Transfer operational ownership

Ownership is the ability to make decisions and act on them. Your business should be able to administer a workflow, authorise changes and recover from an interruption without depending on a departing consultant’s personal account. Make that transfer explicit, with clear responsibilities and enough evidence to distinguish control from simple access.

01 Separate responsibility from access

A manager may be accountable for the business outcome without holding administrator permissions. A technical maintainer may edit the workflow without being authorised to change the underlying business rule. Naming these responsibilities prevents routine repairs from turning into unapproved process changes.

Process owner
Defines the intended outcome, approves business-rule changes and decides whether the workflow remains appropriate.
Operational lead
Checks exceptions, coordinates manual work and follows the agreed interruption procedure.
Technical maintainer
Investigates faults, maintains configuration and records approved technical changes.
Access administrator
Manages identities and permissions, including removal of access that is no longer justified.

One person may hold several roles in a small business. Keep the distinctions in the record anyway, and nominate cover. Without a backup, an otherwise well-documented workflow can become unmanageable during leave or staff turnover.

02 Put accounts under business control

Microsoft Entra ID is Microsoft’s identity and access management service. It illustrates the difference between a person’s sign-in and the organisation’s control of permissions. Confirm who can administer the relevant environment and how the business regains access if an administrator leaves.

Google Admin console is used to manage a Google Workspace organisation. A document visible in Google Drive is not necessarily controlled in the way the business expects. Check ownership and sharing arrangements for handover material, particularly when it was first created by an external account.

GitHub organisations provide a shared structure for repositories and permissions. Where workflow code is maintained there, establish business-controlled ownership and review collaborator access. Having a downloaded copy is useful, but it does not replace access to the active repository and its change history.

03 Give permissions a defined purpose

Use the least access necessary for the task. Someone who checks an exception queue does not automatically need permission to alter connections or delete records. Describe the purpose of elevated permissions and how they are granted, reviewed and withdrawn.

Bitwarden is a password-management product associated with storing and sharing credentials through controlled vault arrangements. Such a tool can support business access practices, but a vault entry alone does not explain who owns an account or how a connected service authenticates. Keep identity records and operational instructions distinct from secret values.

The National Cyber Security Centre provides UK guidance on organisational cyber security. Its general guidance is a useful reference point for authentication and access practices. For a particular environment, obtain suitable technical advice rather than assuming that a generic checklist resolves every security risk.

04 Complete the transfer in a safe order

  1. Inventory control points. Include the workflow platform, connected services, hosting, repositories and documentation.
  2. Confirm business administrators. Check that authorised staff can reach the relevant settings and recovery routes.
  3. Review connection identities. Identify any dependency on a consultant’s account before removing that account.
  4. Test authorised operation. Use an agreed harmless test to confirm that the business-controlled arrangement works.
  5. Remove unnecessary access. Revoke temporary permissions and address credentials that were shared during delivery.
  6. Record what remains. Document any retained support access, its purpose and the conditions for withdrawal.

Abruptly disabling an account can break a working connection. Leaving it indefinitely can create unnecessary exposure. Plan the transfer with a competent administrator so the access change and the continuity check happen together.

05 Define the boundary of ongoing support

Distinguish a completed handover from a support arrangement. Record which faults staff handle, when external help is needed and who can approve that help. Avoid relying on informal promises that leave response expectations or access rights unclear.

Keep commercial ownership questions separate from technical access. Confirm through the relevant agreement what the business may use, modify and retain, including custom scripts and documentation. This is general information, not legal advice; a qualified adviser should review contractual uncertainty.

Finish with a practical exercise: can the operational lead find the pause procedure, can the maintainer find the current configuration, and can the administrator review access? Those checks reveal whether responsibility is backed by usable control.