The missing operational layer

A will can identify beneficiaries and appoint an executor, but it rarely explains how the production domain renews, who can approve payroll or where the cloud recovery factors are held. A technical runbook cannot create legal authority. Founders need both layers to agree.

Do not place changing passwords, seed phrases or recovery codes directly in a document that may be copied, shared or filed with a court. Let the legal document identify the authorised role and the maintained runbook identify the current systems and approved access paths.

Copy this executor instruction structure

Purpose and scope: company, assets and events covered.

Authority: executor, board contact, lawyer and any limits on access.

First calls: co-founder, finance lead, technical responder, insurer and key advisers.

Critical services: domain registrar, DNS, cloud, source control, email, identity provider, billing, banking, payroll, backups and customer support.

For each service: business owner, normal administrators, provider recovery route, location of separately held factors, renewal date and the safe action order.

Do not do: list destructive actions, privacy boundaries and systems that require professional advice.

After access: rotate credentials, preserve logs, document approvals and review customer or regulatory notification duties.

Connect the template to a tested access path

Prefer provider-native delegation and business-owned accounts. Keep offline recovery factors in an appropriate physical or professional custody arrangement. A ZeroLatch delivery can hold a delayed copy of the runbook and selected encrypted files for one intended recipient.

Simple access allows authorised assisted recovery. Private access depends on a separately stored code ZeroLatch does not keep. Neither option grants the executor authority. Test the process with synthetic accounts, then have legal and technical advisers review the real plan.

Review events

Review after a director, administrator, bank, insurer, cloud provider, password manager or authentication method changes. Also review at least annually. Date every page and identify the authoritative copy so an executor does not follow an obsolete runbook.

The test is simple: can an authorised backup explain the first hour, first day and first week without asking the unavailable founder? If not, the template is still a draft.