Blog · 20 September 2026
The Technology Plan Still Has No Owner
This quarter the owner already knows the plan is split. Spend, vendors, approved tools, and licences need one owner before the next pair of reports disagree.
Why no one holds the plan today
The technology plan is already a live decision, not a later project. Vendors keep the systems they sold. Internal staff keep the logins they use. Finance keeps the invoices that arrive. None of those people own the plan that should bind them together. The owner feels the gap when a renewal, a hire, or a failed sign-in lands in the same week.
A split plan looks cheap because no one is paid to hold it. It becomes expensive when three people each wait for someone else to decide. The managed service vendor waits for a signature. The office manager waits for a clear list of what to cancel. Finance waits for a number that matches last month. Work stalls in the space between those inboxes.
This quarter usually exposes the split. A tool appears that no one requested. A licence remains on a person who left. Two exports of the same roster do not match. Those events are not random. They are what a plan without an owner produces on a normal calendar.
Ownership is not the same job as fixing a laptop. The owner of the plan decides what stays, what goes, and who may approve a new tool. The technician still repairs the device. The vendor still runs the platform it was hired to run. The plan owner writes the rules those people follow, then checks that the rules still match the company.
Leave the plan split and every later choice inherits the split. Vendor keep-or-cut talks start from memory. Licence counts start from a spreadsheet that is already stale. Approved tool lists start from whatever people already installed. The company then spends the next quarter arguing about facts that should have been written down.
Who can own it without becoming the technician
The owner, the chief operating officer, or a trusted office manager can own the plan. The job is judgment, not remote control of every setting. That person must have the authority to say no to a new subscription. They must also have the authority to keep a vendor that still earns its place. Without that authority, the title is decoration.
Do not assign ownership to a committee by default. A committee can review. A committee rarely answers a vendor on a Tuesday afternoon. Pick one person who will keep the written plan, the vendor list, and the approved tool list. Name a backup only after the first owner is real. A backup with no primary is another form of no one.
The plan owner does not need to be the most technical person at the company. They need to know whom to ask, and they need to write the answer down. They should be able to explain spend, vendors, tools, and licences to the rest of leadership in plain words. If they cannot do that without a translator, the company still does not have an owner.
Watch for a false owner. A false owner forwards every question to the vendor and calls that management. Another false owner collects screenshots and never decides. A third false owner is the founder who still signs every renewal while claiming the office will handle it. None of those patterns produce a plan other people can use.
If the company already pays for outside technology leadership, treat that person as counsel to the owner of the plan, not as a replacement for ownership. Internal authority still has to sit with someone on the payroll or the board of the company. Outside help can draft, review, and report. It cannot be the only memory the company has. Readers who want a fuller view of that leadership role can use the fractional CIO page as further reading.
Write the name of the owner in a place leadership already opens. A buried file is not ownership. A line in the leadership notes is a start. Repeat the name when a vendor asks who decides. If the vendor cannot get a single name, the plan is still split, no matter how many slides exist.
How spend hides in plain sight
Technology spend rarely lives on one invoice. It lives on the company card, a personal card, a vendor portal, and a payroll add-on that looks like a benefit. Finance sees pieces. The office manager sees other pieces. The vendor sees only what it bills. No one sees the set, so no one can say what the company is actually buying.
Personal cards are a common leak. A staff member buys a tool to finish a job, then leaves. The card remains. The tool remains. The data remains in an account the company does not control. That is not a small exception. It is a second purchasing path with no owner.
Annual renewals hide as well. A quiet email lands in a mailbox that no one watches. The vendor auto-renews. Months later, finance asks why the charge grew. The plan owner should keep a calendar of renewals that matter, with a named person who must review each one before it bills again. A calendar is not administration of a tenant. It is control of money and intent.
Unused seats are another quiet drain. People change roles. People leave. The licence stays because cancellation was never assigned. Ask for a roster of paid licences next to a roster of active people. Where they diverge, someone must decide to cut, reassign, or keep that licence on purpose. Keeping a licence on purpose is allowed. Keeping it by accident is not a plan.
Do not chase a perfect total on the first pass. Chase a complete list of vendors and products, even if the amounts are rough. Completeness beats precision when the list itself is still unknown. Once the list exists, finance can attach real invoices. Until the list exists, every total is a guess dressed as a report.
Ask finance for every recurring technology charge from the last full year. Ask the office manager for every tool people actually open. Ask the vendor for every product on the contract. Those three lists should be the same set. When they are not, the difference is the hidden spend, and that difference needs an owner.
Which vendors still earn their place
A vendor earns its place when it does a defined job, answers a named person, and can be replaced without folklore. Many vendors fail that test and still remain because no one owns the cut. The plan owner should be able to say, in one paragraph, what each vendor is for. If that paragraph cannot be written, the vendor is a habit.
Ask what happens when the primary contact is out. If the answer is a personal mobile number and a hope, the company does not have a vendor. It has a person. That may be fine for a tiny specialist job. It is not fine for mail, files, identity, or the line of business system that holds customers.
Ask who holds admin rights, and in whose name those rights exist. Rights in a personal email address are a risk the company already accepted without writing it down. Rights concentrated on one staff member who never takes leave are the same risk with a different face. The plan owner does not need to click the admin portal all day. They do need to know that more than one controlled account can act.
Ask how the vendor reports. A useful report names what changed, what failed, and what will renew. A weak report restates that everything is fine. If two vendors each claim they own backup, identity, or the website, the overlap is a dispute waiting for an outage. Resolve the overlap in writing before the outage writes it for you.
Keep a vendor that still fits even if a newer brochure looks nicer. Cutting for novelty is not ownership. Keeping a vendor that cannot name its own scope is not loyalty. The test is fit to the written plan. Fit can include a long relationship. It cannot include a relationship no one can explain to a new office manager.
When a vendor should go, name the successor and the data handoff before you name the end date. People skip that order and then discover that files, domains, or phone numbers sit in an account they cannot enter. The plan owner should treat exit as part of the original keep-or-cut choice, not as a later surprise.
How to decide which tools are allowed
Unapproved AI tools and personal AI accounts show up when the company has no written rule. Staff are not trying to cause harm. They are trying to finish work with whatever is already on a phone. The plan owner has to say which tools are allowed on company data, and which are not. Silence is a policy. It is just an accidental one.
Write the rule in the language staff already use. Name the systems that hold customer files, payroll, health information, or donor records. Say those systems may not be copied into a personal AI account. Say who may request a new tool, and who may approve it. A rule that needs a lawyer to decode will not be followed on a busy afternoon.
Approval should be a short path, not a performance. If a new tool takes months to review, people will use a personal account and never ask. If a new tool is approved by a hallway conversation, the company will not know what it allowed. Pick one intake, one owner, and a decision that is written where others can find it.
Unapproved AI tools create a second copy of work the company cannot inventory. The copy may include names, contracts, or grant drafts. When a funder, an auditor, or a customer asks where the data went, “somewhere on a personal account” is not an answer. The plan owner should assume that question will arrive, and write the answer before it does.
Do not confuse a vendor feature inside a paid platform with a personal account on the side. A feature the company already licenses can still be out of bounds if it shares the wrong library of files. Permission and licence are different problems. Both belong in the same plan, because staff experience them as one question: may I use this.
A written rule also protects the people who refuse a shortcut. Without a rule, the careful employee looks slow, and the careless one looks effective. With a rule, both are measured against the same line. That is management, not theater. Further reading on putting that rule on paper sits on the AI use policy page.
When licences no longer match the roster
Licences drift as soon as hiring and exits move faster than the person who buys seats. A new hire waits for access while a former hire still has a paid account. Shared logins hide the true count. Guest accounts linger after a project ends. The plan owner should treat the roster and the licence list as one document that must agree.
Ask for a user list from the identity system, not from memory. Ask for a licence list from the billing portal, not from the last proposal. Sit those lists next to the payroll roster or the volunteer roster, depending on how the company works. Every name that appears in only one list is a decision. Keep, remove, or explain.
Shared passwords make the lists lie. If four people enter one mailbox, the licence count looks tidy and the audit trail is useless. The plan owner should forbid shared sign-in for anything that holds company records. That is not a technical preference. It is how you know which person did which thing when a report is wrong.
Products with extra add-ons drift faster than base licences. A feature gets turned on for a trial. The trial becomes a line item. No one remembers who asked for it. Before the next renewal, list every add-on and name the person who still needs it. If no one will put their name on it, it is a candidate to drop.
Microsoft 365 is a common place for this drift because mail, files, and extra features sit in one bill. The bill can be right and the people can still be wrong. A licensing review is further reading when the roster and the bill refuse to match. The plan owner still has to decide what “match” means for this company.
Do not wait for a fiscal year close to face the mismatch. Exits happen every month. So do role changes. A short monthly check by the plan owner, using lists other people produce, is enough to catch the obvious cases. The plan owner is not doing day-to-day administration of the tenant. They are confirming that spend still follows living people.
Why two reports cannot both be true
Two reports disagree when they are built from different clocks, different filters, or different owners. Finance reports what was billed. The vendor reports what was provisioned. The office reports what people used. Those are not the same fact. They only look like the same fact when no one owns the definitions.
Start with the question the report is supposed to answer. If the question is “who has a paid licence,” billing is the source. If the question is “who can open the file share,” the identity system is the source. If the question is “who actually worked last week,” the line of business system may be the source. Mixing those questions in one grid is how a meeting becomes an argument.
Exports lie in small ways. One export includes guests. Another drops disabled accounts. One uses the date a record was created. Another uses the date it was last opened. The plan owner should require a one-line definition under every important report. That line names the source, the date field, and who is excluded. Without that line, the report is a picture, not evidence.
Staff then spend days reconciling by hand. They know the data exists. They do not trust any single view of it. Grant reports, board packs, and customer statements all suffer the same way. A related picture of reporting under a thin team is in the nonprofit case study, offered here as further reading rather than a model to copy.
When reports disagree, do not average them. Pick a system of record for each kind of fact, write it down, and make the other reports explain themselves against it. Identity facts belong in identity. Money facts belong in finance. Outcome facts belong in the system that records the work. The plan owner is the person who refuses to treat three sources as one number.
A Tuesday version of this fight is familiar. Morning brings a usage report that says a product is idle. Afternoon brings a staff complaint that the same product is essential. Evening brings an invoice that matches neither story. Ownership is the act of staying with that contradiction until one story is true.
What a Tuesday looks like without an owner
Morning starts with a sign-in failure. The technician who answers is not sure whether the licence was pulled, the password expired, or a former admin changed a rule. The office manager searches email for the last vendor note. The owner is in a customer meeting and will see the thread at noon. No one is wrong. No one is in charge of the path.
Midday brings a renewal notice with a reply deadline that has already passed. The notice sat in a mailbox that belongs to a person on leave. Auto-renewal will take it unless someone acts. Finance will see the charge later and ask why. The plan without an owner turns a calendar event into a scavenger hunt.
Afternoon brings a request for a new tool. A manager saw a demo. Staff want it before a deadline. There is no intake, so the request arrives as a chat message. Someone says yes because the work is real. Someone else says no because the data is sensitive. Both people believe they own the answer. The tool gets used anyway on a personal AI account.
Late afternoon brings two spreadsheets that should match and do not. One came from the vendor. One came from finance. A third person built a third copy to “just get through the meeting.” The meeting then spends its time on which copy to trust. The decision the meeting needed never happens.
End of day brings a quiet risk. Admin rights still sit with a contractor whose project ended. A domain login still uses a personal email address. A backup notice was marked read and not understood. None of these need a crisis to be true. They need only a plan that no one owns.
The next Tuesday repeats the pattern with different names. Ownership is what breaks the pattern. It does not make the events stop. It makes the events land on a person who already has the lists, the vendor names, and the authority to decide.
What to check before the next renewal
Check the identity of the plan owner in writing. If that sentence does not exist, stop and write it. Every later check fails if it has nowhere to return. Name the backup only after the primary name is real and known to vendors.
Check the vendor list against the invoice list. Add anything that bills and is missing from the vendor list. Add anything on the vendor list that has not billed, and ask why. A vendor that does not bill may still hold data. A bill without a vendor name is a tool with no owner.
Check admin accounts. Confirm they use company identities, not personal mail. Confirm more than one controlled person can act. Confirm former staff and former vendors cannot. This is a design check, not daily administration. Record the result so the next check has a baseline.
Check the licence roster against living people. Mark seats to remove, seats to reassign, and seats to keep on purpose. Give those marks to the person who actually changes licences. Then confirm the change in the next billing view. Intent without confirmation is how drift returns.
Check the approved tool list against what people open. Ask managers what their teams used this month to finish work. Compare that list to the written approvals. Every extra name is either a candidate for approval or a candidate for removal. Pretending not to see it is how personal AI accounts become normal.
Check the reports leadership already uses. For each one, write the source, the date field, and the owner. If two reports answer the same question from different sources, pick one system of record. Tell the other report to reconcile or to stop claiming the same fact.
Check renewals that will bill in the coming quarter. Assign a person and a date for each. The date must sit before the vendor’s silent renewal. Put the dates on a calendar the plan owner actually opens. A private reminder in one head is not a control.
Questions that belong in the vendor call
Ask who the vendor believes owns the relationship at your company. If they name three people, you have already learned something. Give them one name and make them use it. A vendor that cannot route a decision will route around you.
Ask what they hold that you would lose if the contract ended next quarter. Listen for domains, DNS, archives, phone numbers, encryption keys, and admin identities. If they cannot list those holdings, they do not understand their own scope. If they can list them, write the list into the plan so an exit is possible.
Ask how they will report changes, failures, and renewals to the plan owner. Monthly silence is not a report. A stack of alerts with no summary is not a report either. You want a short record that a non-technician can read and keep.
Ask who on their side can speak to spend, not only to tickets. The person who resets a password is not always the person who can explain a licence change. You need both, and you need to know which inbox is which. If your own technician is the one who talks to them daily, include that technician in the call so stories do not fork.
Ask what they will refuse to do. A vendor that claims every job is not a partner in a plan. It is a source of overlap. Overlap with another vendor is how two parties each think the other owns a control. Get the refusal in ordinary language and keep it.
Ask how they handle unapproved tools they can see. Some platforms can show personal accounts or shadow applications. Some cannot. Either answer is useful. If they can see them, agree who reviews that list. If they cannot, the plan owner must gather that list from staff some other way.
Ask what they need from you to keep the licence roster honest. Then give them a current people list on a schedule you can keep. Vendors drift when the company never sends a clean roster. That drift will be billed back to you as seats you no longer mean to buy.
How staff and vendors share the same silence
Staff stop reporting tools when reporting has no effect. They ask once, wait, and then use a personal account. Vendors stop escalating when every alert lands in a void. Both silences look like peace. Both are the plan decaying in private.
The plan owner should make asking cheaper than hiding. A short intake that gets an answer in a known time will collect more truth than a stern memo. People will still take shortcuts under a deadline. They will take fewer if the official path is real.
Vendors need a single place to send a renewal, a risk, and a request for a decision. If those three things go to three mailboxes, the vendor will pick the person who replies fastest. Fast is not the same as authorized. Over time the unofficial contact becomes the real owner, and the written owner becomes a name on a slide.
Internal staff and vendors also duplicate work when no one owns definitions. Each builds a tracker. Each tracker is almost right. Meetings then compare trackers instead of deciding. Collapse the trackers. One vendor list, one licence view, one approved tool list, each with a date and an owner.
Do not punish the person who admits they used an unapproved AI tool last month. You need that admission to complete the inventory. Punishment trains the next person to hide. Fix the path, record the tool, and decide. Discipline belongs to willful handling of restricted data after the rule is clear, not to the first honest list.
Silence also lives in the board pack. Leadership asks how technology is doing. Three people send three paragraphs that do not refer to each other. The plan owner should be the one who answers, using the written lists. If that answer cannot be given without a week of collection, the lists are not yet in use.
Where the written plan should live
The plan is a short packet, not a slogan. It names the owner, the vendors, the approved tools, the licence rules, and the system of record for each important report. It fits in a place leadership already opens. If it needs a hunt, it will not be used when a renewal arrives.
Keep it where access is controlled and history is kept. A personal drive is a second copy of the old problem. A vendor’s portal is fine for vendor data, but it is not your plan. Your plan has to outlast a single vendor. It also has to be readable by a successor who was not in the last meeting.
Date every list. An undated roster is a rumor. When two dated lists disagree, you can at least see which one is newer. When neither is dated, people argue from memory and the louder memory wins. Dating is a reporting habit, and it is one the plan owner can demand without touching daily administration.
Share the minimum that staff need. They need the approved tool list and the name of the person who can approve a new one. They do not need every contract. Vendors need the owner’s name and the renewal calendar. Finance needs the vendor list and the licence marks. Over-sharing creates noise. Under-sharing recreates the split.
Review the packet when people change, not only when a budget cycle says so. A new office manager with no packet will invent a new system by Friday. A departing manager with no handoff will take the only complete picture with them. Ownership includes the handoff. If the packet cannot be handed off, it was never a plan.
Do not wait for a perfect document. A one-page owner name, vendor list, and tool rule beats a long draft that never leaves a notebook. Add licence matching and report definitions as soon as the first page is in use. Completeness comes from use, not from delay.
What changes once one person owns it
The first change is speed on small decisions. A renewal has a name. A new tool has a path. A mismatched report has a system of record. None of that requires a new platform. It requires a person who will answer, and lists that person will keep.
The second change is cleaner spend without a hunt. Finance still pays. The plan owner still does not become an accounts clerk. They do become the person who can say which charge is intended. Intended charges stay. Unintended charges get a named action. The argument moves from “what is this” to “did we decide this.”
The third change is a calmer vendor relationship. Vendors prefer a single owner even when they will not say so. They stop guessing. They stop finding the fastest inbox. They start sending the renewal to the person who can actually decide. Your own technician can then stay on repair work instead of becoming an unofficial broker.
The fourth change is honesty about unapproved AI tools. Once a rule exists and intake is short, the hidden list can surface. Some tools will be approved and brought under a company account. Some will be barred from company data. The important part is that the company knows which is which before a customer or a funder asks.
The fifth change is a Tuesday that still has problems, but not mysteries. Sign-in failures still happen. Exports still need checks. People still leave. The difference is that each event has a list to consult and a person to close it. That is what ownership looks like when it is working. It is ordinary. It is also the thing the company has been missing.
None of this requires the plan owner to run tickets, devices, or daily tenant clicks. Design the rules. Remediate the obvious mismatches. Migrate holdings that sit in the wrong account. Report the lists on a rhythm leadership will actually read. Leave administration to the people whose job it is.
If leadership wants a deeper question set after the lists exist, the FAQ is further reading on how those questions are commonly framed. Use it as a prompt for your own notes, not as a substitute for naming an owner inside the company.
A plan with an owner will still be incomplete. Completeness is not the test. The test is whether a COO or an office manager can act on Tuesday without translating a vendor’s language into a decision. If they can name the owner, the spend, the vendors, the allowed tools, and the licence match, the company has started. If they cannot, the quarter will spend itself on the same split you already feel.
Third Shift Group LLC publishes notes like this so owners can assign that ownership on purpose, with the lists in one place, before the next pair of reports disagree.
More from the blog
Your turn next
Start with a written assessment.
Every engagement on this site opened with a written assessment of what the company already ran. The assessment is yours to keep either way.