If it's something you're going to be doing often, I recommend creating the employee record (without access) and any necessary roles in production so they carry over with a refresh. E.g. we have some developers that should always have access to sandbox so there's a developer role and their employee records in production. That way I don't have to re-create them every time we do a refresh. I just go into sandbox, add the role to their employee record, tick the give access checkbox, and they're all set.