What is key person risk?

Key person risk arises when essential knowledge or access depends on one person. Reduce it with documented procedures, authorised backup operators and rehearsed recovery. A missed check-in does not verify that a founder has died or become incapacitated.

A delayed message can provide a useful backstop, but it should not be the only route to urgent operational access.

Find the dependencies before choosing software

List who can deploy, restore backups, administer domains, manage billing and handle urgent support. For each job, name a second authorised person and test the documented procedure. Keep business accounts under organisational ownership where possible.

Use role-based access and your organisation’s approved password manager or secret-management system. Avoid bundling root credentials and all recovery factors into a single message.

Use ZeroLatch for a short operational note

Write who to call, where the runbooks and approved recovery records are, and what to do first. Use one set of instructions for each trusted person. Active deliveries in one account share the check-in schedule.

Choose a check-in interval and extra waiting time that fit the purpose. ZeroLatch sends access after that schedule is missed; it does not verify a real-world emergency or guarantee business continuity. Keep an independent copy and rehearse with synthetic information. See an example.