Every business we work with has at least one of these. A payroll system only Cheryl can run. An estimating spreadsheet that lives in Marcus’s head as much as on his laptop. A website nobody has logged into since the guy who built it moved to Austin. Ask who else could do it and you get a pause, then “well, I could probably figure it out.”

That pause is the whole article. We call the fix the two-person rule: every system your business genuinely depends on needs a second human being who has actually done the work, not someone who could theoretically learn it. This is not about distrusting anyone. The people who end up as the only path to a system are almost always your best employees, because competence attracts responsibility. It is about the plain fact that one person cannot be available all the time.

Where Single-Person Knowledge Hides

It is rarely the obvious systems. Everybody knows the accounting software matters, so two or three people already touch it. The exposure sits where nobody thinks of it as a system at all.

  • Payroll and benefits. Often one person, often with a login tied to their personal email, and always on an immovable deadline.
  • The estimating or quoting tool. Real software or a spreadsheet holding twenty years of pricing logic, the person who maintains it is usually the only one who understands why the numbers come out the way they do.
  • The website and domain. Hosting, the registrar, the content system, and the certificate that keeps the padlock showing. Four accounts, frequently one person, sometimes a contractor you no longer work with.
  • The phone system. Changing the after-hours greeting or rerouting calls during a storm should not depend on one specific person being reachable.
  • The bank and the card processor. Who can initiate a transfer, approve one, and add a user. If all three are the same person, you have a gap that is both operational and financial.
  • That one integration. The connection that pushes orders into accounting or syncs the field app with dispatch. Nobody built it as a product. Somebody built it as a favor, and it silently runs your day.

Ready.gov’s business continuity plan template asks organizations to “identify the lines of authority, succession of management, and delegation of authority.” Read that as a prompt rather than paperwork. For each item above, who is the second name?

It Is Not Just About Someone Quitting

Resignation gets the attention because it is dramatic. It is also the version you get the most warning about, and often the one where the departing person will happily walk someone through the work on their way out.

The common cases are gentler and far more frequent. Someone takes a week off and payroll falls inside it. Someone gets the flu on a Tuesday. Someone is on a job site with no signal the day a customer needs a quote. None of these are emergencies. They quietly become emergencies when the only person who can do the thing is not there to do it.

There is a second cost that is easy to miss. When one person is the only path to a system, they cannot fully disconnect, and everyone else routes work through them. That is a bottleneck with a human face on it, and it is the friction we described in our post on why saving time matters more than saving money. Cross-training gets sold as risk reduction. It also just makes the week run better.

Cross-Training Is a Calendar Item, Not an Intention

Everyone agrees cross-training is a good idea. Almost nobody does it, because it never beats today’s work. The only version that survives a busy quarter is scheduled, small, and specific.

  1. Pick one system per quarter. Four a year is a serious program. Doing all of them at once is how the effort dies in February.
  2. Name the second person out loud. Not “someone in accounting.” A person, who knows they have been named, and whose manager knows too.
  3. Have them do it, not watch it. Watching a payroll run teaches almost nothing. Running one with the expert beside you teaches the job. Shadowing is not training.
  4. Then have them do it alone, on purpose. Schedule a real cycle where the primary person is deliberately unavailable but reachable if something breaks. Almost everyone skips this step, and it is the only one that proves the training worked.
  5. Put it on the schedule again. Skills fade. A system somebody learned two years ago and has not touched since is not covered anymore.

CISA makes a parallel point about backups in its cyber guidance for small businesses: “It’s not enough to schedule all important systems to have a regular backup. It’s critical to regularly test partial and full restores.” Untested backups and untested backup people fail the same way, for the same reason.

Document While You Cross-Train, Not After

Documentation written after the fact is usually wrong, because the expert writes down what they think they do rather than what they actually do. Documentation written by the trainee, during training, is accurate by construction. The trainee records each step as they perform it, and the expert corrects what is wrong. It produces something a third person could follow.

Keep it short and keep it where people will find it. What the process is for, when it runs, where to log in, the steps in order, what “done correctly” looks like, and the two or three things that commonly go wrong. Ready.gov’s continuity template makes the same point operationally, instructing organizations to “document all forms and resource requirements for all manual workarounds.” The workaround nobody wrote down is the one nobody can execute.

Apply the Same Rule to Access

Training a second person accomplishes nothing if they cannot get in. No account should have exactly one human who can reach it, and the fix is not sharing a password.

  • Give each person their own login. CISA’s cross-sector cybersecurity performance goals call for organizations to “provision unique and separate credentials for similar services and asset access.” Individual accounts also show you who did what.
  • Make sure two people hold administrator rights. One admin is a locked door with one key. Two is a working business. A dozen is a different problem.
  • Move accounts off personal email and phones. Recovery codes and multi-factor prompts tied to one employee’s cell will strand you at the wrong moment.
  • Use a shared password manager where an account truly cannot be split. Some vendor portals support only one login. A managed vault with controlled access beats a sticky note or a spreadsheet.
  • Have a real offboarding step. The same CISA goals describe a defined process applied to departing employees “by the day of their departure that disables all user accounts and access to organizational resources.” It only works if you know every account they held.

Access hygiene is where operational resilience and security stop being separate topics, a theme we covered in our piece on why cybersecurity is no longer optional for mid-sized businesses.

The Bottom Line

Write down the systems your business cannot go a week without. Next to each, write two names. Wherever there is only one, you have found your next quarter’s project. Do one at a time, have the second person actually perform the work while the first watches, let the trainee write the documentation, and make sure both have their own way in. That is the entire program, and it fits in a spreadsheet.

If you want help mapping which systems have a single human behind them, sorting out account access so nobody is the only key holder, and building documentation your team will actually use, that is work we do with clients across Denton County. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).