The short answer
What should the checklist include?
At minimum, document company and site details, IT responsibilities, computers and devices, servers and network equipment, internet and Wi-Fi services, printers, software and subscriptions, user and administrator accounts, vendors, warranties, backups, recovery information, employee onboarding and offboarding, incidents, replacement history, recurring maintenance, and a review schedule.
The goal is not to place every secret in one file. Ordinary documentation should identify the system, account owner, responsible person, and approved secure-vault location without exposing passwords, MFA recovery codes, encryption keys, private keys, or payment information.
Company, site, contact, and responsibility records
Begin with the business context. List the legal or operating name, locations, primary contacts, normal hours, emergency contacts, and any office, warehouse, retail, or remote-work environments that depend on technology. A consultant or MSP should be able to tell which records belong to which site without relying on folder names alone.
Define responsibility as clearly as the equipment. Record who approves purchases, who manages accounts, who contacts vendors, who receives outage notices, and who can authorize urgent changes. Small companies often split these duties among an owner, office manager, outside provider, and one technically experienced employee.
- Company, location, department, primary contact, and emergency contact
- Internal IT owner, outside provider, billing contact, and decision-maker
- Support hours, escalation path, approved communication method, and service boundaries
- Document owner, backup owner, storage location, and last review date
Computers, devices, servers, and shared equipment
Maintain a current inventory of desktops, laptops, servers, tablets, company phones, printers, scanners, storage devices, and other shared technology. Each record should connect the asset to a person or location and show whether it is active, spare, under repair, retired, or awaiting disposal.
Infrastructure records need enough detail to support replacement and troubleshooting. For servers or NAS devices, include the business purpose, operating system, storage role, warranty, support status, backup relationship, and responsible administrator. For printers and shared devices, include location, model, network name or address, supplies, service vendor, and assigned users where useful.
- Asset ID, manufacturer, model, serial number, purchase date, vendor, and warranty
- Assigned user, department, physical location, status, and planned replacement date
- Hostname, operating system, MAC or IP information when operationally useful
- Server role, storage capacity, backup relationship, support contract, and dependency notes
When a laptop fails, a useful record shows who used it, when it was purchased, whether it is still under warranty, which applications were licensed to it, and whether its business files were expected to be in a managed cloud location or backup system.
Network, internet, Wi-Fi, and connectivity information
Network documentation should describe the installed environment in plain language and preserve the technical details needed for support. Include the router, firewall, switches, access points, UPS equipment, racks, patching, internet circuits, public services, and any site-to-site or remote-access connections.
Internet-service records should identify the provider, service address, account or circuit reference, plan, static IP allocation where applicable, support number, billing owner, equipment ownership, and escalation process. Do not put the provider password in the worksheet; point authorized staff to the approved vault entry instead.
- ISP, service address, circuit or account reference, bandwidth, equipment, and support contacts
- Firewall, router, switch, access-point, UPS, rack, patch-panel, and network-room records
- Network names, VLANs, subnets, DHCP ranges, DNS, addressing conventions, and diagrams
- Wi-Fi networks, intended users, authentication method, coverage notes, and guest-network ownership
- VPN or remote-access platform, approved users, support owner, and secure credential location
Software, subscriptions, user accounts, and administrative access
Keep a software and subscription inventory that shows what the company pays for, who owns the relationship, how many licenses are available, which teams use the service, and when it renews. This includes Microsoft 365 or Google Workspace where applicable, line-of-business systems, security tools, backup services, design software, accounting platforms, and cloud subscriptions.
User records should show the account name, business purpose, assigned licenses, access groups, manager or approver, MFA status, and lifecycle status. Administrative access records should identify the authorized account, owner, recovery process, and secure vault location without copying the secret into routine documentation.
- Product, vendor, subscription tier, quantity, renewal date, cost owner, and cancellation process
- User name, email, department, manager, assigned licenses, groups, and account status
- Microsoft 365 or Google Workspace tenant, verified domains, billing owner, and support arrangement
- Administrator role, responsible person, MFA method, emergency-access procedure, and vault reference
- Shared mailboxes, distribution lists, service accounts, integrations, and ownership
Vendors, warranties, and support contracts
Vendor records reduce confusion during an outage or renewal. Document what each provider supplies, who can open a ticket, which account or customer number applies, contract dates, service levels, billing contact, and escalation route. Separate sales contacts from support contacts when they are not the same.
Warranty records should connect back to the asset inventory. Include coverage dates, proof-of-purchase location, warranty type, advance-replacement terms, serial number, and any support entitlement needed before a claim can be opened.
- Provider, service supplied, account number, support portal, phone, email, and escalation contact
- Agreement start, renewal, notice period, service level, covered locations, and billing owner
- Warranty start and expiration, coverage, claim process, proof of purchase, and replacement history
Backups, recovery information, and recurring maintenance
A backup record should say what is protected, where the backup goes, how often it runs, how long copies are kept, who monitors failures, and when restoration was last tested. A green dashboard is not the same as a tested recovery process.
Document recurring maintenance such as operating-system updates, firewall and access-point reviews, backup checks, license renewals, battery replacement, equipment cleaning, storage-capacity review, and account audits. Assign an owner and due date rather than keeping an informal list of good intentions.
- Protected system or data set, backup product, destination, frequency, retention, encryption, and owner
- Monitoring and alert recipient, failure response, restore procedure, test date, and result
- Recovery priority, acceptable downtime, required contacts, replacement equipment, and dependencies
- Maintenance task, cadence, assigned person or provider, last completion, next due date, and evidence
Onboarding, offboarding, incidents, and replacement history
Use repeatable onboarding and offboarding records for accounts, licenses, groups, devices, VPN, MFA, shared resources, and returned equipment. The checklist should show the request, approval, completion, exceptions, and final verification instead of relying on someone to remember every system.
Incident and replacement records provide useful history. Record the affected system, business impact, timeline, actions taken, root cause when known, recovery, follow-up work, and equipment or configuration changes. Keep the final outcome without exposing sensitive forensic data in a broadly available file.
- Start or departure date, manager, role, equipment, accounts, access, approvals, and sign-off
- Incident date, affected service, impact, contacts, response, recovery, and preventive action
- Old asset, new asset, reason for replacement, data handling, license transfer, and disposition
- Exception owner, target date, final verification, and document update
Set a documentation review schedule
Documentation stays useful only when it is maintained. Review fast-changing records such as users, assets, licenses, and subscriptions more often than stable items such as office addresses. Tie updates to real events: purchases, deployments, renewals, incidents, employee changes, and vendor changes.
A quarterly review is a practical starting point for many small businesses, with immediate updates for significant changes. Record the reviewer, date, corrections made, open questions, and next scheduled review so stale information is visible rather than silently trusted.
Quality-control review
Common omissions and mistakes
- Keeping critical network or vendor knowledge only in one employee’s memory
- Listing assets without assigned users, locations, status, warranty, or replacement information
- Recording subscriptions without renewal dates, owners, license counts, or cancellation steps
- Documenting that backups exist without identifying what is protected or testing restoration
- Storing passwords, recovery codes, or private keys in an ordinary shared spreadsheet
- Completing onboarding but never recording offboarding verification or equipment return
- Creating documentation once and leaving no owner or review schedule
Make the process repeatable
Use a consistent documentation system.
Reusable forms give owners, office managers, internal staff, consultants, and MSPs the same fields to update when technology changes. A consistent system reduces missed information and makes handoff, maintenance, outages, and future service less dependent on memory.
View Small Business IT Documentation Pack
Start a conversation