Fixed price · one entity · up to three named users
One engagement. Everything set up, tested, and in your name.
Email, identity, files, devices, passwords, a business number, backup with a restore that actually runs, a secure AI account, working guides, and an evidence pack. One fixed price, one handoff, and then it is yours to run.
The fit check provides a base-package quote from your answers. Final scope, vendor charges, tax, and service terms are confirmed before work begins.
What actually changes
The setup stops depending on whoever built it.
Right now, the answer to “who can get back into this?” is a person. After the handoff it is a documented procedure with a named owner, recovery material in your own vault, and a second way in that has been tested rather than assumed.
The same applies to leaving. Removing someone becomes a checklist instead of an archaeology exercise, because every account was named and inventoried on the way in.
The point is not more software. It is a small, owned system with a tested way back in.
One bounded setup
The working foundation, organized as one handoff.
The exact products depend on the approved customer-owned path. The outcome stays consistent.
The interactive map needs JavaScript. The complete text outline is available below.
Read the complete map as text
Startup Digital Foundation
- 01 · Customer ownership
- What this layer does
- Purpose: the business controls the identities, services, billing relationships, and recovery decisions that matter.
- Named identities
- Setup: one to three named users, MFA, role boundaries, and a tested break-glass path.
- Proof: owner and recovery custodian recorded.
- Domain and workspace
- Setup: one client-owned domain and one Microsoft 365 or Google Workspace tenant.
- Proof: administrative custody read back with the founder.
- Business phone
- Setup: one client-selected Canadian number assigned to one named user or account.
- Proof: assignment and non-emergency test recorded.
- AI account and API key
- Setup: one client-owned provider account and one project-scoped key, with billing and usage protections where available.
- Proof: custody, safe storage, and revocation steps handed over.
- What this layer does
- 02 · Working system
- What this layer does
- Purpose: the small operating layer people use every day is organized, supported, and understandable.
- Communication
- Setup: business email, calendar, meetings, and the assigned business number.
- Proof: sender and calling paths checked.
- Files and work
- Setup: one document home, a simple work view, and a usable SOP index.
- Proof: location and ownership inventory delivered.
- Devices and passwords
- Setup: a supported baseline for up to three business devices and a client-controlled team vault.
- Proof: device and administrator records delivered.
- One low-risk automation
- Setup: a bounded workflow with an owner, manual fallback, error path, and disable step.
- Proof: fallback and disable step exercised.
- What this layer does
- 03 · Recovery + handoff
- What this layer does
- Purpose: the founder receives evidence, guidance, and a practical way back in without depending on the provider.
- Backup and restore
- Setup: a client-owned backup path and one agreed item restored and recorded.
- Proof: bounded restore receipt delivered.
- Evidence
- Setup: states, owners, and read-back evidence distinguish verified work from open work.
- Proof: evidence matrix reviewed with the founder.
- Guides and inventories
- Setup: quick-start guidance, administrator guidance, and current ownership inventories.
- Proof: operator read-back completed.
- Closeout
- Setup: provider access is transferred or removed, while residual risks remain visible for acceptance.
- Proof: access closeout and remaining risks recorded.
- What this layer does
This shows the delivery relationship between the layers. It is not a network architecture diagram or a promise that every vendor supports the same controls.
Proof before claims
Every important control gets a state, an owner, and evidence.
Open items remain open. A bounded restore is described as a bounded restore. The evidence pack is for founder review—not a certification or an insurance opinion.
Read the acceptance baseline| Control | State | Evidence | Owner |
|---|---|---|---|
| Named human accounts | Verified | Read-back identity inventory | Founder |
| Sample file recovery | Verified | Bounded restore receipt | Recovery owner |
| Legacy sender ownership | Open | Founder decision required | Founder |
| Private network access | Not applicable | No defined private resource | N/A |
Each row says what was checked, what supports the state, and who owns the next decision.
A narrow offer on purpose
One entity. One primary workspace. Up to three people.
Multiple tenants, regulated or high-consequence data, large migrations, 24/7 support, and an ongoing MSP relationship need a different engagement.
The last test
Can the founder run it unaided?
Ownership, recovery custody, administrator guidance, and a clean access closeout are part of the result—not follow-up paperwork.
- Customer owner
- Named founder or delegated administrator Recorded
- Recovery custody
- Placed directly in customer-controlled custody Transferred
- Administrator access
- Customer access confirmed; provider access closed out Read back
- Evidence pack
- Inventories, control states, and bounded restore receipt Delivered
- Residual risk
- Open decisions, dependencies, and accepted exceptions Visible
Closeout is complete only when ownership, recovery, evidence, and unresolved decisions are legible to the customer.