ONTRACBusiness Solutions FZE

Free resource · Documentation & handover

What Your IT Provider Should Hand Over

Everything you should already have, whether or not you ever plan to leave. Ask for it while everyone is still friendly — that is the entire trick.

This is the list we hand over ourselves. We are publishing it because it is the fastest way to explain how we work, and because a business that holds this list is harder to hold hostage — by us or by anyone else.

Most IT providers do not withhold things maliciously. They just never write anything down, and the knowledge lives in one person's head until that person leaves. The result is the same either way: on the day you want to change something, you cannot.

Ask for this while the relationship is good. A provider who is happy to hand it over is telling you something. A provider who stalls is telling you something more important, and you have learned it at no cost.

1Accounts and ownership — the part that actually matters

  • Your domain name registered to your company, with a registrar login someone in your building holds
  • Your Microsoft 365 or Google tenant in your company's name, on your payment method — not your provider's tenant with you inside it
  • At least one Global Administrator account that you control
  • Cloud hosting and backup accounts in your name
  • Carrier and telecoms accounts, including SIM and trunk contracts, in your name
  • Software licences registered to your company, with the renewal dates
  • Your website hosting and DNS control
  • A list of every third party with access to your systems, and what they can reach
If any of these sit in your provider's name, changing provider means rebuilding rather than transferring. That is not a technical problem, it is a commercial one, and it is entirely avoidable.

2Network documentation

  • A topology diagram that matches what is actually installed today
  • IP addressing scheme and VLAN plan
  • Internet connections: carrier, account number, speed, static IPs
  • Firewall rules with a reason recorded for each
  • Wifi network names, and where the access points physically are
  • Patch panel and port labelling that corresponds to reality
  • Where the comms cabinets are, and how to get into them

3The asset register

  • Every server, firewall, switch, access point, phone system and NAS: make, model, serial number
  • Where each one physically is
  • Warranty and support expiry dates
  • Firmware or software versions
  • Which supplier it came from and when
  • Laptops and desktops, with who has which one
  • What is approaching end of support, so it is a plan and not a surprise

4Credentials, handled properly

  • An inventory of what credentials exist and who holds them — even where the passwords themselves are held in a vault
  • Administrator accounts for every system, in a password manager you control
  • A break-glass account, documented, stored safely, tested once
  • Credentials handed over securely — never in the body of an email
  • Named accounts per person rather than shared logins, so actions are attributable
  • A process for rotating anything when someone leaves, on either side
  • Encryption keys and recovery codes, and where they live

5Configuration and backups of the systems themselves

  • Configuration backups for firewall, switches, phone system and access points, held by you
  • Server build documentation, or at least what runs where and why
  • The backup configuration: what is protected, how often, kept how long
  • Date of the last successful restore test
  • Any scripts or automations, and what breaks if they stop
  • Licence keys for anything that would need reinstalling

6How things are supposed to work

  • What to do when the internet fails, in plain language
  • How to add a new starter and how to remove a leaver
  • How to reset a password out of hours
  • Who to call, for what, and what is in scope of your contract
  • Response times you have actually been promised, in writing
  • What is charged extra, and what is included
  • Known issues and workarounds — the things everyone tolerates but nobody wrote down

7The exit clause nobody reads

  • Notice period, and what triggers automatic renewal
  • What is handed over on exit, listed explicitly in the contract
  • Whether handover is chargeable, and at what rate
  • How long they will support a transition to someone else
  • What happens to your data held on their systems, and when it is deleted
  • Whether any equipment is theirs rather than yours, and what happens to it
  • Whether any licences are on their agreement rather than yours
Read this clause on the day you sign, not on the day you are unhappy. If exit terms are missing, ask for them to be added — the answer to that request is itself informative.

8How to ask without starting a fight

None of this needs to be adversarial, and framing matters.

  • Ask as continuity planning, not as an audit: "if you were unavailable for a fortnight, what would we need?"
  • Ask for it in stages rather than as a single demand
  • Offer to store it somewhere you both can reach
  • Accept that some of it will take them time to produce — that is normal and not a red flag on its own
  • Set a reasonable date and follow it up once
  • Review it annually, because it goes stale within months
A good provider will be pleased you asked. It means fewer 2am calls that only they can answer, and it is the difference between a business relationship and a dependency.

9The ones that catch people

The domain in the provider's name. The single most common one, and the most disruptive. Your email and your website both hang off it.

The tenant you do not own. Discovered when you try to leave, and the answer is a migration you did not budget for.

The one person who knows. No documentation, no malice, and then they change jobs.

Diagrams from three years ago. Worse than none, because people trust them.

Licences on the provider's agreement. They stop working the month you leave.

Equipment that turns out to be rented. Removed on the last day, along with your firewall.

Why we publish this

Every design we deliver is documented and transferable. If you move on, you leave with everything — diagrams, configurations, credentials, accounts in your own name. We would rather earn next year than trap you into it.

That is not generosity. A customer who could leave easily and chooses to stay is a better business than one who cannot leave at all.

Want the printable version?

Leave an email and the checklist arrives in your inbox straight away. No newsletter, no drip campaign. You can also just print this page and take it into the meeting.

If you ask your current provider for this and the response worries you, reply and tell us what happened. We will tell you whether it is genuinely a problem or just a busy month — including when the honest answer is that they are fine.