RIPEDA Consulting
OperationsIdentityStrategy

What breaks first when a firm hits 20 people

The founder-does-IT model works at eight people and quietly stops working at twenty, usually without anyone deciding to change it.

By RIPEDA··3 min read

At eight people, one of the founders is the IT department and it works fine. Someone needs a laptop, they order a laptop. Someone is locked out, they walk over. At twenty the same arrangement is still in place, and it has quietly stopped working.

The sections below are roughly the order firms hit them in. None of it is urgent until it is all urgent at once, which is the part that makes it hard to plan for.

The founder-does-IT model stops scaling

The work is now interrupt-driven. It arrives during billable hours, from people who are blocked, and it lands on whoever is most senior and least replaceable. Twenty people generate enough small requests that someone is doing an hour or two of IT a day without ever calling it that. The cost is not the hour itself, it is that the hour comes out of client work and never appears on an invoice.

Identity and access stop being auditable

The informal model is to add people to things as they need them: a shared drive, the accounting system, the client portal, a Slack workspace, and a handful of SaaS tools someone expensed. At eight people, one person holds the whole map in their head. At twenty nobody does, and “who has access to the client folder” cannot be answered without opening six admin consoles and guessing. Access has become unauditable rather than merely untidy, and the difference matters the first time someone asks in writing.

Nobody can say what the firm owns or who has it

Ask a twenty-person firm to list every Mac it owns, who currently holds it, and whether FileVault is on. The honest answer is usually a spreadsheet that stopped being accurate a year ago. Machines bought on personal cards, machines bought before the firm had a card, and one or two that left with contractors and never came back. Without Apple Business Manager and an MDM there is no authoritative list, only recollection, and recollection fails at exactly the wrong moment: an insurance claim, a departure that goes badly, a laptop left in an airport.

Onboarding and offboarding stop being events

At eight people a new hire happens twice a year and someone improvises. At twenty, hiring is continuous enough that improvising costs the better part of a day per person and still misses something. Offboarding is worse because the failures are silent: an account left active, a license still billing monthly, a device nobody chased. Both need to become a written checklist rather than a memory, and that transition is the actual work.

The first client security questionnaire arrives

Somewhere around this size a client sends a security questionnaire, or an insurer asks about multi-factor authentication and endpoint encryption. The document wants to know whether devices are encrypted and centrally managed, how access is reviewed, and who holds administrative rights. Answering it honestly produces either a clean set of answers or a delay while things get fixed under time pressure. That is the point where the gap stops being an internal annoyance and starts affecting whether the work gets signed.

If you only do one thing

Build an accurate device list and write down the offboarding steps. Those two documents cost nothing, and they make every other item on this list solvable rather than theoretical.

Found this useful? Share it.

LinkedInPostEmail

Thinking through this for your business?

RIPEDA helps Apple-first organizations make these decisions every day.

Get in touch