The 90-day onboarding is the process by which an operations partner takes over a business's website or software, stabilises it, and moves it into steady-state operations with a clear service commitment. Three 30-day phases: intake and stabilisation, optimisation and automation, steady state. A business that runs these 90 days properly ends up with a fully documented system, monitoring, verified backups, and a partner who knows the system well enough to handle an incident at 2 a.m. Skip it, and outsourcing becomes a chain of misunderstandings about "who is responsible for this".
Why the first 90 days decide
When a business moves operations from the previous person (a departing employee, the agency that built the site, a friend who helped) to a new partner, three things are usually lost: access, knowledge of how the system really runs, and the promises made to customers. None of them live in the source code. They live in the previous person's head, in Zalo messages, in an Excel file on someone's laptop.
Ninety days is long enough for the new partner to find all of those before they cause an incident, and short enough that the business does not pay for an extended "getting acquainted" period. In-house team or outsourced compares the two options; this article assumes outsourcing has been chosen and focuses on how to hand over.
Before day 1: the business's preparation checklist
The partner cannot take over what nobody hands them. Before day one, the business gathers:
- Access: domain, hosting or cloud account, source code, database, system email, third-party services (payments, email delivery, maps, analytics). Move everything into a shared password manager; do not send it over chat.
- Running contracts and invoices: when the domain renews, when hosting expires, which paid services are active and whether they are still used.
- Contact list: who in the business decides what, and which third parties to call when payments fail.
- Promises to customers: response time commitments, features under development, bugs promised to be fixed.
- Incidents from the past 12 months: any record, including chat messages.
Starting without a complete list is fine, but each missing item is a risk the partner will need time to discover during phase 1.
Phase 1 (days 1 to 30): intake and stabilisation
Goal: nothing else breaks, and the partner knows the system well enough to handle incidents.
- Week 1: full inventory. Every server, domain, service, account and software version recorded in one document. Rotate admin passwords, revoke access for anyone no longer involved.
- Week 2: enable monitoring (uptime, errors, resources) and automated daily backups. Run a restore test from backup at least once; backup is not enough, you must be able to restore explains why this step cannot be skipped.
- Week 3: address obvious risks: end-of-life software, expiring SSL certificates, known vulnerabilities, paid services nobody uses.
- Week 4: day-30 report: current state, risks addressed, risks remaining, proposals for phase 2.
By the end of phase 1, the partner must be able to handle a severity-1 incident without asking the previous person. If not, extend phase 1; do not move on.
Phase 2 (days 31 to 60): optimisation and automation
Goal: the system runs better than when received, and repetitive work is automated.
- Scheduled software and library updates, tested in a staging environment before production.
- Performance optimisation at measurable points: page load time, slow queries, wasted infrastructure spend.
- Automation: deployments, backups, health checks, alerts routed to the right person by severity.
- Operations documentation rewritten to match how the partner actually works: procedures per incident type, restore steps, who to call when.
- Outstanding customer promises resolved: either delivered or re-communicated with realistic dates.
This is also when the formal service commitment is agreed: severity levels, response time, resolution time, uptime. What is an SLA explains how to read those numbers.
Phase 3 (days 61 to 90): steady state
Goal: long-term operating mode with a fixed reporting rhythm.
- The service commitment takes effect; every incident is logged and measured against it.
- Monthly report in a fixed format: uptime, incidents and resolution times, updates made, infrastructure costs, upcoming risks, recommendations.
- Six-month roadmap: major upgrades needed, features the business wants, expected costs.
- Incident drill: simulate a serious out-of-hours failure, measure time from detection to resolution, capture lessons.
Measuring the result at day 90
The handover succeeded when the answer is "yes" to all six:
- Is all access in one place, with the previous person's access removed?
- Has a restore from backup been tested successfully at least once?
- Does monitoring alert before customers do?
- Is the documentation sufficient for a new engineer at the partner to handle a severity-1 incident?
- Is there a written service commitment and a first monthly report?
- Are there no customer promises left hanging without a date?
5 warning signs during the 90 days
- The partner asks nothing in week one. Every system has oddities; no questions means nobody has looked.
- No restore test after day 30. An unverified backup is not a backup.
- Reports only say "everything is fine". A good report always has a remaining-risks section.
- Changes made directly on production. No staging environment means an update-induced incident is coming.
- The business assigns no counterpart. The partner cannot decide on the business's behalf about customer promises or upgrade budgets.
Cost of the onboarding period
Most operations partners charge a one-off intake fee (typically 1 to 2 months of the operations fee) for phases 1 and 2, because the workload is higher than steady state. For a business website, steady-state operations start from a few million dong a month; for business software, more depending on complexity. Against the cost of one data-loss incident or one day of downtime, the hidden costs of self-hosting has numbers to compare.
Siri9 applies exactly this 90-day process under website maintenance and software maintenance. The day-30, day-60 and day-90 reports are part of the contract.
Frequently asked questions
What if the previous person will not cooperate?
It is still possible, but phase 1 takes longer: the partner recovers access through the domain and hosting providers (business documents required) and rebuilds documentation from the source code and the live system. This is why the domain and cloud accounts should be owned in the business's name from the start.
Does a small website need the full 90 days?
The three phases are still needed, but each is shorter; a simple business website can be done in 30 to 45 days. The restore test and the service commitment are never skipped, however small the system.
Can onboarding start during an incident?
Yes, and it is often the reason a business looks for a partner. The partner handles the incident first, then returns to the week-1 inventory. Only the emergency fee for the initial work needs to be agreed clearly.
How do we start?
Send Siri9 the website address or a description of the software, along with whatever you have from the checklist above; we reply within 24 hours with a 90-day plan and a specific price.
