IT Stack at 10, 50, and 100 Employees: How Your Tools Should Evolve
A well-planned IT stack carries a company from its first hires to its first hundred without ever being rebuilt. The foundation stays the same at every size: one identity provider, managed devices, a single home for documents, and a known place to ask for help. What growth changes is how much capability each layer carries, and every upgrade below is an extension of the layer before it, not a replacement. Configure the foundation for scale from day one and each stage arrives as a settings change. If your company grew up on default settings and one-off access grants instead, the same ladder is the cleanup path, and none of it is hard to retrofit.
The headcounts in the title are markers, not rules. The honest trigger for each upgrade is a signal you can observe: requests going unanswered, offboarding taking longer than onboarding, a security questionnaire you cannot answer from settings that already exist. When a signal shows up, the next rung is due, at whatever size you are.
The Foundation Every Size Shares
Five pieces, set up once and kept for good: a company-controlled domain, an identity provider (Google Workspace or Microsoft 365), email authentication, a team password manager, and a baseline for company devices. A founding team can stand all of it up in the first weeks, and a hundred-person company runs on the exact same pieces.
What the rest of this post covers is what gets added on top, layer by layer:
- Identity grows from single sign-on into automated provisioning and access reviews
- Support grows from a channel with an owner into a service desk with commitments
- Device management grows from a checklist into zero-touch enrollment
- Security grows from a baseline into evidence you can hand to an auditor
- SaaS administration grows from a list into a managed portfolio
Identity: From One Login to a Managed Lifecycle
Identity is the layer where early configuration pays off most, because every app you connect inherits it.
- First rung: single sign-on everywhere. Every app added with "Sign in with Google" or "Sign in with Microsoft" from day one. One account created per hire, one account suspended per departure.
- Second rung: access by role. Apps assigned to groups in the identity provider rather than to individuals, so joining the sales group grants the sales stack. This is least privilege in practice, and it turns every access question into a membership question.
- Third rung: automated provisioning. SCIM connections between the identity provider and your core apps create, update, and deactivate accounts automatically. Offboarding stops being a checklist and becomes one action.
- Fourth rung: scheduled access reviews. A recurring review of group memberships and admin lists keeps grants current. Enterprise customers and insurers ask for exactly this.
The signal for each rung: manual invites piling up, access nobody remembers granting, offboarding checklists with more than a handful of manual steps.
Support: From a Channel to a Service Desk
- First rung: one visible place to ask. A dedicated channel where questions about access, hardware, and tools land, owned by a named person. The habit matters more than the tool.
- Second rung: tickets with history. A ticketing tool such as Jira Service Management, so requests get tracked, solved problems stay searchable, and nothing depends on who saw the message first.
- Third rung: commitments and automation. Response-time targets, a knowledge base answering the repeat questions, and AI triage resolving routine requests before a human touches them. Support in the channel your team already works in, with a real system behind it.
The signal: requests answered twice, requests missed entirely, or a founder still being the default IT contact.
Devices: From a Checklist to Zero-Touch
- First rung: a written baseline. Full-disk encryption, screen lock, and automatic updates on every company machine, applied at setup.
- Second rung: enforced by management. Devices enrolled in Jamf or Kandji for Mac fleets, Microsoft Intune for Windows, so the baseline is policy rather than habit and a lost laptop can be locked remotely.
- Third rung: zero-touch enrollment. Purchases routed through Apple Business Manager or registered for Windows Autopilot, so a new laptop ships straight to the hire and configures itself on first sign-in.
The signal: a machine you cannot account for, a new hire waiting on a laptop someone had to build by hand, or a customer asking how devices are secured.
Security: From a Baseline to Evidence on Demand
Security grows along the same line as everything above it, because most controls a reviewer asks about are the identity and device settings you have already made.
- First rung: the baseline. MFA enforced by policy, devices encrypted, access assigned by role, and a written offboarding checklist.
- Second rung: written down. Short policies that match what is actually configured, plus the scheduled access reviews from the identity ladder.
- Third rung: audit-ready. When enterprise deals put SOC 2 or a detailed questionnaire on the table, the work is assembling evidence from settings that already exist rather than changing how the company operates.
The signal here is external: the first enterprise security questionnaire, the first cyber-insurance application, the first customer contract with a compliance clause.
SaaS Subscriptions: From a List to a Managed Portfolio
- First rung: an inventory. Every app the company pays for, in one list, sourced from billing statements and the identity provider's app dashboard.
- Second rung: licenses tied to the lifecycle. Seats reclaimed as part of offboarding and renewals on a calendar, so the bill tracks actual usage.
- Third rung: an owned portfolio. A named owner for each admin console, overlapping tools retired, and renewals negotiated with usage data in hand.
The signal: paying for seats that belong to former employees, or discovering two tools doing the same job.
Who Runs the Ladder
At every one of these sizes, the common pattern is that IT is somebody's additional duty, usually a founder, a COO, or a senior engineer whose hours are worth far more on the product. The ladder above is routine work for a managed IT provider: the foundation configured for scale on day one, each rung added when its signal appears, and the whole thing run on a subscription while your team stays on the business. In-house IT headcount makes sense at scales and regulatory loads well past where most SMBs operate; until then, outsourcing the ladder is the practical default.
Related Reading
- The IT Stack for a 10-Person Startup: What to Set Up First
- How to Implement Least Privilege Access Across Your SaaS Stack
- How to Set Up SCIM Provisioning in Okta for Google Workspace
Want your stack to be one settings change ahead of your growth instead of one rebuild behind it? ScaleIt designs and runs this ladder for startups and SMBs as managed IT support. Book a free call and we will map your current stack against it.
Cross-referenced against Google Workspace, Microsoft 365, Okta, Microsoft Intune, Jamf, Kandji, Apple Business Manager, Windows Autopilot, and Jira Service Management documentation on 2026-09-17.