Research

The cost of one person

Key-person dependency across 312 systems in forty firms.

Forty-three per cent had exactly one operator. Most organisations did not know.

Talk about a handover

The finding

Across 312 systems in 40 firms, 134 — 43% — had exactly one person who could operate them. In 116 of those the organisation either did not know, suspected without confirming, or knew and had no plan. What separated the systems that were fixed from those that were not was a single act: somebody who had not built the system successfully operating it from the documentation. Where that happened, 84% had a second capable operator six months later. Where documentation was merely written, 23% did.

LengthEight exhibits, full method and appendices
Basis312 systems, 40 firms
AccessFree, in full

What is in it

The argument, in full.

Not a preview. What the study looked at, what it found, and what separated the outcomes.

Three hundred and twelve systems across forty firms of 30 to 600 people were inventoried between March 2024 and May 2026, across professional services, healthcare, software and financial services, to answer a question every firm interviewed agreed was a real risk and none could actually quantify: how many of our systems does exactly one person know how to run? A system entered the count when its loss for a week would be noticed by somebody outside the team running it. Capability itself was defined strictly — able to operate the system routinely, make a change to it, and recover it after a failure, all three required, not simply holding login credentials.

That distinction did most of the work. By access alone, most systems in the study looked adequately covered; by the stricter test, 134 of the 312 — 43% — had exactly one person who could actually run them, more than double the median estimate the sponsoring organisations gave of their own systems beforehand. Fifty-two systems had a second person with full credentials who, when asked directly, said they could not recover the system after a failure. Of the 134 single-operator systems, management was entirely unaware of 42 and had suspected but never confirmed a further 33 — meaning most of this risk was invisible to the organisations carrying it, not merely unmanaged.

Discovery mattered as much as existence. Only 22 of the 134 dependencies were found by somebody deliberately looking; the other 112 surfaced through a resignation, an internal audit, an incident, or an absence — each a moment when the organisation learned about the gap at the same time it had to deal with the consequence. The cost of that timing was stark: systems found through a planned inventory took a median of six working days to reach a second capable operator; systems found during an incident took seventy-one. Twenty-four dependencies surfaced specifically during due diligence for a sale, where eleven appeared directly in the buyer's report and at least four were cited in a price adjustment.

Concentration wasn't random. Bespoke internal tools had a single operator 79% of the time and data pipelines 71%, against 21% for core platform services and 29% for customer-facing applications — the inverse of visibility, since the systems everyone can see tend to have teams around them, while the ones built by one person because it was faster than asking are the ones nobody else can run. Risk registers, built around business criticality, largely missed this: of the 42 systems the organisation didn't know about at all, 31 sat in the three most concentrated categories.

The report's central operational finding concerns what actually fixes a dependency once found: writing documentation alone produced a second capable operator six months later in only 23% of cases, while having someone who hadn't built the system attempt a real task from that documentation — and correcting it where they got stuck — produced one in 84% of cases. The cheapest version tested, a single unassisted afternoon where a stranger attempted one real task while the original operator wasn't consulted, succeeded in nine of eleven cases. The report is explicit that this conclusion runs toward a service it sells, and states the countervailing finding — that the cheap version works nearly as well as the expensive one — as the reason to trust it anyway.

The exhibits

Eight charts, all in the PDF.

01

Systems by number of capable operators

02

Single-operator systems by prior awareness

03

How the dependency was discovered

04

Median working days to a second capable operator

05

Share of systems with a single operator, by kind

06

Share undocumented, by operator tenure on the system

07

All systems by runbook status

08

Share with a second capable operator at six months, by intervention

Method

How the finding was reached.

Period March 2024 to May 2026
Population 312 systems across 40 firms of 30 to 600 people
Sectors Professional services, healthcare, software, financial services
Basis Systems inventory conducted on site, plus 88 interviews with named operators and their managers
Selection Not random. Firms that commissioned an inventory or a handover engagement. Plausibly more aware of the risk than average, which would understate the finding.
Unit One system. A platform with three independently operable components counts as three.
Capable operator Can operate routinely, make a change, and recover from failure. All three required.
Follow-up Six months after the inventory, for the 134 single-operator systems.

Limits

What this does not show.

Written before the analysis was run. Afterwards, limits come out shaped to protect what was found.

THE FIRMS ASKED FOR AN INVENTORY

Every firm here commissioned an inventory or a handover engagement. They are plausibly more aware of this risk than average, which means 43% is more likely to understate the population figure than overstate it. It also means these are firms willing to spend money looking, and those may differ in other ways we did not measure.

CAPABILITY WAS ASSESSED, NOT TESTED

For most systems we established capability through interview and access records rather than by asking a second person to actually perform a recovery. Where we did test — the fifteen executed runbooks — the assessed figure proved optimistic. The true concentration is probably worse than 43%.

SIX MONTHS IS SHORT

The follow-up window is six months. Interventions that work slowly are undercounted, and documentation may look better at eighteen months than it does here. We doubt it, and we cannot show it.

THE INTERVENTION COMPARISON IS NOT RANDOMISED

Firms chose their own interventions. Those choosing to have a stranger execute a runbook may be more serious about the problem in ways that also drive the outcome. The gap is large — 84% against 23% — and a gap that large is unlikely to be entirely selection, but some of it will be.

WE SELL HANDOVER WORK

This report concludes that a specific service we offer is effective. That is a conflict and it is disclosed. The countervailing finding is in section 09: the cheapest version, one unassisted afternoon, produced nine successes in eleven cases and requires nobody to be paid.

The download

Download the full report.

The full report — eight exhibits, the complete method, and every appendix.

Five fields, and the file.

The finding, the method and the limits are on this page. The form is for the complete document.

It arrives in your browser on the next screen, not by email. We ask about your sector because it tells us which sectors read which report, and that is a finding in itself.

Verification widget mounts here.

Questions

Before you read further.

Do I have to give an email to read it?

No — the finding, the method, the summary, all eight exhibits and the full limits section are all on this page. The email address is only for the complete formatted PDF, which adds the inventory method appendix and the buyer due-diligence checklist.

Is 312 systems across 40 firms enough to conclude anything?

It's enough to see a consistent pattern — 43% of systems had exactly one capable operator, well above what any firm estimated for itself — but the 40 firms all commissioned an inventory or handover engagement, which the report flags as making them more aware of this risk than average, not less.

Does this apply to firms much larger or smaller than these?

Not established here. The firms studied ranged from 30 to 600 people; firm size made no measurable difference to concentration within that range, but the report doesn't extend the claim beyond it.

What counts as a 'capable' operator, not just someone with access?

Someone who can do all three of operate the system routinely, make a change to it, and recover it after a failure — not simply hold credentials. Fifty-two systems had a second person with full access who, when asked, said they couldn't actually recover it.

Can I get the underlying data?

The inventory instrument, the capability definitions, the system-level codes with firm and system names removed, and the six-month follow-up determinations are available on request. Email research@xonik.com.

Who conducted this and when?

XONIK Research, fieldwork March 2024 to May 2026, published August 2026. A systems inventory conducted on site, plus 88 interviews with named operators and their managers.

Cite this

Govil, A. (2026). The cost of one person: key-person dependency across 312 systems in forty firms. XONIK Research, Report 04.