HANDOFF PLAYBOOK PROTOCOL

Key Administrator Departure

A step-by-step protocol for discovering hidden administrative shares, reassigning top-level directory ownership, and ensuring audit continuity when senior sysadmins leave the organization.

2026-06-25 | Custody Lead: Sarah Connor | Governance Standard #OHS-2026
Active Scenario RUNBOOK v4.2

Handoff Governance Matrix

Execute this protocol step-by-step to prevent orphaned data volumes during institutional role reassignments.

Apply Playbook to Department

Managing Administrative Shadow Zones and Root Access Transition

When a lead system administrator or senior infrastructure engineer departs, they leave behind not just credentials, but years of ad-hoc directory architectures, personal staging scripts, and unmapped storage volumes. Without a formal custody review, these areas quickly turn into unmanaged orphan zones.

Senior administrators frequently create utility directories, temporary batch storage points, and custom script repositories that sit directly outside normal departmental governance matrices. Over years of operational firefighting, these directories amass critical backup dumps, API tokens, and legacy configuration templates. Conducting an exhaustive directory walk prior to offboarding ensures these sensitive files receive documented departmental custodians rather than falling into unmonitored limbo.

Critical Custody Principle: Root Ownership vs Functional Stewardship

Administrative permissions must never be conflated with business ownership. While IT infrastructure teams maintain root NTFS ACLs and filesystem health, every single directory subtree must have a designated functional stakeholder in finance, engineering, or operations before the administrator departure sign-off is approved.

Three-Stage Administrative Custody Transfer Process

Execute the following sequential phases across corporate SAN, NAS, and cloud object stores during the standard two-week departure notice window.

Phase 1: Active Directory & Storage Tree Walk

Scan all enterprise storage volumes for folders created by or exclusively restricted to the departing administrator's security identifier (SID).

  • Run automated TreeSize directory ownership scans against all volume mount points.
  • Identify custom staging paths, personal scratch spaces, and local script archives.
  • Generate a comprehensive cryptographic catalog (SHA-256) of administrative file trees.

Security Controls & Escalation Safeguards

To prevent disruption to ongoing production pipelines, apply structured access modification rules and quarantine hold times.

System administrator departures require resetting root ownership to generic administrative security groups rather than personal accounts. Revoke direct user ACLs while preserving inherited permissions across active network shares to ensure operational continuity.
Audit existing retention schedules attached to administrative data dumps. Any archive older than 180 days without a documented business charter should be scheduled for lifecycle archival or formal decommissioning.
Directories lacking identifiable business stakeholders enter a 90-day read-only quarantine. If no department claims custody during this evaluation window, the data moves to encrypted offline tape backup before final purge.
REQUEST DIRECTORY HANDOFF AUDIT

Schedule Ownership Transfer Protocol

Submit this form to initiate an IT directory audit ledger transfer for this specific scenario. Our governance team verifies custodian identity and generates audit logs.

Enterprise Data Protection
24-hour Governance Response
Auditable Handoff Certificate