
Operating Cadence
Part of Startup risk and access controls
Identifying single-person dependencies in a young company
Find work that depends on one person's knowledge, access or authority, and check whether a proposed cover could act.
A single-person dependency exists when essential work would stop because only one person knows how to do it, can access what it needs or has authority to decide the next step. Find these dependencies by tracing real work and asking what a colleague could do if that person were unavailable. A backup name alone does not establish cover.
Trace work that cannot wait
Choose a few current activities whose delay would matter, such as customer delivery, payroll preparation, a critical system change or an incident response. Follow a recent case from its trigger to its result. At each step, ask who knew what to do, held the information, had access and could approve an exception.
Look for less obvious gaps. A procedure may exist while one founder alone knows which version is current. Two people may have account access while only one can recover it. A deputy may be able to prepare a payment but lack authority to release it.
| Work at risk | Sole point today | What stops | Proposed cover | Gap to resolve |
|---|---|---|---|---|
| A named activity or decision | Knowledge, access or authority held by one person | The specific operating or customer effect | A person or temporary route | Missing instruction, permission, approval or capacity |
Treat the proposed cover as unverified until someone checks whether it works.
Decide which concentration matters
Specialist knowledge is common in a young company. The question is whether an absence would prevent the team from protecting a current commitment. Ask how long the work can wait and what an interim response could achieve. A strategic choice may wait for a founder; an urgent customer or security issue may need a route available sooner.
Do not solve every gap by granting broad access. Cover for a task needs the relevant instructions and permissions, plus a limit on decisions. For a powerful account, consider authorised recovery or a controlled alternative administrator instead of sharing an everyday password. The options depend on the service.
Key risks and mitigation strategies for single-person dependencies
- Risk: Sole knowledge holder absent
- Work halts; no alternative path exists
- Mitigation: Document current procedures
- Ensure version control and accessible records
- Risk: Shared access without recovery ability
- Account lockout possible if primary user unavailable
- Mitigation: Set up authorised recovery options
- Use multi-factor recovery or controlled admin accounts
- Risk: Deputy lacks decision-making authority
- Delays occur even with correct information
- Mitigation: Define clear approval limits
- Grant authority to act within predefined boundaries
Check the proposed cover
Ask the proposed cover to show where they would find the current record, how they would start, where they would stop and whom they would contact for a decision. Where suitable, let them handle a low-risk case under the owner's supervision. Record any point where they must guess.
For example, if only a founder handles changes to agreed delivery dates, a colleague might gather the current promise and available slot, then seek approval from the authorised person. Covering the first steps need not give that colleague authority to change customer terms.
Prioritise the fixes
Act sooner when the work has a near deadline, the consequence is material and no safe interim route exists. A fix may be a short instruction, a trained deputy, an approval alternative or a change in scheduling.
Give it an owner and check it on the next suitable case or role change. The result should show what would stop and what the team can actually do next.



