Learn

Playbook

The Founder-Led IT Playbook: Running Provisioning, SaaS Spend and Security From One Login

The Founder-Led IT Playbook: Running Provisioning, SaaS Spend and Security From One Login

The Founder-Led IT Playbook: Running Provisioning, SaaS Spend and Security From One Login

Three surfaces decide whether a company with no IT hire stays in control: access, SaaS spend and security. How to run all three from one login.

Three surfaces decide whether a company with no IT hire stays in control: access, SaaS spend and security. How to run all three from one login.

Julien Monguillot

Julien Monguillot

Julien Monguillot

Co-Founder

Co-Founder

Co-Founder

Created:

Created:

Created:

Learn

Three surfaces decide whether a company without an IT hire stays in control: who has access, what the software costs, and what happens when something goes wrong. Running all three from a single login is possible today because Google Workspace admin controls, SaaS management platforms and identity tools have converged into purpose-built products. A founder or ops lead can now handle employee onboarding, track software spend and enforce basic security policy from one dashboard, in roughly the time it used to take to file an IT ticket. This matters because small companies without full-time IT staff never had the option before. The tools built for that gap are what this playbook covers.

TL;DR

  • The three surfaces that matter are access, SaaS spend and security. Running them from one login replaces four separate tools and a spreadsheet.

  • Manual onboarding costs real money, in administrative hours per hire and in the lost time before a new starter is productive.

  • Unused and duplicated SaaS licenses waste a meaningful share of what small and mid-sized companies spend on software each year.

  • Security compliance frameworks like SOC 2, ISO 27001 and GDPR all require the same underlying discipline: role-based access, least privilege and regular access reviews.

  • ShiftControl was built by operators who ran IT at ExpressVPN, and it bundles provisioning, spend visibility, permission auditing and incident response into one Google Workspace login.

About the Author: This article is written by the ShiftControl team, founded by Dan Gericke and Julien Monguillot, who ran IT and global SaaS operations at ExpressVPN. ShiftControl supports founder-led and IT-less companies with a platform purpose-built for Google Workspace.

What Does “Founder-Led IT” Actually Mean?

Founder-led IT means the person running access, security and software spend decisions is a founder, COO or ops lead rather than a dedicated IT department. It doesn’t mean doing IT badly or ignoring it. It means the systems have to be simple enough for a generalist to operate correctly without specialized training.

This playbook is about the consolidation itself: what it takes to run those three surfaces (access, spend and security) from one login, and where the seams are. If you’re earlier than that and still working out whether the operator role is yours to own at all, the companion piece on the COO as the IT department covers that question directly.

This is now the default reality for most small companies. Many small businesses rely on managed service providers for at least part of their IT needs, but MSPs are usually reactive: you call them when something breaks, not when you’re deciding how to structure Google Workspace groups for a new sales team. The gap between having an MSP on retainer and having someone who owns IT operations day to day is where founder-led IT operates.

The shift toward founder-led operations isn’t unique to IT. It mirrors a broader trend in how small SaaS-driven companies operate lean, where a single person or small team handles functions that used to require entire departments. IT is simply the latest function to get that treatment, helped along by tools that consolidate what used to require four separate logins.

Why Does Manual Provisioning Cost So Much More Than It Looks Like?

Manual provisioning looks cheap because it doesn’t show up as a line item. It shows up as lost hours and delayed productivity instead. Manual onboarding requires significant administrative effort per new hire, and it delays a new employee reaching full productivity. Count the time spent creating accounts, assigning app access, setting permissions and chasing whatever was missed. That time is the cost.

Offboarding carries a different but equally real risk. An employee who leaves and keeps access to Slack, a CRM or shared drives for even a few days is a live security gap, not a paperwork problem. This is one of the reasons user provisioning software exists as its own category: it removes the manual step where access revocation gets forgotten.

Here’s the mechanism worth understanding: provisioning software works by syncing your HR system (who’s an employee, what team, what role) with your identity and app layer (who has access to what). When someone’s status changes in the HRIS, that change propagates automatically. Think of it like a thermostat instead of manually adjusting a furnace: you set the rule once (“engineering hires land in the right groups with the right apps on day one”), and it runs every time the trigger fires, without anyone remembering to flip a switch.

ShiftControl’s Smart Provisioning connects to HRIS platforms including HiBob, BambooHR, Omni HR, Deel, Dream Team and Gusto, and syncs with Google Workspace to grant or revoke access based on role, department, location or group. Apps that support SCIM provision automatically; the steps that still need a person arrive as a guided task list for the app owner, rather than a checklist you have to remember. Dynamic group management extends this further: when someone changes teams, their access changes with them, without a manual ticket.

How Much SaaS Spend Is Actually Being Wasted?

SaaS spend waste is a bigger line item than most founders realize, because software spend rarely gets audited the way payroll or rent does. Small and mid-sized companies invest heavily in software, and a meaningful share of that spend goes to licenses nobody uses, barely uses or bought twice.

This happens for a structural reason, not because anyone is careless. Software gets purchased by whoever needs it at the time, a marketing tool here, a design tool there, while nobody owns the job of reviewing what’s still being used six months later. Without a centralized view, a company can be paying for three project management tools because three different teams each picked their own and nobody noticed the overlap.

Worth looking for in a SaaS spend dashboard:

  • Spend broken down by team, individual and application

  • Renewal dates with advance alerts, so contracts don’t auto-renew unnoticed

  • Which licenses are actively used versus dormant

  • Total cost trends over time, not just a single snapshot

ShiftControl’s SaaS spend dashboard shows cost by department, tool and employee, alongside contract renewal dates, once your app cost data is in.

What Does “Security” Actually Require for a Small Company?

Security for a small company requires the same fundamentals that larger enterprises follow, just implemented at a smaller scale. The compliance frameworks make this explicit. SOC 2 requires strict logical access controls and regular user access reviews. ISO 27001 mandates a formal access control policy built on least privilege. GDPR requires technical measures like role-based access and multi-factor authentication to protect personal data. None of these frameworks assume you have a security team of ten. They assume you have controls, documented and enforced consistently.

Google Workspace SSO and MFA enforcement handle a large part of this. But a less obvious risk sits in third-party app permissions. Unmanaged third-party apps connected to Google Workspace introduce risk through excessive OAuth scopes, unvetted shadow IT and abandoned integrations that keep active access to company data long after anyone remembers granting it. A marketing app that requested full Gmail access two years ago and was never revisited is a standing liability, and it is easy to lose track of how many of those exist.

The stakes are also asymmetric in a way that surprises a lot of founders: ransomware doesn’t discriminate by company size. Small companies are, if anything, more exposed, because they can least afford the downtime or the payout.

This is why a cyber incident response plan shouldn’t be treated as something you write after a breach. ShiftControl includes IR-1, delivered through a partnership with Blackpanda, an incident response and digital forensics firm, as part of the subscription rather than a paid add-on. It covers 24/7 access to incident responders, one annual incident response credit for the full organization, ransomware negotiation support, containment, initial investigation and Attack Surface Management scans.

Can One Platform Really Replace Four Separate Tools?

One platform can replace four separate tools when those tools are solving connected problems: provisioning and access, SaaS spend management, app-permission visibility and incident response. These four jobs are usually handled by different vendors, which means the data about who has access to what lives in four different places and nobody has the full picture.

ShiftControl consolidates these into a single Google Workspace login, purpose-built for Google Workspace. Setup can take as little as 10 minutes: sign in with a Google Workspace admin account, authorize Workspace, then set up your org: locations, departments, teams and the apps you use most. You need Workspace admin rights; you do not need IT expertise, and there is no implementation project.

Gene Yu, CEO of Blackpanda, described the effect on onboarding directly: “Onboarding a new employee was seamless. ShiftControl made it feel like we had the same capabilities as a large enterprise, without the complexity.”

For teams evaluating identity and SaaS management platforms like Okta, BetterCloud or Rippling’s IT product, the distinguishing factor is depth: ShiftControl was designed for Google Workspace specifically, rather than treating it as one integration among many.

One thing it deliberately does not do: ShiftControl does not ship its own password manager.

Frequently Asked Questions

Do we still need to hire someone for IT?

For the core functions (giving people access, managing it, tracking SaaS spend and having incident response in place), ShiftControl is built so a founder, COO or ops lead can run them without a dedicated IT hire. You do need Google Workspace admin rights.

Is ShiftControl’s security offering actually compliant with recognized standards?

ShiftControl is SOC 2 Type 2 compliant and ISO 27001 certified, and signed the CISA Secure by Design Pledge in 2024. These frameworks require documented access controls and regular reviews, which ShiftControl’s automated provisioning and audit trails are built to support.

How does Google Workspace automation reduce onboarding time?

By syncing your HRIS with Google Workspace groups and app permissions, so that account creation, app access and group assignment happen automatically when someone joins, changes roles or leaves, instead of requiring manual setup for each step.

What is included in ShiftControl’s incident response coverage?

IR-1, delivered via Blackpanda, includes 24/7 access to incident responders, one annual incident response credit covering the full organization, ransomware negotiation support, containment, investigation and Attack Surface Management scans, all included in the subscription.

How is ShiftControl priced compared to enterprise identity platforms?

ShiftControl publishes standard per-user pricing along with a separate, discounted startup tier for early-stage companies. The standard rate is $10 per user per month with everything included, and the startup discount is 80% off your first 10 seats for the first year.

Does ShiftControl handle identity and devices?

ShiftControl works with your existing Google Workspace identity, and device management is available through the ShiftControl for JumpCloud add-on. Native device management beyond that add-on is on the roadmap, not available today.

Does ShiftControl work if we’re not using Google Workspace as our primary platform?

ShiftControl is purpose-built for Google Workspace specifically, with deep native integration. Companies primarily on other productivity platforms would not get the same depth of functionality.

About ShiftControl

ShiftControl is an IT operations and SaaS management platform purpose-built for Google Workspace, designed for small and growing businesses without a dedicated IT team. It combines automated provisioning and de-provisioning, SaaS spend management, third-party app permission visibility and included cyber incident response into a single platform, set up in as little as 10 minutes through one Google Workspace login. It was founded by Dan Gericke and Julien Monguillot, former ExpressVPN operators, on the principle that security fundamentals shouldn’t be locked behind expensive tiers.

If you are running provisioning, SaaS spend, permissions and incident response across separate tools and spreadsheets, it is worth seeing what running all four from one login looks like. Book a live demo, or start a 14-day free trial with no credit card required.

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.

Company

Your privacy choices

© 2026 Shift Control Pte. Ltd. All rights reserved.

Company

Your privacy choices

© 2026 Shift Control Pte. Ltd. All rights reserved.

Company

Your privacy choices

© 2026 Shift Control Pte. Ltd. All rights reserved.