Co-Working
If your IT provider refuses to hand over passwords or documentation, put the request in writing, preserve evidence, regain control of accounts through their official recovery processes, and set a 48-hour deadline for an initial handoff. For a coworking operator, prioritize internet, email, identity, billing, cameras, and door access so members and the business remain protected.
In This Article
- What should a coworking operator do first when an IT provider withholds access?
- Which accounts and systems need to be recovered first?
- How can you regain control without creating a bigger outage?
- What documentation should you insist on receiving from your IT provider?
- When should you involve counsel, vendors, or a new IT partner?
- Frequently Asked Questions
What should a coworking operator do first when an IT provider withholds access?
Stop treating the dispute as a routine support issue. Create one incident owner on your leadership team, document every request and response, and inventory the systems the provider may control. Your first goal is continuity: keep members connected, staff productive, doors operating, and security monitoring visible.
Send a concise written demand to the provider using the contract’s notice method. Request administrative access, current credentials or approved transfer steps, configuration exports, vendor contacts, network diagrams, asset lists, licenses, backup status, and documentation. Name a responsible person and a deadline for the initial return of critical materials.
Do not accept a verbal promise that access will come “soon.” Ask for a system-by-system handoff tracker showing the account owner, recovery email, administrator, current status, and next action. That record prevents a high-risk account from disappearing inside a long email thread.
Set a written 48-hour deadline for the initial handoff of business-critical accounts and access records.
Takeaway: Stabilize critical services first, then make every handoff request traceable.
Which accounts and systems need to be recovered first?
Start with identity and communications. The Microsoft 365 or Google Workspace tenant, domain registrar, DNS, email security, password manager, and accounting-linked SaaS accounts can determine who can reset other services. Establish company-owned recovery contacts and multi-factor authentication before moving to lower-priority tools.
For a flexible workspace, then protect the systems that affect safety and member experience: firewall administration, Wi-Fi controller, internet circuits, VLANs and SSIDs, captive portal, VoIP, access control, and video surveillance. A former provider should not remain the only party able to change a door schedule or inspect a camera system.
Confirm where backups run, who owns the backup tenant, what data is covered, and whether restoration has been tested. Access to a backup console is not the same as confidence that your tenant data, shared drives, line-of-business data, and configuration records can be restored. Review data backup and recovery planning as part of the transition, not after it.
In Atlanta’s multi-tenant buildings, physical infrastructure can be as important as the cloud account. Identify the ISP demarc, MDF and IDF access, riser pathways, circuit contracts, landlord approvals, cabling records, and any third-party equipment. That reduces the risk of a delayed move, suite reconfiguration, or outage along the I-85 corridor.
Takeaway: Recover the accounts that control resets, revenue, safety, and member connectivity before everything else.
How can you regain control without creating a bigger outage?
Use each vendor’s formal ownership, administrator-recovery, and billing-contact process rather than relying solely on the outgoing provider. The business may need to provide incorporation documents, a billing statement, domain proof, or an authorized officer’s identification. Keep copies of submissions and case numbers.
Change credentials only after confirming dependencies. A rushed password reset can break backup jobs, printer scanning, conference-room integrations, door controllers, or vendor remote support. Create new company-controlled administrator accounts first, record the purpose of every service account, and rotate access in a controlled sequence.
Segment the transition. Keep the outgoing provider’s access narrowly scoped and time-bound where immediate removal would jeopardize operations, then disable it once replacement access has been tested. Review admin logs, forwarding rules, remote-control tools, API keys, shared mailboxes, VPN users, and unmanaged local accounts for residual access.
GDS’s own episode on service-access risks in building operations explains why shared credentials and disconnected facilities processes become an operational problem. In coworking, an ungoverned digital key can affect both tenant privacy and building access.
Takeaway: Recover ownership methodically; do not trade one access problem for an avoidable outage.
What documentation should you insist on receiving from your IT provider?
Request usable documentation, not a pile of screenshots. At minimum, it should identify every business system, vendor, account owner, administrator, renewal date, license, recovery contact, configuration location, and support escalation path. It should also distinguish company-owned accounts from provider-owned internal tools.
- Network records: current diagrams, IP addressing, VLANs, Wi-Fi SSIDs, firewall rules, ISP circuit details, equipment inventory, and MDF, IDF, or riser locations.
- Security records: endpoint protection, email security, vulnerability findings, administrator lists, incident contacts, MFA methods, remote-access tools, and firewall configuration exports.
- Operational records: backup scope and reports, disaster-recovery procedures, help-desk history, warranty details, software licensing, renewal calendar, and vendor tickets still in progress.
- Physical-technology records: door-controller credentials, camera inventory, access schedules, installer contacts, structured-cabling drawings, and any landlord or property-management approvals.
Ask for current versions and machine-readable exports where possible. A diagram without equipment names, a password list without ownership, or a backup report without retention details is not sufficient for a new technology partner to operate safely.
For building-side records, the GDS resource on infrastructure documentation is a useful example of why asset and cable ownership need a durable record. That level of organization matters when a new provider must troubleshoot a space without relying on former staff memory.
Takeaway: Documentation must let a qualified team operate, secure, and recover the environment without guessing.
When should you involve counsel, vendors, or a new IT partner?
Involve legal counsel when a provider refuses access to business-owned accounts, threatens an outage, retains data, asserts a disputed lien, or ignores contractual handoff terms. Counsel can assess the agreement, preserve evidence, and communicate the demand without turning a technical transition into an uncontrolled confrontation.
Contact the underlying vendors early when the provider is unresponsive. Domain registrars, cloud platforms, internet carriers, access-control vendors, and security-product vendors each have escalation paths for legitimate business owners. Ask what proof they require and whether an emergency ownership review is available.
Bring in a new provider before making major changes, especially if you operate private offices, dedicated desks, and shared member networks. A capable transition team can map dependencies, validate failover, separate tenant and guest traffic, review firewall and camera access, and coordinate with property management. Explore IT support designed for coworking spaces and cybersecurity services for business continuity when building the recovery plan.
Real follow-through matters during a transition. Kawal, a professional-services client, said, “GDS followed up the next day to make sure the door sensor issue is resolved. That kind of attention shows real customer service.” A handoff should include the same confirmation mindset: verify that a recovered system actually works, not merely that someone supplied a login.
Takeaway: Escalate early when ownership, security, or continuity is at risk, and require tested results.
Frequently Asked Questions
Can my IT provider legally keep my business passwords?
It depends on the contract, account ownership, and the type of credentials involved. A provider may need to protect its own internal tools, but business-owned domains, cloud tenants, data, network configurations, and administrator access require prompt legal and technical review when withheld. Preserve records and have counsel assess disputed claims.
What if the provider owns the domain or Microsoft 365 tenant?
Begin the registrar or platform ownership-recovery process immediately and gather invoices, corporate documents, prior correspondence, billing proof, and evidence of your company’s use of the account. Do not create a competing tenant until a transition team evaluates mail, identity, licensing, and data-migration consequences. Escalate through vendor support and counsel.
Should I change every password during an IT-provider transition?
Yes, but in a planned sequence after company-controlled administrator accounts, recovery contacts, and MFA are established. Inventory service accounts and integrations first because an immediate reset can interrupt backups, printing, VoIP, door systems, or monitoring. Test each critical service after rotation and document who owns the new credentials.
How do I prevent this problem with my next IT provider?
Use a contract that states the business owns its accounts, data, configurations, documentation, and transferable licenses. Require named administrative access, a current handoff register, regular documentation reviews, and defined offboarding obligations. Keep billing and recovery contacts in company control, and test your ability to access essential systems at least annually.