It usually happens on a Friday.
The person who "knows the computers" resigns, and everything they carried in their head leaves with them: the passwords, the vendor contacts, the reason a server is configured this way, and the answer to "who do we call when this breaks?"
If that person was your only IT person, this is not a small problem. It is a coverage gap with a countdown on it, because the systems they managed will need attention whether they are there or not. The good news is that most of the damage can be prevented, and the rest can be recovered, if you move in the right order.
This guide covers what you actually lose, what to do in the first 48 hours, the recovery checklist, and how to make sure one resignation never puts your business in this position again.
Key Takeaways
- •The real loss when an IT person leaves is undocumented knowledge, not the job they did.
- •Secure admin accounts first, then capture everything you can before their last day.
- •A recovery checklist of passwords, vendors, and documentation should exist before you ever need it.
- •One person handling all your IT is a single point of failure; coverage and documentation remove the risk.
What you actually lose when the IT person leaves
Business owners usually assume the loss is temporary help. That is the smallest part of it. The parts that hurt are the things that only one person knew:
- Passwords and admin access. Microsoft 365, the server, the firewall, the Wi-Fi, the phone system, the backup console, the camera system. Some of these may exist nowhere else.
- Vendor accounts and relationships. The ISP login, the domain registrar, the software vendor, the hardware warranty. Without these, even routine renewals become research projects.
- How the environment actually works. Why certain settings exist, which machine runs the old accounting program, what that scheduled task does. Configuration that made sense to one person is invisible to everyone else.
- Coverage. When something breaks at 7 a.m., there is no one to call. That is not an inconvenience, it is downtime with nobody assigned.
Notice what all four have in common: they are knowledge and access, not effort. Rebuilding effort is easy. Rebuilding undocumented knowledge is not.
What to do in the first 48 hours
How you handle the first two days depends mostly on one thing: whether the person is leaving on good terms or not.
If they are leaving on good terms
Sit down with them before their last day and capture what you can. Most people will happily document their work when asked, especially if the departure is a promotion, a move, or retirement. Do not ask them to build a full IT manual in a day. Ask for the essentials:
- A list of every system and where the admin login lives
- Every vendor with a contact, account number, and renewal date
- Which tasks are scheduled and what happens if they fail
- Where the backups go and when they were last tested
If they are leaving suddenly or on bad terms
Protect the building first. Change or reset the admin passwords they knew, especially for Microsoft 365, email, the firewall, and backups. If multifactor authentication is in place, make sure the recovery methods belong to the business, not to their personal phone. Then do the same capture exercise with whoever else is left, even if the list is short.
The standard employee offboarding rules apply here too: revoke access, recover company devices, and change shared passwords. Our employee offboarding checklist covers the mechanics of removing access once you have control.
The recovery checklist every business should already have
Here is the uncomfortable test: if you can produce all of the following today, you are in good shape. If you cannot, this list is your to-do list, and it does not require a specialist to complete, just an afternoon with a checklist.
- Admin logins. Microsoft 365, server, firewall, Wi-Fi, phone system, camera system, backup console, domain registrar.
- MFA recovery. Who owns the recovery phone or keys for each system, and how you regain access if that device is lost.
- Vendor list. Every IT vendor with a contact name, account number, and renewal date.
- Network overview. A simple list of servers, main applications, and which office or device depends on them.
- Backup proof. Where backups live, when they last succeeded, and when one was last actually restored.
- Hardware and warranties. What equipment you own, how old it is, and what is still under warranty.
- Documentation location. One place, written down, that more than one person can open.
Store this in more than one place, and let more than one person know it exists. A password manager for the business is the practical tool here, not a spreadsheet that lives on one computer.
Why one IT person was never enough
Hiring one IT person is a reasonable choice for a small business. It feels cheaper than a provider, and one person who knows the environment can be very effective. The problem is structural, not personal: one person is a single point of failure.
When they take vacation, coverage disappears. When they get sick, there is no backup. When they resign, the knowledge leaves with them. None of that makes the person bad. It makes the arrangement fragile, and the fragility only becomes visible at the worst possible moment.
This is also why the common alternative, waiting until something breaks to call a break-fix shop, does not solve it. A break-fix provider will happily fix an outage, but they are not documenting your environment or holding your vendor logins while nothing is broken.
How managed IT removes the dependency
A managed IT provider changes the math in three ways:
- Documentation lives outside any one person. Passwords, vendors, configs, and backup status are maintained in systems the provider runs, not in an employee's head.
- There is always someone on call. Support is covered by the provider, so illness, vacation, or resignation does not create a coverage hole.
- Knowledge is shared. When the provider answers, the person on the other end can see your environment instead of asking you to remember who set it up.
A managed plan still works alongside internal staff, in a co-managed model, but the business no longer depends on a single employee for access and knowledge. If you are wondering whether that model fits, our guide to what an IT managed service actually is explains the difference in plain terms.
If you are hiring a replacement, do it differently this time
If the business decides to hire another IT person, build the structure before the person, not after:
- Require documentation as part of the job, not as a favor.
- Put admin access in a business password manager, and give the new hire access to it instead of a personal head full of passwords.
- Keep at least one external source of coverage, even if it is limited, so the business is never exposed during the next transition.
- Treat the departure checklist as part of every IT role, written down, the same way you would for any critical position.
And when you compare providers during the search, compare documentation and access too, not just price. That is the part that saves you in a transition. If you would like a sense of what to look for, we cover the provider evaluation basics in our guide to evaluating an IT provider.
Final thoughts
One resignation should not put your business at risk. It should not require your office manager to reverse-engineer a server, and it should not mean a weekend of downtime while someone figures out where the passwords went.
The fix is not complicated: documented access, tested backups, and more than one person or provider who can step in. Start with the recovery checklist above, even if you are not hiring anyone today. If you want help building that structure, or you find yourself in the middle of a transition right now, a free assessment is a sensible first step. We will help you figure out what you have access to, what you are missing, and what it will take to close the gaps.
Powerful IT Systems · Sussex, WI
Master's degree in Computer Science with 15+ years of hands-on IT experience serving Milwaukee-area businesses.

