The IT Stack for a 10-Person Startup: What to Set Up First
A startup that gets its IT foundation right in the first few weeks runs on rails afterward. New hires get working accounts on day one, company data lives in company-controlled systems, and founder hours go to the product instead of access questions. The foundation is five pieces, set up in this order:
- A company domain and an identity provider
- Email authentication on that domain
- A team password manager
- A security baseline for company devices
- One shared home for documents and requests
This list is written for a founding team, and the same foundation carries a company to 120 people and beyond. The best move is to configure for scale from day one. If you launched on personal accounts and default settings and have already grown past them, it is not too late to move to this baseline.
Sequence Is the Strategy
Each layer depends on the one before it. The password manager syncs with the identity provider, the device baseline enrolls machines against company accounts, and the document home inherits its access rules from the directory. Set them up in order and every piece takes less work than it would standalone. Set them up ad hoc and you spend the next year reconnecting systems that never knew about each other.
1. Company Domain and Identity Provider
The identity layer is the single point of control for everything that follows. When someone joins, you create one account and they get email, files, and app access together. When someone leaves, you suspend one account and access closes everywhere at once.
The pattern to follow:
- Register the company domain under a company-controlled account, with billing and recovery contacts that survive any single person leaving.
- Pick Google Workspace or Microsoft 365 as the identity provider. Google Workspace fits teams living in Docs and Gmail; Microsoft 365 fits teams with Windows devices and Office dependencies.
- Give every person a work address from day one, and add each new SaaS app with "Sign in with Google" or "Sign in with Microsoft" instead of a standalone login.
The anti-pattern is the company that runs on personal Gmail addresses, with the domain registered to a founder's personal account. Every later cleanup step gets harder from there, and account recovery during a departure turns into a negotiation.
2. Email Authentication: SPF, DKIM, and DMARC
Mail from your new domain has to land in inboxes, and only you should be able to send it. Three DNS records handle both: SPF names the servers allowed to send for your domain, DKIM signs each message, and DMARC tells receiving servers what to do when a message fails the first two checks.
The pattern: publish all three records the same week the domain goes live. Google and Microsoft both document the exact values for their platforms, and the records take minutes to add at the DNS host. Start DMARC in monitoring mode, review the reports, then tighten the policy.
The anti-pattern is treating authentication as a someday task and discovering the gap when an investor update lands in spam or a customer receives a spoofed invoice from "your" domain.
3. Team Password Manager
Every startup accumulates shared credentials: the registrar, social accounts, billing portals, API keys. A team password manager makes those credentials shared on purpose, with an audit trail, instead of shared by chat message.
The pattern: a business plan on 1Password or Bitwarden, connected to the identity provider so accounts provision and deprovision with the directory. Shared vaults organized by function, and a rule from day one that any credential more than one person needs lives in the vault.
The anti-pattern is passwords in chat threads and spreadsheets. Those credentials cannot be rotated confidently, cannot be audited, and turn every departure into a guessing game about what needs changing.
4. Device Security Baseline
Company laptops carry customer data, source code, and financials long before there is an office. A baseline makes every machine a known quantity.
The pattern, applied to every company device at setup:
- Full-disk encryption turned on
- Screen lock and automatic updates enforced
- Enrollment in device management: Jamf or Kandji for Mac fleets, Microsoft Intune for Windows
At founding size, even a written checklist applied to each new laptop beats nothing. Device management makes the baseline enforceable instead of aspirational, and enrolling machines at purchase is far less work than enrolling them after habits form.
The anti-pattern is a mix of personal and company machines with no record of which ones hold company data, discovered during the first security questionnaire from an enterprise customer.
5. One Home for Documents and Requests
Knowledge and requests both need a default location before habits form around personal drives and direct messages.
The pattern: a shared drive or a workspace tool like Notion for documents, with a top-level structure set up before content accumulates. For requests, a single visible place where questions about access, hardware, and tools land, owned by a named person. A dedicated channel works at founding size; graduate to a ticketing tool like Jira Service Management when volume justifies it.
The anti-pattern is files scattered across personal accounts and requests routed to whoever responds fastest. Both feel fine at ten people and get expensive to unwind later.
Set Up the Foundation Once
ScaleIt sets up this exact foundation for startups and manages it as the team grows. Your best hours go to the product instead of admin consoles. Book a free call and we will map your current setup against this baseline.
Cross-referenced against setup and security documentation for Google Workspace, Microsoft 365, 1Password, Bitwarden, Jamf, Kandji, and Microsoft Intune on 2026-07-30.