You are the only person who knows the router password, the billing portal login, the SIM PIN, and which breaker feeds the radio. You want two weeks off. The problem is not trust. The problem is that your absence is a single point of failure, and no one else has the context to recover from it.
This is a procedure for making that absence survivable. It has three parts: a handover document that tells a competent stranger what to do, a break-glass envelope that gives them the credentials to do it, and a phone that rings when something goes wrong. Each part has a cost and a failure mode it does not survive. I will state both.
Start with what actually breaks
Before writing anything, list the things that will page you at 2 a.m. if you are gone. For a community ISP, that is usually the upstream link, the billing system, and the tower power. For a rural clinic, it is the patient records server and the lab printer. For a fintech branch, it is the agent float and the transaction terminal. For a small factory, it is the PLC network and the payroll file.
Rank them by what happens if they stay down for four hours, one day, and one week. The four-hour list is what the handover doc must cover. The one-week list is what the break-glass envelope must cover. The rest can wait until you are back.
RFC 2196, the Site Security Handbook, makes the same point in its risk assessment section: identify the assets, identify the threats, then implement measures that protect assets in a cost-effective manner. It also warns that the cost of protection should be less than the cost of recovery, counting losses in real currency, reputation, and trustworthiness. That is the right frame here. A handover doc that costs you a weekend to write is cheap if it prevents a week of downtime.
The handover document
The handover doc is not a runbook. A runbook assumes the reader knows the system. The handover doc assumes the reader has never seen your network and is mildly annoyed to be reading it.
Write it in this order:
- What this is. One paragraph: what the system does, who depends on it, and what happens if it stops.
- What you can safely ignore. List the alerts and warnings that are normal. This is the single most valuable section for a stand-in. Without it, they will chase ghosts.
- The five things that actually matter. For each: symptom, likely cause, first action, who to call if that fails.
- Access map. Where the credentials live, how to get them, and what each one opens. Do not put the credentials themselves in this document. Point to the envelope.
- Contacts. Upstream provider, hardware vendor, landlord, power utility, and one person who knows you well enough to say “Felix would not do that.”
- What not to do. The changes that look helpful but will make things worse. Factory-resetting the router. Reinstalling the billing database. Calling the upstream provider and asking them to “reset everything.”
Keep it under ten pages. If it is longer, the stand-in will not read it. Print two copies. One goes in the envelope. One goes in a drawer that the stand-in can find without calling you.
NIST SP 800-53 Rev. 5 is the reference catalog for this kind of control. It is written for organizations with security programs, not one-person teams, so do not try to implement it wholesale. But two control families are worth reading directly: Contingency Planning (CP) and Access Control (AC). The CP family covers what you are doing here. The AC family covers who is allowed to do it. The publication is free and the control text is specific enough to be useful even if you ignore the assessment procedures.
The break-glass envelope
The break-glass envelope is a physical envelope containing the credentials the stand-in needs to recover from the one-week list. It is sealed, signed across the flap, and stored somewhere the stand-in can reach without breaking into your house.
What goes in:
- Local admin password for the router and the server.
- Login for the upstream provider portal.
- Login for the billing or records system, with a note on what not to touch.
- SIM PIN and the number to call for a PUK if the SIM locks.
- One-time recovery codes for any account with two-factor authentication.
- A written note: “If you open this, call me. If I do not answer within 24 hours, proceed.”
What does not go in: your personal email password, your bank login, or anything that gives access to systems outside the one-week list. The envelope is for recovery, not for convenience.
The trade-off is real. A sealed envelope in a drawer is a physical attack surface. Someone with access to the drawer can open it, use the credentials, and reseal it badly. You will not know until you check the signature. The mitigation is to check the signature when you return and to rotate every credential in the envelope after any use, planned or not. That rotation costs you an afternoon. It is the price of the envelope.
If the stand-in is in a different city, the envelope becomes a problem. Options: a sealed envelope with a trusted third party, a safe with a combination that is split between two people, or a cloud password manager with emergency access. Each has a failure mode. The third party can lose it. The safe can be opened without you knowing. The cloud manager depends on the internet, which is the thing you are trying to survive. Pick the one whose failure mode you can live with.
The phone that must ring
The stand-in needs to know when something is wrong. If your monitoring sends alerts only to your phone, your absence is invisible until a customer calls.
Set up a second alert path that does not depend on you. The cheapest version is a prepaid SIM in a cheap phone that lives with the stand-in, with your monitoring system configured to send SMS to that number. The cost is the phone plus airtime, maybe 15,000 to 25,000 naira in Nigeria or the equivalent in shillings or rupees. The failure mode it survives is your phone being off, lost, or out of coverage. The failure mode it does not survive is the monitoring system itself being down, which is why the stand-in also needs a way to check the system manually.
Be careful with alert volume. A stand-in who gets forty SMS messages a day will stop reading them. Route only the four-hour list to the second phone. Everything else can wait.
If your monitoring depends on the same internet link that carries your customers’ traffic, it will go down with the link. That is a design flaw, not a monitoring flaw. The fix is a second path, even if it is a cheap 2G modem that only sends SMS. ITU data shows that mobile-cellular coverage is far more widespread than fixed broadband in most of the regions this blog serves, so a 2G or 3G SMS path is often the most reliable option available. Check the ITU statistics for your country before assuming a second fixed line is possible.
What about the legal and regulatory side
If you run a clinic, a fintech branch, or anything that touches patient or customer data, the break-glass envelope is not just an operational decision. It is a data protection decision. The person holding the envelope may be able to see records they are not authorized to see.
NIST publishes a Privacy Framework that is a voluntary tool for managing privacy risk. It is not a law and it does not tell you who may hold credentials. But it does give you a vocabulary for the trade-off: you are accepting a privacy risk in exchange for an availability benefit. Write that trade-off down. If a regulator or a partner asks why a non-employee had access to the records system, the answer should be a document, not a shrug.
For mobile money agents, the GSMA State of the Industry Report on Mobile Money is the standard reference for how the sector operates. It does not prescribe break-glass procedures, but it does document the scale of the agent network and the dependence on individual agents. If your branch is one of those agents, the provider’s own terms of service may already require you to have a named alternate. Read them before you write your own procedure.
The two-week test
Before you take the time off, run a test. Give the stand-in the handover doc and the envelope, then leave for a weekend. Do not answer your phone unless it is the second phone. When you return, ask three questions:
- What did you have to guess?
- What did you look for and not find?
- What did you almost break?
Fix the answers. Then take the two weeks.
The test costs you a weekend. It is the only way to know whether the doc and the envelope work. A handover doc that has never been used is a guess. A break-glass envelope that has never been opened is a hope.
When this is wrong
This procedure assumes you can find one competent person who is willing to be the stand-in. If you cannot, the procedure does not work. The alternative is to reduce the blast radius: move what you can to a managed service, accept longer downtime for what you cannot, and tell your customers what to expect. That is a worse outcome, but it is an honest one.
It also assumes the stand-in is trustworthy. If they are not, the envelope is a liability. The mitigation is the signature check and the rotation, but those only tell you after the fact. If you cannot find someone you trust, do not use an envelope. Use a managed service with a support contract, even if it costs more.
Finally, this procedure assumes you have the time to write the doc and run the test. If you do not, you have a bigger problem than the vacation. The doc is the vacation. Without it, you are not taking time off. You are just working from a different location.
FAQ
How long should the handover doc be? Under ten pages. If it is longer, the stand-in will not read it. The five-things section is the part that matters.
Can I use a password manager instead of an envelope? Yes, if the stand-in has reliable internet and you have tested the emergency access feature. The failure mode is the internet, which is often the thing that is broken. A physical envelope does not need the internet.
What if the stand-in needs to call the upstream provider? Put the account number, the support number, and the name on the account in the handover doc. Do not put the portal password in the doc. Put it in the envelope.
How often should I rotate the credentials in the envelope? After every use, planned or not. Also rotate them if the envelope is lost, if the stand-in leaves, or if you have any reason to believe the seal was broken. An annual rotation is a reasonable baseline if none of those happen.
What if I cannot find a stand-in at all? Reduce the blast radius. Move what you can to a managed service. Accept longer downtime for the rest. Tell your customers what to expect. It is a worse outcome, but it is honest.













