If your IT person disappeared tomorrow: the documentation test
A one-page test for whether your business actually controls its own IT, and the 7 documents that should exist before you ever need them.
· Jake Schaaf, Founder of Atticus Rowan
The website renewal notice goes to an email address nobody in the company recognizes. The person who set up the domain 9 years ago was a contractor, and the registrar account is his personal Gmail. He is not answering. The site expires in 6 days.
We see some version of this story across 10-30 user businesses more often than any other single IT failure. Not ransomware. Not a server crash. Just a business discovering, at the worst possible moment, that it does not actually hold the keys to its own infrastructure.
Here is the test. If your IT person, whether that is an employee, a solo consultant or a managed provider, disappeared tomorrow, could a competent replacement pick up your environment within a week? If the answer depends on information that exists only in one person’s head or one person’s inbox, you do not have an IT setup. You have a dependency.
The 7 documents that should exist right now
None of this is exotic. A complete documentation set for a 10-30 user business fits in a few dozen pages and takes a provider who knows the environment roughly 8 to 12 hours to produce from scratch. Here is what belongs in it.
- Administrative credential inventory. Not the passwords themselves, but a record of every administrative account that exists, what it controls and where the credentials are stored. The storage location should be a business password manager vault the company owns, not a technician’s personal vault.
- Domain registrar and DNS access. Who owns the registrar account, which email address it is tied to and where DNS is actually hosted. Domains and DNS are the most commonly orphaned assets we encounter, and losing them takes email and the website down together.
- Software license and subscription list. Every paid product, the license count, the renewal date and the account that owns it. Microsoft 365, the accounting platform, the industry line-of-business app, the backup product, all of it.
- Vendor and renewal contact list. The internet provider, the phone system, the copier company, the security tools. Account numbers, support numbers and contract end dates. When something breaks, the first 30 minutes is usually spent figuring out who to call.
- Network diagram. Even a simple one. What the firewall is, what the switches are, what wireless equipment exists, what the internal IP scheme looks like and how remote access works. A photo of a labeled rack beats nothing.
- Backup and restore procedure. What is backed up, where it goes, how long it is retained and, critically, the actual steps to perform a restore. We wrote about why untested backups fail in our post on tested restores. Documentation is the first half of that discipline.
- Microsoft tenant ownership record. Who holds Global Administrator on the Microsoft 365 tenant, what the tenant name is and which account is the break-glass admin. The tenant is the single most important asset a modern small business has, and plenty of owners cannot name a single person with admin rights to it.
The uncomfortable questions to ask your current provider
If an outside company manages your IT, the documentation above should be yours on request. Not eventually. Not summarized. Yours.
Ask these 4 questions in your next review meeting:
- Can you send us our full documentation set this week?
- Is our domain registrar account in our name, with recovery going to an email address we control?
- Do we hold at least 1 Global Administrator credential on our own Microsoft tenant?
- If we ended our agreement today, what would the handoff package contain?
A professional provider answers all 4 without flinching, because documentation and clean offboarding are built into how they operate. We covered what mature service delivery looks like in the move from break-fix to managed IT, and documentation is one of the clearest markers separating the two.
Red flags that mean you have a problem
Some patterns come up repeatedly when we take over environments where documentation was never a priority:
- The registrar, DNS or tenant admin lives in a personal account belonging to a current or former technician
- Requests for documentation are answered with “you would not really be able to use it anyway”
- The provider positions their exclusive knowledge as a feature, “we know your environment inside and out, so you do not need any of this written down”
- Admin passwords change but the business is never told, and no one inside the company can reset them independently
- The answer to “where is that documented” is consistently a person’s name instead of a location
None of these automatically mean bad intent. Solo operators and small shops often hoard access out of habit, not malice. But the effect is identical either way. The business cannot change providers, cannot survive its IT person’s bad month and cannot honestly answer the vendor questions its own customers and insurers are starting to ask. Access hoarding is a vendor risk like any other, and it belongs in the same conversation as the rest of your vendor risk review.
Why this shows up on insurance and customer paperwork now
Cyber insurance applications increasingly ask whether administrative access is inventoried and whether privileged credentials are stored in a managed vault. Customer security questionnaires ask who administers your email tenant and how access is revoked when people leave. “Our IT guy handles it” is not an answer either audience accepts anymore.
The good news is that the fix is boring and fast. For most 10-30 user businesses, going from nothing to a complete, owner-held documentation set is a 2 to 3 week project, and most of that is calendar time waiting on account transfers, not labor.
What to do this month
- Run the disappearance test honestly. List what you could not recover or operate without your current IT person.
- Request your documentation set in writing and set a 2 week deadline.
- Move the domain registrar and DNS into a company-owned account with recovery contacts you control.
- Confirm a company-held Global Administrator credential exists for your Microsoft tenant and store it in a company-owned vault.
- Put a recurring calendar item on the books to re-verify all of it once a year.
Atticus Rowan builds this documentation as a standard part of onboarding every client, because we think a client who could leave us easily is the only kind of client worth having. If you cannot get straight answers about who holds your keys, talk to us and we will help you find out what you actually own.
Related insights
More on Operations & OT →August 20, 2026
Still on Windows 10? The ESU runway ends in October
Extended Security Updates bought Windows 10 holdouts some time, but the runway is short and the per-device price doubles each year, so August is the month to decide.
August 14, 2026
The 5-year-old laptop problem: hardware lifecycle without the drama
A staggered 4 to 5 year refresh cycle turns the surprise $30,000 hardware year into a predictable line item and quietly closes security gaps.
August 5, 2026
Your team is already pasting company data into AI tools
AI tool use in small businesses is already happening with or without a policy, so here is the sane setup: a sanctioned tool, plain data rules and a 1-page policy.