Working with your internal IT: where the lines are

How a digital partner and a company's own IT team divide responsibilities without gaps or turf wars: the six lines and the two accounts that overlap.

3 minread 768words last updated

The short answer

A company with its own IT team and a digital partner has two groups with different jobs and a few overlaps, and the arrangement works when the lines are written down once. Internal IT owns the workplace: devices, the office network, user accounts and identity, business software, internal security policy and support for staff. The partner owns the customer-facing digital side: website, hosting, domains, forms, integrations, portals and the operations around them. The lines touch at three places, identity, email and DNS, where both have a legitimate interest and one must be named as owner with the other consulted. Neither holds the other’s keys; both work inside accounts the company owns. A one-page table of who owns, who is consulted and who is informed, plus a quarterly touchpoint, prevents both the gaps and the turf wars.

Who owns what

AreaInternal ITPartnerNotes
Devices, office network, printersOwns
Staff accounts and identity providerOwnsConsulted for portal and admin loginsThe partner integrates with IT’s identity for staff access
Business software: office suite, ERP, CRMOwnsConsulted for integrationsThe partner connects the website and portals to them through APIs
Internal security policy, endpoint protectionOwnsComplies and reportsThe partner’s practices documented for IT
Website, hosting, storefront, portalsInformedOwnsIn company accounts; IT has read access
Domains and DNSConsulted, sometimes owns the registrarManages records; owns web recordsOne named owner for the zone; changes logged
Email: mailboxesOwns
Email: authentication records and website sendingConsultedOwns the sending service recordsBoth must agree on the domain’s records
Forms, integrations, automations on the web sideInformedOwnsData flows documented for IT
Incidents touching both sidesJoint, with a named lead per typeJointContacts in both incident plans

Setting it up

  1. Draft the table together in one meeting, area by area.
  2. Name the owner of each overlap: DNS zone, email authentication, identity for portals.
  3. Give each side read access to the other’s relevant accounts where useful; nobody holds the other’s credentials.
  4. Document the partner’s practices for IT: hosting, data flows, security controls, incident handling.
  5. Agree the change process for DNS and identity, with response times.
  6. Put a quarterly touchpoint in the calendar for both.
  7. Cross-reference the incident plans with contacts.

Where each helps the other

IT brings identity, so staff log in to portals and admin tools with their normal accounts and leave when they leave the company. IT brings policy, so the partner’s practices fit the company’s security stance. The partner brings the web operations discipline: monitoring, pipelines, hosting in the company’s name, forms that deliver, integrations that work. The partner brings the customer-facing view that IT rarely has time for. Together they cover the whole digital estate with no area assumed to be someone else’s.

What this means for you

Write the table once: IT owns the workplace, the partner owns the customer-facing side, and the overlaps at identity, email and DNS each have a named owner and a consulted party. Keep both working inside company accounts, exchange documentation, and meet quarterly. The arrangement then covers everything without a gap or a turf war, which is what two competent teams should produce.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Should our IT team manage the website instead of a partner?

Rarely; the skills differ. Internal IT is workplace technology: devices, networks, identity, business applications. Websites, storefronts, portals and integrations are software development and web operations. Some IT teams have both; most do not, and asking them to run the web side produces a site nobody has time for. The productive arrangement is a clear division with named overlaps.

Where do turf wars usually start?

At the overlaps: who controls DNS, who owns the email domain's authentication records, who manages the identity provider that the customer portal uses for staff login. Each is legitimately of interest to both. Naming one owner per overlap, with the other consulted, ends most disputes before they begin.

What does IT need from the partner, and the reverse?

IT needs to know what runs where, which accounts exist, what data flows, and what the partner's security practices are, so it fits the company's policies. The partner needs identity and access for staff logins, DNS changes made promptly, email authentication records set, and a contact for incidents that touch both sides. A one-page table and a quarterly touchpoint cover it.