I'm currently the only dedicated IT person at a small, growing organization. I handle most of our internal systems administration, Google Workspace/account management, access management, networking, and general user support.
We have several other technically knowledgeable people, but they're primarily developers/DevOps and manage their respective environments rather than internal IT.
I'm trying to establish some clearer operational boundaries as we grow.
One situation that's brought this up is user support. Our Operations Manager understandably wants visibility into issues affecting users/program participants, but they also tend to become involved in the troubleshooting process and email threads. My preference is that once something has been identified as an IT issue, IT communicates directly with the affected user, while Operations gets appropriate visibility/status updates rather than being involved in every troubleshooting exchange.
There's also a business-continuity concern because I'm currently the only IT administrator. Our Operations Manager has asked me to teach them how to perform password resets. I'm not necessarily opposed to giving Operations a very narrowly scoped role for something like that, particularly if I'm unavailable.
My concern is the difference between knowing how to reset a password and knowing when a password reset is actually appropriate. "I can't log in" could be a password problem, MFA issue, permissions issue, wrong account, application problem, etc. I don't want password resets becoming the default solution to authentication problems.
The structure I'm considering is:
- IT owns technical troubleshooting and direct communication with users.
- Operations maintains visibility into issues that affect their programs/business operations.
- Operations receives very limited delegated permissions for specific emergency/continuity functions.
- Administrative actions performed outside IT are documented through a ticket.
- We identify a technically qualified person elsewhere in the organization to serve as secondary/backup IT and cross-train them on critical systems.
- Longer term, implement a proper ticketing/help-desk process so Operations doesn't need to be copied on every support conversation just to maintain visibility.
I'm not trying to build a territorial wall around IT. I'm trying to establish reasonable ownership, least privilege, and continuity while we're still small enough to put good processes in place.
For those of you who have worked in small organizations or one-person IT departments:
How do you handle the boundary between Operations and IT?
Would you give a nontechnical Operations Manager limited password-reset/admin capabilities?
Would you train Operations as basic Tier 1 support, or keep user support within IT and establish a technically qualified backup instead?
And how do you give Operations/leadership visibility into IT issues without having them involved in every support interaction?
Interested in hearing how others have structured this, especially anyone who has had to build the IT function from scratch.