Bookings[email protected] San Antonio · Texas
Obsidian guide · Small office IT

Small-office IT documentation, in Obsidian.

When the person who “does the IT” is away, or a laptop goes missing, the office that wrote things down works from a checklist. Here’s what to record, what to keep out, and a simple way to do it in Obsidian.

Updated October 2026 · Tested in Obsidian 1.14 · No plugins

Why write it down

Most small offices run their IT from memory, usually one person’s. That works until the day it doesn’t:

  • A laptop is left in a taxi. Was it encrypted? What was on it? Which accounts were signed in?
  • Someone leaves. Which of the apps you use do they have a login for?
  • The website and email stop working because the domain expired, and nobody knows which registrar it’s with.
  • Someone clicks a phishing link at 4:55 on a Friday. Who do you call first?

An office that wrote things down works through each of these from a list. One that didn’t has to rebuild the picture from memory, under pressure. You don’t need special software: six lists and a few one-page runbooks cover it.

What to record: six lists

  • People. Who works here, which accounts they have, whether two-step login and a password manager are set up, and when they last had security training.
  • Devices. Every laptop, phone and router: who has it, purchase date, warranty end, and whether it’s encrypted, backed up and updating itself.
  • Systems and access. Every app and account: what data it holds, who the admin is, whether two-step login is on, and how you’d get your data out.
  • Vendors. Everyone who can touch your data, such as your IT provider, payroll and cloud apps, with a contact and the date you last reviewed them.
  • Renewals. Domains, software licenses, insurance and warranties: the date, whether it auto-renews, the cost and who pays.
  • Emergency contacts. IT support, your insurer, your bank’s fraud line, your domain registrar, and who in the office makes the call.

What never goes in your IT notes

Your notes should say where secrets live, never the secrets themselves. Keep these out:

  • Passwords, PINs and recovery codes, including two-step backup codes.
  • Encryption recovery keys (BitLocker, FileVault).
  • Card numbers, bank details, and Social Security or ID numbers.
  • Private keys and API keys.

Write a pointer instead: “Recovery key: in the password manager, entry ‘Front desk laptop’.” Notes are plain files that sync to every device you use. A password manager is built to protect secrets; notes aren’t.

Set it up in Obsidian: devices

One note per device, with true/false properties for the three things that matter most if it’s lost: encryption, backups and automatic updates. A true/false property shows as a checkbox.

Devices/Front desk laptop.md
---
type: device
kind: Laptop
status: In use
assigned_to: "[[Maria Lopez]]"
purchased: 2024-03-02
warranty_until: 2027-03-02
os: Windows 11
encrypted: true
backup: true
auto_updates: false
---

Then a Base that lists every device and flags the ones that need attention. (New to Bases? Our Bases recipes explain how to paste one in.)

Devices.base
filters:
  and:
    - type == "device"
    - '!file.inFolder("Templates")'
formulas:
  warranty: if(!warranty_until, "", if(date(warranty_until) < today(), "Expired", if((date(warranty_until) - today()).days.round(0) <= 60, "Ends soon", "OK")))
  problems: if(!encrypted, "Not encrypted. ", "") + if(!backup, "No backup. ", "") + if(!auto_updates, "Updates off.", "")
properties:
  file.name:
    displayName: Device
  note.assigned_to:
    displayName: Assigned to
  formula.problems:
    displayName: Needs
views:
  - type: table
    name: Needs attention
    filters:
      and:
        - status == "In use"
        - '!encrypted || !backup || !auto_updates'
    order:
      - file.name
      - assigned_to
      - formula.problems
  - type: table
    name: All devices
    filters:
      and:
        - status != "Retired"
    groupBy:
      property: kind
      direction: ASC
    order:
      - file.name
      - assigned_to
      - status
      - formula.warranty

Needs attention lists any device in use that isn’t encrypted, isn’t backed up or has updates off. The problems formula spells out what’s missing, so the list reads like a to-do list. When it’s empty, you’re done.

Renewals: the cheapest outage to prevent

Domains, licenses, insurance and warranties lapse on dates you can know in advance. Give each renewal a note with type: renewal, renews_on, auto_renew and cost, and this Base adds a traffic light and a total:

Renewals.base
filters:
  and:
    - type == "renewal"
    - '!file.inFolder("Templates")'
formulas:
  days_left: if(renews_on, (date(renews_on) - today()).days.round(0), "")
  alert: if(!renews_on, "", if(date(renews_on) < today(), "🔴 Lapsed", if((date(renews_on) - today()).days.round(0) <= 30, "🟡 Soon", "🟢 Later")))
views:
  - type: table
    name: Next 60 days
    filters:
      and:
        - if(renews_on, (date(renews_on) - today()).days <= 60, false)
    order:
      - file.name
      - renews_on
      - formula.days_left
      - auto_renew
      - cost
      - formula.alert
    sort:
      - property: renews_on
        direction: ASC
    summaries:
      cost: Sum

Check the domain first: if it lapses, your website and email can stop at the same time. Turn on auto-renew at the registrar, and check the card on file hasn’t expired.

Runbooks: write them before the bad day

A runbook is a one-page checklist for one bad day, written while everyone is calm. Start with three: someone clicked a phishing link, a laptop is lost or stolen, and someone is leaving. Here’s the phishing one from our Office IT Binder:

Runbooks/Someone clicked a phishing link.md
---
type: runbook
area: Incidents
last_tested: 2026-07-08
---
**First 15 minutes**
1. If they typed a password: change it now, from a different device, and sign out all sessions.
2. Check two-step login is still on and no new MFA device or app password was added.
3. If a file was downloaded or run: disconnect that computer from the network (unplug or Wi-Fi off). Leave it on.
4. Check the email account for new forwarding rules or filters, and remove them.

**Next hour**
- [ ] Look at recent sign-in activity for unfamiliar places.
- [ ] Warn your bank if payments could be affected.
- [ ] Call your IT support. Call your insurer if data or money may be involved.
- [ ] Open an Incident note with times and actions.

Keep IT support and insurer contacts on an Emergency contacts page, and walk through each runbook once a year to fix whatever has changed.

A 10-minute monthly check

  1. Look at renewals in the next 60 days.
  2. Clear the Needs attention list.
  3. Add new starters, and close every account for anyone who left.
  4. Once a quarter, restore one real file from your backup to prove it works.

If you handle customers’ financial information

Tax preparers, mortgage brokers, many auto dealers and other businesses the FTC treats as financial institutions need a written information security program under the FTC Safeguards Rule. Records like these (systems and data, access, vendors, incident response) support that program, but they aren’t the whole program. Our free WISP builder drafts the written plan, and this page explains the rule in plain English.