What you get

A working setup, its recovery path, and the instructions to own it.

The package is designed around an operational handoff. Product names may change; ownership and acceptance boundaries do not.

Foundation system mapOne owned system, not a pile of tools.Explore the three branches. Each setup item opens to show what is configured and what evidence is handed over.

The interactive map needs JavaScript. The complete text outline is available below.

Read the complete map as text

Startup Digital Foundation

  • 01 · Customer ownership
    • What this layer does
      • Purpose: the business controls the identities, services, billing relationships, and recovery decisions that matter.
    • Named identities
      • Setup: one to three named users, MFA, role boundaries, and a tested break-glass path.
      • Proof: owner and recovery custodian recorded.
    • Domain and workspace
      • Setup: one client-owned domain and one Microsoft 365 or Google Workspace tenant.
      • Proof: administrative custody read back with the founder.
    • Business phone
      • Setup: one client-selected Canadian number assigned to one named user or account.
      • Proof: assignment and non-emergency test recorded.
    • AI account and API key
      • Setup: one client-owned provider account and one project-scoped key, with billing and usage protections where available.
      • Proof: custody, safe storage, and revocation steps handed over.
  • 02 · Working system
    • What this layer does
      • Purpose: the small operating layer people use every day is organized, supported, and understandable.
    • Communication
      • Setup: business email, calendar, meetings, and the assigned business number.
      • Proof: sender and calling paths checked.
    • Files and work
      • Setup: one document home, a simple work view, and a usable SOP index.
      • Proof: location and ownership inventory delivered.
    • Devices and passwords
      • Setup: a supported baseline for up to three business devices and a client-controlled team vault.
      • Proof: device and administrator records delivered.
    • One low-risk automation
      • Setup: a bounded workflow with an owner, manual fallback, error path, and disable step.
      • Proof: fallback and disable step exercised.
  • 03 · Recovery + handoff
    • What this layer does
      • Purpose: the founder receives evidence, guidance, and a practical way back in without depending on the provider.
    • Backup and restore
      • Setup: a client-owned backup path and one agreed item restored and recorded.
      • Proof: bounded restore receipt delivered.
    • Evidence
      • Setup: states, owners, and read-back evidence distinguish verified work from open work.
      • Proof: evidence matrix reviewed with the founder.
    • Guides and inventories
      • Setup: quick-start guidance, administrator guidance, and current ownership inventories.
      • Proof: operator read-back completed.
    • Closeout
      • Setup: provider access is transferred or removed, while residual risks remain visible for acceptance.
      • Proof: access closeout and remaining risks recorded.

This shows the delivery relationship between the layers. It is not a network architecture diagram or a promise that every vendor supports the same controls.

Delivered together

The system and the explanation.

Inventories
Users, administrators, devices, domains, vendors, data owners, and recovery owners.
Working guides
Employee quick-start, administrator notes, onboarding, offboarding, outage, and account-loss steps.
Evidence
A control matrix that separates verified, not applicable, open, and blocked items.
Recovery receipt
A record of one agreed restore path, including exactly what that test did and did not prove.

Customer owned

Subscriptions and renewals do not disappear inside a bundle.

The customer owns the domain, tenants, administrative identities, data, telephone number, AI provider account and credentials, billing relationships, and renewal choices. Vendor costs are separate and require approval before any purchase or activation.

The fit check separates the fixed setup quote from vendor subscriptions, calling plans, usage, renewals, and taxes so those costs remain visible.

Synthetic specimenHandoff passport / reference environment
Customer owner
Named founder or delegated administrator
Recorded
Recovery custody
Placed directly in customer-controlled custody
Transferred
Administrator access
Customer access confirmed; provider access closed out
Read back
Evidence pack
Inventories, control states, and bounded restore receipt
Delivered
Residual risk
Open decisions, dependencies, and accepted exceptions
Visible

Closeout is complete only when ownership, recovery, evidence, and unresolved decisions are legible to the customer.

Optional services by request

See what can be added after a short scope review.

Add-ons are not included in the automatic quote. Request any that look useful and the boundary is confirmed in a written custom quote.

Foundation and operations

Additional named phone user + number

For another named user: available Canadian number selection, suite-native assignment, voicemail, emergency-address validation, a non-emergency call test, and handoff.

Available by requestCustom quote after review

Additional supported business device

Enroll and verify another supported device against the accepted security and update baseline. Hardware, repair, data rescue, and vendor licensing stay separate.

Available by requestCustom quote after review

Additional supported SSO application

Connect another supported SaaS application to the primary tenant, test sign-in and recovery, and add the result to the administrator guidance.

Available by requestCustom quote after review

Additional suite-native workflow

Add one bounded renewal or obligation reminder using the agreed template, with a named owner, manual fallback, error path, and disable step.

Available by requestCustom quote after review

Additional bounded restore exercise

Exercise another agreed restore path and add a precise recovery receipt. This does not turn a sample restore into full disaster-recovery validation.

Available by requestCustom quote after review

Questionnaire evidence mapping

Map technical questions to verified evidence with a founder review round. Final answers stay founder-approved; this is not a legal, compliance, or insurance opinion.

Available by requestCustom quote after review

AI account and adoption

Additional AI provider account + API key

Set up another supported provider in a client-owned account, apply billing and usage protections where available, create one project-scoped key, run a non-sensitive test, and document handoff and revocation.

Available by requestCustom quote after review

AI workspace user onboarding

Invite named users, confirm access and MFA, provide a short safe-use orientation, and test sign-in. Provider seat and usage charges stay separate.

Available by requestCustom quote after review

Prompt starter pack

Prepare five reviewed prompts for one ordinary business workflow, using non-sensitive examples and a human-review checklist. Automation and sensitive-data workflows need a separate scope.

Available by requestCustom quote after review

Vendor subscriptions, calling plans, usage, hardware, taxes, unsupported products, migrations, repairs, and anything beyond these limits remain separate. Add-ons never change or delay the automatic base-package quote. You can pay for the base package separately and request a written quote for any selected add-ons.

Start with the boundary

Four answers lead to the right quote path.

A standard fit gets the fixed base-package quote. Anything outside that boundary prepares a custom request you review before sending.

Check fit and quote