Learn

Guide

The IT Conversation Every Founder Avoids Until It's Too Late

The IT Conversation Every Founder Avoids Until It's Too Late

The IT Conversation Every Founder Avoids Until It's Too Late

The IT conversation every founder avoids: what good enough access management actually costs a growing Google Workspace company.

The IT conversation every founder avoids: what good enough access management actually costs a growing Google Workspace company.

Julien Monguillot

Julien Monguillot

Julien Monguillot

Co-Founder

Co-Founder

Co-Founder

Created:

Created:

Created:

Learn

Most founders don’t skip access management because they’re careless. They skip it because the company feels small, the team feels trusted, and the problem feels like something to address once the business is bigger. That reasoning is rational. It is also the reason the early-growth window is when access hygiene drifts the fastest and costs the most to unwind later.

This article is about the psychology of that delay: why founders make the deferral decision, what specifically makes the early-growth period the highest-drift window, and what the actual trigger for change tends to be. The mechanics of what broken access management costs, and what a purpose-built fix looks like, are covered in depth in our COO-as-IT-department guide and SaaS management plain-English guide.

TL;DR

  • Founders defer access management not from ignorance but from a rational-feeling belief that small teams and mutual trust make formal controls unnecessary.

  • Hiring speed and SaaS proliferation make early growth the highest-drift window, not a safe period to wait out.

  • The moment a company feels too small to need IT governance is often exactly when informal habits become structurally embedded and hardest to reverse.

  • The trigger for change is almost always an incident, an audit, or a financial surprise -- none of which are good times to start from scratch.

  • Fixing this for a Google Workspace company does not require an IT hire or an implementation project.

About the Author: ShiftControl was founded by operators who personally scaled IT from 100 to over 700 employees across 7 global offices at ExpressVPN. The platform is purpose-built for Google Workspace, and ShiftControl works with small and growing businesses that need enterprise-grade IT operations without the overhead.

The Reasoning That Keeps Founders Stuck

The mental model most founders use goes something like this: “We trust our team, everyone knows each other, and access problems are what happen at bigger companies.”

This is not irrational. At five people, access management is genuinely low-friction. Accounts are few, everyone is visible, and a quick conversation handles most of it. The problem is that the reasoning doesn’t update as the company scales. The founder still feels like they’re running a small trusted team, even after they’ve hired their fifteenth person, connected a dozen SaaS tools, and brought in contractors who needed temporary access to systems nobody tracked.

The feeling of smallness persists longer than the reality of smallness. By the time a founder recognizes the gap, informal access habits are already load-bearing. Changing them requires unwinding decisions that were never documented, auditing apps that were never approved, and offboarding accounts that were never properly created.

Why Early Growth Is the Highest-Drift Window

Two forces accelerate access drift during the early-growth period specifically, and they compound each other.

Hiring speed outpaces process. When you’re onboarding quickly, access gets granted informally. A new hire asks a colleague for credentials. A manager shares their own login to unblock someone for the afternoon. A contractor gets access that was never scoped or time-limited. None of this is malicious. All of it creates access that accumulates rather than expires. Permissions pile up because the process for removing them either doesn’t exist or depends on someone remembering to act.

SaaS proliferation happens faster than anyone tracks it. Teams adopt tools independently because the tools are cheap, the signup friction is low, and asking IT (which doesn’t exist) takes too long. Each new tool is a new set of OAuth permissions, a new subscription line, and a new potential stale account waiting to be forgotten. By the time a founder tries to get a clear picture of what’s running, the inventory is already larger and messier than expected.

The intersection of these two forces is what makes early growth specifically risky, not just early-stage. A five-person company with no process has few enough accounts to manage manually. A thirty-person company with no process has too many to manage manually and not enough structured oversight to know it.

The result is a company that feels like it’s running fine because nothing has visibly broken, while access drift compounds quietly in the background. The security and financial mechanics of what that costs are detailed in our MFA-is-not-enough article and the SaaS management guide.

The Inflection Points Founders Miss

There are three moments when access drift accelerates and informal habits become structurally embedded. Most founders don’t recognize them as IT inflection points in real time.

Moment

What founders think is happening

What is actually happening

First 10 hires

“We’re small, everyone knows each other”

Informal access habits become the default pattern

First team leads / department heads

“Each team manages its own tools”

Shadow IT and decentralized SaaS spend begin compounding

First departures

“We handled it, no issues”

Offboarding checklists replace systematic deprovisioning; gaps open

Each of these feels manageable in isolation. Together, they describe a company that has built its access layer on informal foundations that grow harder to replace with each subsequent hire.

Why the Trigger Is Almost Always Reactive

Founders who have addressed access management seriously almost never describe doing it proactively. The trigger is usually one of three things: a security incident or near-miss, an audit or compliance review that surfaces gaps, or a financial surprise when someone finally adds up what the company is paying for SaaS subscriptions it can’t fully account for.

None of these are good starting points. Each one means addressing the problem under pressure, with incomplete information, and often with the additional cost of whatever the trigger event itself caused.

The counterargument founders make is that proactive investment in IT governance feels like overhead at a stage when every dollar and hour matters. That’s a fair framing of the tradeoff. What’s less fair is the assumption that the overhead is large. For a company on Google Workspace, getting provisioning and access, SaaS spend management, app-permission visibility, and incident response onto a single platform does not require an IT hire, a multi-tool stack, or an implementation project. Setup takes about 10 minutes via a single Google Workspace login.

What Functional Looks Like, Without an IT Team

The goal is not to build an IT department. It is to stop making decisions that will be expensive to unwind.

Concretely, that means replacing four informal habits with four managed jobs:

Job

What “good enough” looks like

What functional looks like

Provisioning and access

Manual checklists, shared credentials

Automated provisioning tied to a consistent process

SaaS spend management

Distributed, untracked across expense reports

Central view with renewal alerts and license tracking

App-permission visibility

Unknown, unreviewed

Shadow IT discovery and OAuth scope review

Incident response

Reactive, no plan

Included response capability from day one

ShiftControl handles all four in one platform, purpose-built for Google Workspace, with cyber incident response (IR-1, via Blackpanda) included in the subscription. The platform is made for operators, not IT professionals, and does not require a dedicated IT function to run.

The right time to have this conversation is before the next hire, not after the next incident. The setup cost is lower than most founders expect. The cost of waiting is higher than it looks while it’s accumulating.

Ready to see what you’re actually managing? Visit shiftcontrol.io to explore the platform, run a live demo without logging in, or start a free trial with no commitment required.

References

  1. The First-Time Founder’s Guide to Learning Everything the Hard Way

  2. Startup Founder Survival Guide - by David Politis

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.