If Your IT Person Got Hit by a Bus Tomorrow,
Could You Recover?

Everything about your business IT lives in someone's head. One resignation, one illness, one unexpected departure — and you're locked out of your own systems. Here's how to fix that before it becomes a crisis.

We call it the bus factor. It's a morbid way to phrase it, but it captures the risk perfectly: if your IT person got hit by a bus tomorrow, what would happen to your business?

More likely scenarios than a bus: they quit without notice. They retire. They get sick for two months. A family emergency takes them offline for a week at the worst possible time. Any of these things happen every day, to real businesses, and the damage they cause isn't from bad intentions — it's from the fact that everything about the technology that runs the business was stored in exactly one person's head.

After three decades of walking into businesses as a new IT provider, I can tell you that the scariest moments in this job aren't ransomware or server crashes. They're the moments when a business owner looks at me and says, "We don't know any of our passwords. Our IT guy set everything up and he's not returning calls." That's a real situation. It happens more than you'd think.

The good news: this problem is entirely preventable. What follows is a plain-English guide to IT documentation — what it is, why it matters, and exactly what needs to be documented so that your business can survive any single point of failure in your IT support.

The Real Risk Isn't a Bus. It's a Two-Week Notice.

Let's be clear about what we're really talking about. The bus is a thought experiment. The actual risk that bites businesses is far more mundane: your IT person leaves.

Maybe they got a better offer. Maybe they're retiring. Maybe the working relationship turned sour and they're not feeling particularly generous on their way out the door. Regardless of the reason, when an undocumented IT person leaves, they take a huge chunk of institutional knowledge with them — and you don't always realize how much until you need it.

Here's a partial list of what disappears when an undocumented IT person walks out:

Any one of those gaps can bring your business to a halt. Together, they can take weeks to untangle — and during those weeks, you're either dead in the water or paying someone like us emergency rates to piece it back together from scratch.

The solution isn't complicated. It's just documentation. And the time to build it is now, before you need it.

What Actually Needs to Be Documented

The word "documentation" sounds like a bureaucratic nightmare. It doesn't have to be. Think of it less as writing a manual and more as answering a simple question: if a competent IT person showed up tomorrow with zero prior knowledge of your business, what would they need to know to keep everything running?

Here's the core of what needs to exist:

1. Your Credential Inventory

Every admin account, every service account, every system login. This doesn't mean writing passwords on a sticky note — it means storing them in a secure, shared password manager that your business controls. A business password manager like Bitwarden Teams or 1Password Business is a $4/user/month insurance policy against credential chaos. If your IT person is the only one with access to all the passwords, you don't own your own systems.

2. Your Network Diagram

A simple diagram showing what equipment you have, how it's connected, and what everything is for. Router, switches, access points, servers, firewalls — drawn out so someone new can understand your setup without having to trace every cable. It doesn't need to be beautiful. It needs to be accurate and current.

3. Hardware Inventory

A list of every significant piece of equipment — servers, switches, firewalls, UPS units — with the model, serial number, purchase date, warranty status, and what it does. When something fails at 2 AM, you want to know in 30 seconds exactly what you're dealing with and whether it's still under warranty.

4. Software and Licensing

What software is installed, what licenses you own, who the license is registered to, how many seats, what the renewal date is, and who the vendor contact is. This applies to everything from Microsoft 365 to your accounting software to any industry-specific tools. Licensing surprises at renewal time are expensive and avoidable.

5. Your Backup Configuration

What's being backed up, how often, where to, and how to restore from it. This is separate from actually having a backup — it's documentation of the backup so that if the person who set it up is unavailable, someone else can verify it's working and recover from it if needed. We've written more about building a real disaster recovery plan if you want to go deeper on this.

6. Vendor and Support Contacts

Every vendor you work with: your internet provider, your phone system, your software vendors, your hardware suppliers. Account numbers, support phone numbers, and who at your company is the account contact. When your internet goes down, you shouldn't have to spend twenty minutes finding the right phone number.

7. Runbooks for Common Tasks

Short, step-by-step procedures for the things that happen regularly: how to add a new user, how to set up a new computer, how to grant access to a shared drive, what to do when the server goes down. These don't need to be novels. They just need to be specific enough that someone could follow them without calling the person who wrote them.

Where to Keep It (And Where Not To)

The most common place we find IT documentation: in the IT person's head. Second most common: in a folder on their laptop. Third: in a spreadsheet that's two years out of date. None of these work.

Good documentation needs to be:

For credentials, a business password manager is the right answer. Not a shared spreadsheet, not a sticky note, not a text file — a dedicated tool that stores passwords securely, tracks who has access, and lets you revoke access when someone leaves.

For everything else — network diagrams, hardware inventory, runbooks, vendor contacts — a shared document repository works well. Microsoft SharePoint or OneDrive, Google Drive, or even a simple IT documentation platform like IT Glue or Hudu (tools we use internally). The key is that it lives somewhere the business owns, not in the IT provider's systems, and that at least two people know how to get to it.

One rule we live by: your IT documentation should never live exclusively with your IT provider. We keep documentation about our clients' environments in our own systems — that's part of the job — but our clients always have their own copy of everything. When a client leaves us (it happens, and that's fine), they walk away with everything they need to hand to the next IT team. That's how it should work. If your current provider isn't giving you that, ask why.

The Offboarding Problem Nobody Talks About

Here's a scenario we've seen play out too many times. A business has an IT person — either an employee or a contractor — who's been with them for years. Then the relationship ends, for whatever reason. And suddenly the business realizes that:

This isn't a villain story. Most of the time, the IT person set things up the way they set things up because it was convenient, not because they were planning to hold you hostage. But the effect is the same either way: you don't control your own business's technology.

The fix starts with a clean offboarding process every time a person with IT access leaves the business. Before they leave, you should have already transferred ownership of every account, changed every password they knew, and revoked their access to every system. If you don't know what they had access to, you can't properly close it out — which is exactly why the documentation needs to exist before someone leaves, not after.

If you're reading this and thinking "I'm pretty sure our old IT guy still has access to some of our systems," you're not alone. And you should fix that today. A security audit of your active accounts is a good place to start.

How to Get Started Without Being Overwhelmed

I'm not going to pretend documentation is exciting work. It isn't. Nobody hired you to write IT procedures. But it's one of those things that's genuinely boring when you do it and genuinely catastrophic when you don't.

Here's a practical starting point that won't take a month:

Week 1: Credentials. Get a business password manager set up. Have your IT person spend a few hours logging every admin account into it. At minimum: your domain registrar, your DNS provider, Microsoft 365 or Google Workspace admin, your firewall, your server admin accounts, and your backup software. That's your most critical foundation.

Week 2: Hardware and vendors. Walk through your server room or equipment closet with your IT person. List everything with make, model, and serial number. Pull together vendor contacts for your top five vendors. This doesn't need to be perfect — something is dramatically better than nothing.

Week 3: Network and runbooks. A rough network diagram drawn in something as simple as draw.io. Two or three runbooks for the most common tasks your team handles (new user setup, new computer setup, what to do if the server's down). Not comprehensive — just the highest-traffic procedures.

After that, make documentation part of how you run IT. Every time something changes — new hardware, new software, new employee, new vendor — update the documentation. Fifteen minutes of updating beats fifteen hours of reconstructing.

If your IT provider handles all of this for you, great — but still ask them for a copy. If they can't or won't provide it, that's worth a serious conversation about whether you're in a vendor lock-in situation.

What a Good IT Partner Does Differently

When we take on a new client, one of the first things we do is a documentation sprint. We go through their environment, catalog everything, set up a shared credential vault they control, and build a network diagram and hardware inventory. It takes a few hours. It's not glamorous. But it means that on day one, the client is no longer dependent on any single person — including us.

That's how a professional IT relationship should work. Your IT provider should be making you more self-sufficient over time, not more dependent on them. If you've been with your IT provider for two years and you still couldn't tell me what your admin password is or where your backups go, something's wrong.

Good IT support means you always have access to your own systems, your own documentation, and your own credentials — even if you never need to use them directly. It means that if we got hit by a bus tomorrow (there's that bus again), you could call another IT firm and hand them everything they need to keep your business running without missing a beat.

That's not just good practice. It's basic respect for the business you've built.

If you want to do a quick gut-check on your current situation, our IT Buyer's Guide covers the questions you should be able to answer about your own IT environment. If you can't answer most of them, that's your starting point.

Not Sure What You'd Find If You Looked?

We can walk through your environment with you, assess where the gaps are, and build the documentation your business needs to stop depending on any single person. It's one of the highest-value things we do for new clients — and it doesn't take long.

Get a Free IT Assessment