal part of business operations, but they require disciplined management. Each request can affect productivity, security, cost, and user experience. By standardizing intake, defining approvals, maintaining accurate records, coordinating departments, classifying risk, automating repeatable tasks, and measuring outcomes, organizations can turn routine service activity into a reliable operational strength.
When MAC management is mature, employees receive the tools and access they need at the right time, assets remain visible, and technology changes become easier to control. The result is a more responsive IT organization and a more efficient business environment.
FAQ
What does MAC mean in IT?
In IT service management, MAC stands for Moves, Adds, and Changes. It refers to routine technology service activities such as relocating users or equipment, adding new accounts or devices, and modifying existing access, configurations, or services.
Is a MAC request the same as a change request?
Not always. Some MAC requests are standard service requests with low risk, such as adding a monitor. Others may qualify as formal change requests when they affect infrastructure, security, compliance, or critical services.
Who is responsible for MAC management?
IT usually owns the MAC management process, but other departments often participate. Human resources, facilities, finance, security, procurement, managers, and application owners may all have responsibilities depending on the request type.
Why are approvals important for MAC requests?
Approvals help control cost, access, risk, and compliance. They ensure that the requested hardware, software, or permissions are appropriate for the employee’s role and business need.
How can organizations improve MAC request speed?
Organizations can improve speed by using standardized forms, automated workflows, predefined service catalog items, accurate asset records, clear approval paths, and measurable service level targets.
What are common risks of poor MAC management?
Common risks include delayed onboarding, unauthorized access, lost equipment, duplicate software spending, inaccurate inventory, user downtime, compliance failures, and increased help desk workload.
Recent Comments