Notes
IT team of one, holding identity, endpoints, cloud and compliance
The job title says one thing. The actual remit is identity, endpoints, network, cloud, backups, the helpdesk queue, procurement, whatever compliance somebody has promised a customer, and the printer. There is no rota, no second pair of eyes, and no escalation path that does not terminate in your own inbox.
These notes are about that job. Not the version in a job description, the version where three things are broken, one of them matters, and nobody senior can tell you which.
What an it team of one is actually short of
Not knowledge. The information is all published, and a competent person can learn any individual thing here in an afternoon.
Attention. Everything arrives at the same person, so the constraint is which of forty legitimate demands gets the next hour. That is a triage problem, and triage without a model is just responding to whoever asked most recently.
Independence. Several things genuinely require somebody who is not you. An internal audit. A second opinion on an architecture you designed. Approving your own privileged access. These are structural rather than solvable by effort, and pretending otherwise produces controls that exist on paper.
Slack. No capacity to absorb a bad week, which is why the recurring activities are the first casualty and why the annual controls lapse first.
The two failure modes
Solo IT functions fail in one of two directions and both are avoidable.
Everything is urgent, so nothing is improved. The queue is served, the fires are fought, and the structural work that would reduce the queue never starts. Two years later the estate is the same estate with more of it.
A project consumes everything. A certification, a migration, a platform rebuild. It gets done, and the eighteen months of deferred maintenance behind it becomes its own crisis.
The way out of both is the same and unglamorous: automate the recurring, refuse some things explicitly rather than by silence, and buy independence where the constraint is structural rather than a matter of hours.
What actually reduces the load
Three things, in order of return.
Automating anything that recurs and has a compliance consequence. Joiner, mover and leaver. Evidence collection. Access reviews. These are the tasks where being inconsistent is expensive and where a script is strictly better than a checklist, which is the automation argument.
Making the recurring things visible. A calendar with owners beats intention. Most lapsed controls were not decided against, they were never scheduled.
Writing down the three things somebody else would need. Not everything. Three: how to get emergency access, how to run the leaver process, and who to call. That is the difference between being unavailable and being a single point of failure.
Reading order
Priorities first, because it is the framework the other two sit inside. Documentation second. The consultant note last, and it is deliberately honest about when bringing somebody in does not help, which is most of the time.
The book is the long version of the compliance half of this job, written from doing it alone for a company of about forty people.