I started a solo IT position about a month ago after the previous IT person retired. I received access to his old email and files, but the planned knowledge-transfer meetings never happened. My CEO is also leaving at the end of the month and only knows a limited amount about the technology environment.
There is almost no reliable documentation. The existing files are outdated and refer to a previous office location, and there is no ticketing system, SOP library, knowledge base, or clear record of vendors. I recently had trouble identifying the vendor for a broken multifunction fax machine and the provider responsible for its phone line. The phone system itself also has unresolved issues and no troubleshooting history.
I do not have a clear picture of user groups, role-based access, firewalls, wireless access points, network layouts, hardware, backups, software renewals, or the systems in each building. I may need to create the network diagrams and asset inventory from scratch. I have started organizing useful files in a private SharePoint site and have tried using Microsoft Copilot to search OneDrive, but the results have been inconsistent.
This is a nonprofit with a very limited budget after losing $500,000 in funding. I may eventually recommend hiring another helpdesk person and automating repetitive tasks, but right now I need a practical way to discover and document the environment, identify the biggest risks, and build a useful knowledge base without spending much money. What should I prioritize, and how would you approach learning an undocumented IT environment on your own?
5 Answers
Do a physical discovery of every site. Locate where the internet connection enters, network closets, switches, firewalls, wireless equipment, servers, printers, phone equipment, and backup devices. Record manufacturers, model numbers, serial numbers, IP addresses, configurations, warranties, and support contacts. A basic spreadsheet, OneNote, or a simple SharePoint list is enough initially. Network discovery tools such as NetBox, Lansweeper alternatives, or Domotz can help, but do not let tool selection delay the inventory.
Get outside help if the risks are beyond your experience or available time. A reputable local managed service provider or nonprofit technology consultant can perform an environment assessment, review backups and security, and help create a prioritized roadmap. Organizations such as NTEN and nonprofit technology discount programs may provide affordable advice, software, hardware, or consulting options. Also make sure your role, salary, staffing, and budget match the responsibility being assigned to you.
Treat the current setup as something you may eventually need to rebuild, not just preserve. After documenting the essentials, simplify and standardize where possible. For a small Microsoft nonprofit environment, nonprofit licensing programs, Microsoft 365, Intune, Autopilot, and cloud-based services may reduce the amount of infrastructure you have to maintain. Keep configurations and procedures in version-controlled documentation where practical, and automate only after you understand the process.
Finance and accounting are often the best starting point for discovering the environment. Review invoices, recurring payments, purchasing records, and upcoming renewals to build a vendor and licensing list. Talk with department leads about what they use every day, then compare that with what is being paid for. You will probably find unnecessary or abandoned services as well as important ones nobody documented.
Start with risk and business continuity rather than trying to fix everything at once. Verify that backups actually exist and can be restored, confirm who has administrative access, and document critical systems, contacts, renewal dates, and dependencies. Then create a ranked list of issues and have leadership approve the order. That gives you protection from unrealistic expectations and keeps the work focused.

Also ask about contractors and one-time project payments. Network installers, phone vendors, consultants, and security providers may not appear as obvious monthly subscriptions.