Who owns what

Technology roles without the title confusion.

The business needs clear decisions, operating ownership and escalation. Job titles alone do not provide any of them.

Reviewed October 10, 2026 · Published by SecureStepPartner

System Administrator

Keeps the daily environment dependable. This is the hands-on owner for identities, devices, updates, backups, routine troubleshooting, technical records and controlled changes. A strong administrator makes the work repeatable, documents exceptions, and escalates risk early. They should not be asked to approve their own privileged access, silently accept major risk, or serve as the only continuity plan for the business.

Managed Service Provider

Supplies contracted operational capacity. That can include help desk, endpoint management, monitoring, Microsoft administration, security operations, projects and vendor coordination. A good MSP brings a documented service model and evidence of what it manages. It does not replace an internal decision-maker for business priorities, access approval, budget, legal obligations, risk acceptance or performance review.

Director of IT

Turns business needs into an operating plan. The role owns service quality, standards, vendors, asset lifecycle, projects, architecture, staffing, budget discipline, resilience and risk reporting. A good director makes tradeoffs visible before they become outages, emergency purchases or failed audit answers.

CIO or CTO

Connects technology direction to operations, revenue and enterprise risk. A CIO commonly emphasizes internal systems, information and operating performance. A CTO commonly emphasizes products, engineering and customer-facing technology. Smaller manufacturers may combine both. The practical test is whether one executive is accountable for the technology strategy and can bring material choices to the leadership team.

HR and IT

Share responsibility for the employee technology lifecycle. HR owns authoritative employment events and workforce policy. IT turns approved events into timely access, equipment and security actions. Both teams need a tested process for hires, moves, leaves, terminations, investigations, training and equipment return.

Operating guidance

What good looks like in each role

Titles vary across manufacturers. The useful question is not who has the most senior title. It is whether the work has a named owner, a realistic rhythm, evidence of completion, and an escalation path when the work cannot be done on time.

System Administrator

Owns the operating details

Keep an accurate inventory of accounts, devices, software, critical services, backups and recurring maintenance. Work from approved standards rather than memory. Record unresolved risks, temporary exceptions and changes that could affect production or recovery.

Healthy weekly rhythm

Review urgent alerts, failed backups, vulnerable or unmanaged devices, privileged access changes, aged tickets and failed automated jobs. Escalate items that have a business effect, not just a technical symptom.

Evidence a CFO can expect

Coverage reports, a current asset list, backup restore results, completed change records, a concise exception log and a plain-language summary of problems that need funding or leadership decisions.

Managed Service Provider

Owns the contracted service

Run the agreed service desk, management tools and escalation process. Maintain documentation, meet response commitments, communicate incidents clearly and produce evidence for the controls it says it manages.

Healthy monthly rhythm

Report ticket trends, device and security coverage, patching, backup status, access exceptions, open risks, planned work and decisions required from the client. Review the unresolved work, not just the completed ticket count.

Boundary to write down

Specify who owns the firewall, network failures, vendor renewals, privileged accounts, onsite response, after-hours incidents, software purchasing, security notifications and the final decision to accept risk.

Director of IT

Owns the system of work

Set standards, approve the operating roadmap, hold providers accountable and make sure individual technology choices support production, quality, finance and customer commitments. The director turns technical issues into prioritized business decisions.

Healthy monthly rhythm

Review service performance, material risks, technology spend, lifecycle commitments, vendor performance, project status, insurance evidence and unresolved audit findings. Make tradeoffs explicit: defer, fund, transfer, mitigate or accept.

Evidence a CFO can expect

A current roadmap, a budget with lifecycle assumptions, a risk register with owners and dates, vendor scorecards, a disaster-recovery test summary and a clear explanation of any gap that could stop operations.

CIO or CTO

Owns direction and executive alignment

Translate business strategy into technology priorities. Decide when a platform, automation, security program or data capability is worth the cost and organizational change. Ensure major risk reaches the right executive rather than remaining a technical backlog item.

Healthy quarterly rhythm

Review technology against company strategy, production and customer needs, regulatory exposure, insurance requirements, talent, concentration risk and investment outcomes. Test whether the organization can continue operating through a serious outage or supplier failure.

Evidence a CFO can expect

A small set of decision-ready measures: service reliability, recovery readiness, security exceptions, major vendor exposure, project value, budget variance and risks that require a leadership choice.

Practitioner consensus

What experienced IT teams repeatedly recommend

Across recent practitioner discussions, the positive pattern is consistent: co-managed IT works when the responsibilities are explicit, the internal team and provider share information freely, and neither side is treated as an informal backup with undefined authority. Teams also describe the HR to IT handoff as a workflow and data-ownership problem, not a reminder problem. That perspective informs the operating guidance below. It is not a legal or industry standard.

A practical division of responsibility

A useful responsibility matrix is more specific than a contract heading. It names the service or decision, the accountable owner, the people who must be consulted, the escalation route and the evidence that proves completion.

Decision or activityPrimary ownerRequired partnersEvidence of completion
Daily administration, tickets and maintenanceSystem Administrator or MSPDirector of IT and system ownersTicket history, monitoring, change records and recurring reports
Security monitoring and incident responseNamed IT or MSP incident ownerDirector of IT, operations and executive sponsorEscalation plan, alert handling, incident record and lessons learned
Technology strategy, major investment and risk escalationCIO, CTO or accountable executiveCFO, operations, legal and Director of ITApproved roadmap, decision record and budget owner
Operating plan, standards, vendors and budgetDirector of ITSystem Administrator, MSP and department leadersStandards, vendor review, risk register and lifecycle plan
Hiring, role changes, leave and termination triggersHRManager and ITApproved HR event with effective time and required data
Access removal, device recovery and evidenceITHR, manager and physical securityIdentity, device, data and asset checklist with exceptions
Accepting significant residual riskBusiness executive with authorityIT documents options and consequencesWritten decision, owner, review date and expiration

How HR and IT should work together

  1. Choose one authoritative trigger. HR records the approved employment event, effective time, manager, department, location and worker type. Informal messages should not be the only source.
  2. Define a usable lead time. HR and managers know when IT needs notice for equipment, accounts, specialized software or site access. A late request is visible as an exception rather than an invisible operating norm.
  3. Translate the role into approved access. The manager states the business need. IT assigns role-based groups and approved equipment rather than copying another employee’s access without review.
  4. Separate safe automation from approval decisions. Account creation, standard groups and equipment tasks can be automated. Privileged access, unusual software, external sharing and exceptions receive documented human approval.
  5. Coordinate sensitive departures. HR owns timing and employee communication. IT prepares access removal, session revocation, equipment and data actions. Legal and security join when preservation or investigation is required.
  6. Prove the end state. A closed ticket is not proof that the process worked. Confirm access, licenses, devices, shared data ownership, equipment return and outstanding exceptions.
  7. Review the workflow. Sample recent hires, transfers and departures. Measure late notices, unresolved access, missing equipment and manual rework, then fix the recurring cause.
Where an MSP fitsThe MSP may perform many IT actions, but the company still needs an internal person who can authorize access, prioritize outages, approve spend, accept risk and hold the provider accountable. For co-managed IT, write the responsibility matrix before an incident, not after one.

Questions for the leadership team

  • Who can approve administrator access, and who independently reviews it?
  • Who owns an incident at 2 a.m., and who may pause a system that affects production?
  • Who tells customers, insurers or regulators when an event may require notice?
  • Which responsibilities belong to the MSP, and which remain with employees and business leaders?
  • What evidence proves onboarding and offboarding actually reached a complete end state?
  • Who reports overdue risk, control exceptions and material vendor issues to the CFO or board?

Use the provider question guide