
Your operations manager gave two weeks’ notice yesterday.
She’s been with you for six years, so she knows everything: customer relationships, vendor passwords, project workflows, and accounting access. She’s the person who gets things done.
Once she’s gone, here’s what you’re about to find out. Nobody else knows how to run payroll. Three vendors only take requests from her email. The accounting software password lives in her personal password manager, and she’s the master admin on your network. Customers ask for her by name. And a good chunk of what keeps your company running only ever existed in her head.
That’s the simple version of this problem. Here’s the one that keeps me up at night.
What If She Hadn’t Given Notice?
What if instead, she got angry about something, called to quit on the spot, and spent the next two hours changing passwords and deleting files before you even knew what was happening?
Most businesses have no way to stop that, and I don’t think most business owners have ever really sat with how bad that could get.
Not Sure How Exposed You Are Right Now?
Most business owners have never tested this. If you’re realizing you don’t know the answer, let’s take a closer look before it becomes a real problem.
Get a Quick Access & Security Check
We’ll walk through who has access to what, and identify anything that could leave you locked out if the wrong person walked away tomorrow.
Two Different Problems
The first problem is dependency. If your business can’t function without one person, you’re vulnerable. When they leave, whether it’s planned or not, you’re looking at operational chaos, lost relationships, and knowledge walking straight out the door. That’s painful, but it’s survivable if you have some documentation and some time.
The second problem is worse. It’s all about security. If one person holds master admin access across your systems, and two-factor authentication (2FA) for those systems is tied to their personal phone, they can lock you out of your own business. Financial records, customer data, and the bank account all become something they control, not you. And if the 2FA code only goes to their phone, you can’t even get back in to fix it.
How Businesses End Up Here
Nobody sets out to build this kind of risk. It usually happens because growth outpaced planning. You needed someone who could do everything, so one person quickly became the keeper of all the knowledge. It was convenient to just ask “hey, can you handle this?” instead of building a real system. The systems worked, so everyone left them the way they were. And you trusted the person, so it never occurred to you to ask what would happen if they weren’t here one day.
The lack of a backup plan is a problem.
Can You Lock Down Your Systems in an Hour?
If a key employee walked out today, could you regain full access to everything within an hour?
Could you reset the network’s master admin password? Get into the accounting software? Access banking? Recover email if the admin account is compromised? Pull customer files? Do you have 2FA backups that don’t depend on that one person’s phone?
If you’re hesitating on any of those, that’s the vulnerability. And a disgruntled employee with just an hour of unsupervised access can cause damage that takes months to undo, if you can undo it at all.
I’ve seen the angry departure where someone gets let go, and before they’re even out the door, they’ve changed admin passwords, wiped shared drives, transferred funds, or emailed the client list to a competitor. I’ve also seen the more quiet version, where someone who was job-hunting on the side sets up forwarding rules or hides credentials weeks before anyone notices anything’s wrong. And I’ve seen it get even uglier, where an employee realizes exactly how much leverage they have and uses it to demand money before they’ll hand back access.
None of these require a criminal mastermind. They just require one person to have more access than they should and for no one to have a plan for what happens next.
What Fixes This
Start with an audit. Who has master admin access right now? Where are passwords stored? Who’s tied to your 2FA? Who is the only point of contact for a vendor or a client? If you’re not sure, that’s your answer.
After the audit, move on to system and program access. Your bookkeeper doesn’t need network admin rights, and your ops person doesn’t need banking access. Spreading access out means one person’s departure doesn’t take down everything at once.
Then, fix your 2FA so it isn’t tied to a personal device. Instead, use a company phone, an authenticator on a company-owned device, or backup codes stored somewhere leadership can reach.
Next, export passwords from personal password managers into a shared, company-controlled system like 1Password or LastPass, where access can be revoked instantly, and there’s an audit trail.
Finally, make sure you write things down. These documents should have enough information for someone else to step in and keep everything moving for a few weeks, such as how key systems work, who to call, and where the login information is stored. Cross-train at least two people on anything truly critical.
And when someone does leave, treat the transition seriously the same day, not the day after: change passwords, pull devices, and do a full systems walkthrough before they’re out the door.
Is It Worth the Effort?
The cost of getting this wrong is a big deal. This cost can include downtime, forensic recovery, legal fees, damaged client trust, and often tens of thousands of dollars before it’s over.
The cost of fixing it is a few hours of your time, a password manager subscription, perhaps a company phone for a couple of key roles. Call it $1,000 to $2,000 total.
That’s much better than possibly losing thousands.
Where This Leaves You
Your business shouldn’t hinge on one person. And no single employee should have the power to lock you out of your own company in an afternoon.
If either of those is true for you right now, start acting today, not after someone walks out angry.
Worried About Your Business Continuity?
We can help you audit your current access and security, identify where you’re relying too heavily on one person, and start making the changes you need to protect your business in the future.
Schedule Your Free Business Continuity Assessment
We’ll review your current configuration, flag the risks, and show you exactly what needs to change.
About Fruitful Enterprises: We help business owners build systems that stay resilient and independent of any single person. Your business should survive personnel changes and be protected against them.
