Put the company in control of its accounts
List the domain registrar, email platform, password manager, accounting system, source-code hosting, and cloud infrastructure. Record the business owner and the administrator for each. A founder’s personal inbox should not be the only way to recover the company domain. Keep recovery information in a controlled place that another authorized person can reach.
- Confirm who can renew the domain and update billing.
- Document administrative access and a recovery process.
- Use individual accounts; avoid passing around one shared administrator password.
- Record who approves access to finance, production, and customer data.
Make a repeatable laptop setup
Pick a small set of supported devices based on actual work. A software engineer running local containers and a coordinator working in a browser may need different configurations. Write down what arrives on a laptop, how it is enrolled in management, and how you verify its security settings. The goal is a repeatable handoff, not a different setup for every person.
- Record the assigned person, serial number, purchase date, and warranty.
- Check updates, disk encryption, screen lock, and recovery ownership.
- Install only the applications the role needs.
- Plan a replacement path for a failed or missing laptop.
Connect hiring and departures to IT
Choose one place for People Ops or the hiring manager to request equipment and access. Capture the start date, work location, role, device needs, and approver. Use the same inventory when someone leaves. A departure should trigger an access review across the whole application list, not just the email account.
- Assign an owner to each onboarding task.
- Test access to email, chat, and role-specific tools before handoff.
- Coordinate the departure time and access removal with the responsible manager.
- Record equipment return and data ownership decisions.
Decide what happens when something fails
Write down where employees ask for help, who triages requests, and who makes decisions during an outage. Separately, name the data you cannot afford to lose and test how to recover it. A synchronized folder is not a recovery plan by itself: confirm what happens after an accidental deletion, compromised account, or lost device.
Use your next business change as the review date
Review this checklist before a hiring wave, a move, or a customer security review. There is no universal headcount at which every startup needs a full IT department. The useful signal is whether recurring work has an owner and whether that owner has time to finish it. If engineers or operators keep absorbing interruptions, compare internal ownership, project help, and ongoing support.
Your working checklist
Use this as a starting point. Assign an owner and a due date to each item. Checkmarks stay on this device only; don’t enter employee information here.
0 of 12 completed
Common questions
What IT does a small startup need first?
Start with company-owned identity and accounts, a device inventory, a consistent laptop setup, controlled access, a recovery plan for critical data, and a support owner. Add tools when they address an identified need.
Can operations own IT before we hire an IT manager?
Operations can coordinate requests and vendors. Technical configuration and security decisions still need a qualified owner, and sensitive access needs approval from the appropriate business owner.
Platform references
For product-specific actions, check the current instructions for your edition and account type.