A lot of small businesses run on institutional knowledge: one person who knows the Wi-Fi password, the admin login, which server does what, and how the backup actually works. That arrangement is invisible until the person is no longer available, and then it becomes a real problem.
Secure administrative ownership
Start with every account that can change, recover, purchase, delete, or transfer a business system. Record the platform, account name, responsible owner, recovery method, and where the credential is stored. Confirm the business controls the recovery email and phone number rather than relying on a departing employee's personal information.
Prioritize the domain registrar, DNS, email tenant, cloud platforms, internet provider, firewall, network equipment, backup platform, website, accounting systems, and line-of-business applications. Losing control of a domain or tenant can affect many other systems at once.
- Primary and secondary administrator accounts
- Recovery methods and emergency codes
- Domain, DNS, website, and email ownership
- Cloud, network, security, and backup portals
- Software licensing and billing accounts
Capture how the environment fits together
A useful network diagram does not need to be elaborate. It should show internet connections, firewalls, switches, wireless access points, servers, important network segments, remote access, and links between locations. Label devices with their location, purpose, management address, and support status.
Cloud documentation should identify tenants, subscriptions, identity providers, storage locations, shared mailboxes, groups, security policies, and integrations. The goal is to reveal dependencies. If changing one system affects another, the relationship should not exist only in someone's memory.
Document recurring operations and unfinished work
Ask for the procedures that keep the environment running: employee onboarding and departure, account recovery, device setup, patching, certificate renewal, backup review, vendor escalation, and after-hours response. Include who approves access and how unusual requests are handled.
Also record work that is incomplete, temporary, or intentionally postponed. A future consultant needs to know which settings are deliberate, which risks have been accepted, and which changes were waiting on budget, a vendor, or a business decision.
Verify backups and vendor relationships
A backup record should state what is protected, how often it runs, how long data is retained, where copies are stored, who receives failure alerts, and how a restore is started. If possible, perform a representative restore while the current IT person is still available.
Create a vendor list with account numbers, support contacts, contract dates, renewal terms, and the services each vendor provides. Confirm that invoices and contracts are accessible to the business. This prevents a future outage from beginning with a search through old email.
Make the handoff usable
Store the final record in a location the business controls and restrict sensitive credentials appropriately. Separate passwords from general documentation while making sure authorized leadership knows how to obtain them. Review the material with the incoming owner rather than treating a folder transfer as a complete handoff.
Documentation should be current enough to support the next decision, not impressive enough to sit untouched. A concise diagram, accurate access record, vendor list, recovery procedure, and known-issues log are more valuable than a large document nobody can maintain.
