Ownership and recovery
IT Ownership Register
Know who can act on the accounts, domains and essential services before a departure or provider change forces the question.
You may recognize this
Start with what is happening
Domain renewal notices go to an address or card nobody recognizes.
The main Microsoft 365 administrator account is still controlled by a former employee or provider.
Nobody can recover the firewall, cloud or backup-provider portal.
Backup alerts arrive somewhere, but no accountable owner has been named.
Why it matters
A decision you can explain
A business can keep operating while its technology ownership becomes fragile. The gap appears at the worst time: a departure, renewal, provider change or incident that requires administrator access.
Examples
- A registrar sends renewal notices to a former mailbox.
- A provider knows the password, but recovery still depends on someone who has left.
- A firewall or backup portal exists without a business owner or recovery method.
- One vendor account is shared by several people, with no clear approval path for a change.
Review scope
What the agreed review examines
- The services that could interrupt work: domain, Microsoft 365, DNS, backup, network and key vendors.
- Who is authorized to act, and how access would be recovered if that person became unavailable.
- Available evidence such as renewal notices, contracts, portals, documentation and contacts — without collecting secrets.
- Responsibilities held by the business, the current provider or an approved specialist.
Customer receives
Useful next steps
- A readable register of services, owners, administrative access and recovery paths.
- A short list of unknowns that deserve a decision before a departure, renewal or transition.
- A clear distinction between what the business should control and what a provider may operate for it.
- A next documentation or verification step, without turning every unknown into a project.
Scope clarity
What is included and what may be added
Included
- An interview with the people who understand the systems and business decisions.
- A review of agreed accounts, vendors and documents, producing a map without passwords or MFA secrets.
- Priority for access whose loss could block a renewal, recovery or provider change.
Additional work
- Account recovery, provider change or configuration after the ownership issue is understood.
- A secrets vault, automation or integration with a management system.
- Security remediation and infrastructure work beyond clarifying ownership.
Scope, deliverables, and pricing are confirmed before work begins. Additional work requires approval.
Setup and onboarding
Preparation is part of the work
We confirm the scope, evidence, customer responsibilities and any licences or third-party costs before changes are considered.
Customer responsibilities
- Name the people authorized to confirm ownership and approve a change.
- Provide available documents and observations without sending secrets by email or putting them in the register.
- Confirm business owners, vendors and recovery priorities.
A useful next conversation
Start with technology ownership
Tell us what is happening. Initial contact confirms the right scope and requirements; it does not authorize a change.
Start with technology ownership